魔盾安全分析报告

分析类型 开始时间 结束时间 持续时间 分析引擎版本
FILE 2024-04-26 11:13:46 2024-04-26 11:16:12 146 秒 1.4-Maldun
虚拟机机器名 标签 虚拟机管理 开机时间 关机时间
win7-sp1-x64-shaapp02-1 win7-sp1-x64-shaapp02-1 KVM 2024-04-26 11:13:48 2024-04-26 11:16:14
魔盾分数

10.0

恶意的

文件详细信息

文件名 EasyConnectInstaller.exe
文件大小 14609040 字节
文件类型 PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
CRC32 EB372983
MD5 26c1aa3d2dea9bb2353c25dac001ac63
SHA1 63056238d5c9631c8c22a8067a4aaf759d5bf08d
SHA256 d884ef1b508e24aec9ba60813d1fddb7b6e5ac34f29e4ae85412c3006fae9e06
SHA512 c51b107deb9533c179523bca5605711c8f5e8545073ba136963a3ef51395fd7cecef2225bc52fefe92134651c80e14b204a3e63d3033fdcf1c52d7b1bb2909cf
Ssdeep 393216:K/SJj/m2EdAgPJ9YQCVSomddxSAU817tS90KnuYkD:7J62wJOVSlxSG17P3b
PEiD 无匹配
Yara
  • DebuggerTiming__Ticks (Detected timing ticks function)
  • screenshot (Detected take screenshot function)
  • create_process (Detection function for creating a new process)
  • escalate_priv (Detected escalate priviledges function)
  • keylogger (Detected keylogger function)
  • win_registry (Detected system registries modification function)
  • change_win_registry (Change registries to affect system)
  • win_token (Affect system token)
  • win_files_operation (Affect private profile)
  • win_private_profile (Detected private profile access function)
  • Proprietary_Anomoly_Combined_Activities_7 (Spotted potential malicious behaviors from a small size target, like process manipultion, privilege, token and files)
  • IsPE32 (Detected a 32bit PE sample)
  • IsWindowsGUI (Detected a Windows GUI sample)
  • IsPacked (Detected Entropy signature)
  • HasOverlay (Detected Overlay signature)
  • HasDigitalSignature (Detected Digital Signature)
  • HasRichSignature (Detected Rich Signature)
  • CRC32_poly_Constant (Look for CRC32 [poly])
  • with_urls (Detected the presence of an or several urls)
VirusTotal VirusTotal查询失败

特征

创建RWX内存
在加密调用中发现至少一个IP地址,域名,或文件名
ioc: nic.cat
ioc: 5.9.0.0
ioc: nic.ndi
ioc: nic.reg
ioc: nic.ndi.Services
ioc: nic.service
ioc: nic.sys
ioc: angfor.inc
通过进程尝试延迟分析任务
Process: VNICInstaller_X64.exe tried to sleep 60 seconds, actually delayed analysis time by 0 seconds
多次尝试建立挂起的进程
强制将一个创建的进程加载为另一个不相关进程的子进程
装载一个驱动器
driver service name: \Registry\Machine\System\CurrentControlSet\Services\SangforTcpDrv_7,5,0,1
driver service name: \Registry\Machine\System\CurrentControlSet\Services\SangforDnsDrv_7,5,0,1
driver service name: \Registry\Machine\System\CurrentControlSet\Services\WudfPf
从文件自身的二进制镜像中读取数据
self_read: process: EasyConnectInstaller.exe, pid: 2612, offset: 0x00000000, length: 0x00deb404
self_read: process: EasyConnectInstaller.exe, pid: 2612, offset: 0x0001641c, length: 0x00908000
self_read: process: EasyConnectInstaller.exe, pid: 2612, offset: 0x0095a41c, length: 0x00228000
self_read: process: EasyConnectInstaller.exe, pid: 2612, offset: 0x00b8641c, length: 0x00264fec
self_read: process: SangforCSClientInstaller.exe, pid: 2400, offset: 0x00000000, length: 0x00009200
self_read: process: SangforCSClientInstaller.exe, pid: 2400, offset: 0x00000000, length: 0x0019b3c1
self_read: process: SangforCSClientInstaller.exe, pid: 2400, offset: 0x0000921c, length: 0x001921a9
self_read: process: TcpDriverInstaller.exe, pid: 2716, offset: 0x00000000, length: 0x00009c00
self_read: process: TcpDriverInstaller.exe, pid: 2716, offset: 0x00000000, length: 0x00020ffd
self_read: process: TcpDriverInstaller.exe, pid: 2716, offset: 0x00009c1c, length: 0x000173e5
self_read: process: DnsDriverInstaller.exe, pid: 2188, offset: 0x00000000, length: 0x00009c00
self_read: process: DnsDriverInstaller.exe, pid: 2188, offset: 0x00000000, length: 0x00019820
self_read: process: DnsDriverInstaller.exe, pid: 2188, offset: 0x00009c1c, length: 0x0000fc08
self_read: process: SuperExeInstaller.exe, pid: 2756, offset: 0x00000000, length: 0x00009200
self_read: process: SuperExeInstaller.exe, pid: 2756, offset: 0x00000000, length: 0x00031ec0
self_read: process: SuperExeInstaller.exe, pid: 2756, offset: 0x0000921c, length: 0x00028ca8
self_read: process: SangforServiceClientInstaller.exe, pid: 2288, offset: 0x00000000, length: 0x00008a00
self_read: process: SangforServiceClientInstaller.exe, pid: 2288, offset: 0x00000000, length: 0x0001c44f
self_read: process: SangforServiceClientInstaller.exe, pid: 2288, offset: 0x00008a1c, length: 0x00013a37
self_read: process: VC2010RedistX86UInstaller.exe, pid: 2528, offset: 0x00000000, length: 0x00219d81
self_read: process: VC2010RedistX86UInstaller.exe, pid: 2528, offset: 0x00008c1c, length: 0x001b0000
self_read: process: VC2010RedistX86UInstaller.exe, pid: 2528, offset: 0x00219d81, length: 0x00000004
self_read: process: SJobberInstaller.exe, pid: 2440, offset: 0x00000000, length: 0x00008c00
self_read: process: SJobberInstaller.exe, pid: 2440, offset: 0x00000000, length: 0x0001521f
self_read: process: SJobberInstaller.exe, pid: 2440, offset: 0x00008c1c, length: 0x0000c607
self_read: process: SangforUpdateInstaller.exe, pid: 2968, offset: 0x00000000, length: 0x00008a00
self_read: process: SangforUpdateInstaller.exe, pid: 2968, offset: 0x00000000, length: 0x00056e08
self_read: process: SangforUpdateInstaller.exe, pid: 2968, offset: 0x00008a1c, length: 0x0004e3f0
self_read: process: SangforRAppInstaller.exe, pid: 3044, offset: 0x00000000, length: 0x0000ec00
self_read: process: SangforRAppInstaller.exe, pid: 3044, offset: 0x00000000, length: 0x003ee200
self_read: process: SangforRAppInstaller.exe, pid: 3044, offset: 0x0000ec1c, length: 0x003df5e8
self_read: process: VNICInstaller_X64.exe, pid: 2636, offset: 0x00000000, length: 0x00038637
self_read: process: VNICInstaller_X64.exe, pid: 2636, offset: 0x0000a01c, length: 0x0002e61f
创建一个隐藏文件或系统文件
file: C:\Program Files (x86)\Sangfor\SSL\Promote\$dpx$.tmp
file: C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\$dpx$.tmp
可疑的样本异常终止
专有的Yara规则检测结果 - 高危
Critical: Spotted potential malicious behaviors from a small size target, like process manipultion, privilege, token and files
将自己装载到Windows开机自动启动项目
service name: SangforTcpDrv_7,5,0,1
service path: C:\Program Files (x86)\Sangfor\SSL\TcpDriver\SangforTcpDrv.sys
service name: SangforDnsDrv_7,5,0,1
service path: C:\Program Files (x86)\Sangfor\SSL\DnsDriver\SangforDnsDrv.sys
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\ImagePath
data: \??\C:\Program Files (x86)\Sangfor\SSL\DnsDriver\SangforDnsDrv.sys
重置WinSock配置
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\StoresServiceClassInfo
data: 0
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\SupportedNameSpace
data: 15
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015\ProtocolName
data: @%SystemRoot%\System32\wshqos.dll,-103
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\ProtocolName
data: SangforLSP_def over [RSVP TCP \xe6\x9c\x8d\xe5\x8a\xa1\xe6\x8f\x90\xe4\xbe\x9b\xe5\x95\x86]
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num
data: 12
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\Enabled
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderId
data: \xa2\xcbJ\x96\xbc\xb2\xeb@\x8cj\xa6\xdb@\x16\x1c\xae
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderInfo
data:
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\LibraryPath
data: %SystemRoot%\System32\mswsock.dll
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\SupportedNameSpace
data: 12
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\00000007
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014\ProtocolName
data: @%SystemRoot%\System32\wshqos.dll,-102
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\LibraryPath
data: C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforNsp.dll
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Version
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Version
data: 0
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\SupportedNameSpace
data: 12
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\PackedCatalogItem
data: %SystemRoot%\system32\mswsock.dll\x00\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00 \x06\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\xc0\xb0\xea\xf9\xd4&\xd0\x11\xbb\xbf\x00\xaa\x00l4\xe4\xed\x03\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x17\x00\x00\x00\x1c\x00\x00\x00\x1c\x00\x00\x00\x02\x00\x00\x00\x11\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xf7\xff\x00\x00\x00\x00\x00\x00@\x00%\x00S\x00y\x00s\x00t\x00e\x00m\x00R\x00o\x00o\x00t\x00%\x00\\x00S\x00y\x00s\x00t\x00e\x00m\x003\x002\x00\\x00w\x00s\x00h\x00i\x00p\x006\x00.\x00d\x00l\x00l\x00,\x00-\x006\x000\x001\x000\x001\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Num_Catalog_Entries
data: 16
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\Version
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\LibraryPath
data: %SystemRoot%\system32\pnrpnsp.dll
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\StoresServiceClassInfo
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\SupportedNameSpace
data: 32
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString
data: @%SystemRoot%\system32\napinsp.dll,-1000
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Num_Catalog_Entries
data: 8
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\ProtocolName
data: @%SystemRoot%\System32\wshtcpip.dll,-60102
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Enabled
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\PackedCatalogItem
data: %SystemRoot%\system32\mswsock.dll\x00\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00f \x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\xe0\xa9`\x9dz3\xd0\x11\xbd\x88\x00\x00\xc0\x82\xe6\x9a\xef\x03\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x17\x00\x00\x00\x1c\x00\x00\x00\x1c\x00\x00\x00\x01\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00@\x00%\x00S\x00y\x00s\x00t\x00e\x00m\x00R\x00o\x00o\x00t\x00%\x00\\x00S\x00y\x00s\x00t\x00e\x00m\x003\x002\x00\\x00w\x00s\x00h\x00q\x00o\x00s\x00.\x00d\x00l\x00l\x00,\x00-\x001\x000\x000\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\ProtocolName
data: @%SystemRoot%\System32\wshtcpip.dll,-60101
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Enabled
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\PackedCatalogItem
data: %SystemRoot%\system32\mswsock.dll\x00\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00 \x06\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x0c\x00\x00\x00\xc0\xb0\xea\xf9\xd4&\xd0\x11\xbb\xbf\x00\xaa\x00l4\xe4\xee\x03\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x17\x00\x00\x00\x1c\x00\x00\x00\x1c\x00\x00\x00\x03\x00\x00\x00\x00\x00\x00\x00\xff\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x80\x00\x00\x00\x00\x00\x00@\x00%\x00S\x00y\x00s\x00t\x00e\x00m\x00R\x00o\x00o\x00t\x00%\x00\\x00S\x00y\x00s\x00t\x00e\x00m\x003\x002\x00\\x00w\x00s\x00h\x00i\x00p\x006\x00.\x00d\x00l\x00l\x00,\x00-\x006\x000\x001\x000\x002\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderId
data: \xce\x89\xfe\x03mvvI\xb9\xc1\xbb\x9b\xc4,{M
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\DisplayString
data: NTDS
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\PackedCatalogItem
data: C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00 \x06\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x0c\x00\x00\x00\xa0\x10f\xbd\xee\xc6,G\xb0\xc9\x90\xc4\x9f,\x02\xe6\xf6\x03\x00\x00\x02\x00\x00\x00\xf3\x03\x00\x00\xeb\x03\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x02\x00\x00\x00\x10\x00\x00\x00\x10\x00\x00\x00\x03\x00\x00\x00\x00\x00\x00\x00\xff\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x80\x00\x00\x00\x00\x00\x00S\x00a\x00n\x00g\x00f\x00o\x00r\x00L\x00S\x00P\x00_\x00d\x00e\x00f\x00 \x00o\x00v\x00e\x00r\x00 \x00[\x00M\x00S\x00A\x00F\x00D\x00 \x00T\x00c\x00p\x00i\x00p\x00 \x00[\x00R\x00A\x00W\x00/\x00I\x00P\x00]\x00]\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\StoresServiceClassInfo
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Version
data: 0
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\StoresServiceClassInfo
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Version
data: 0
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\PackedCatalogItem
data: %SystemRoot%\system32\mswsock.dll\x00\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00 \x06\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x0c\x00\x00\x00\xa0\x1a\x0f\xe7\x8b\xab\xcf\x11\x8c\xa3\x00\x80_H\xa1\x92\xeb\x03\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x02\x00\x00\x00\x10\x00\x00\x00\x10\x00\x00\x00\x03\x00\x00\x00\x00\x00\x00\x00\xff\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x80\x00\x00\x00\x00\x00\x00@\x00%\x00S\x00y\x00s\x00t\x00e\x00m\x00R\x00o\x00o\x00t\x00%\x00\\x00S\x00y\x00s\x00t\x00e\x00m\x003\x002\x00\\x00w\x00s\x00h\x00t\x00c\x00p\x00i\x00p\x00.\x00d\x00l\x00l\x00,\x00-\x006\x000\x001\x000\x002\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014\PackedCatalogItem
data: %SystemRoot%\system32\mswsock.dll\x00\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00 &\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\xe0\xa9`\x9dz3\xd0\x11\xbd\x88\x00\x00\xc0\x82\xe6\x9a\xf1\x03\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x17\x00\x00\x00\x1c\x00\x00\x00\x1c\x00\x00\x00\x02\x00\x00\x00\x11\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xf7\xff\x00\x00\x00\x00\x00\x00@\x00%\x00S\x00y\x00s\x00t\x00e\x00m\x00R\x00o\x00o\x00t\x00%\x00\\x00S\x00y\x00s\x00t\x00e\x00m\x003\x002\x00\\x00w\x00s\x00h\x00q\x00o\x00s\x00.\x00d\x00l\x00l\x00,\x00-\x001\x000\x002\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString
data: @%SystemRoot%\system32\nlasvc.dll,-1000
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderInfo
data:
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\StoresServiceClassInfo
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\PackedCatalogItem
data: C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00f\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\x99^\xbck/\xd2\xe3H\x80Yb(B\x10*\xe3\xf4\x03\x00\x00\x02\x00\x00\x00\xf3\x03\x00\x00\xe9\x03\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x02\x00\x00\x00\x10\x00\x00\x00\x10\x00\x00\x00\x01\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00S\x00a\x00n\x00g\x00f\x00o\x00r\x00L\x00S\x00P\x00_\x00d\x00e\x00f\x00 \x00o\x00v\x00e\x00r\x00 \x00[\x00M\x00S\x00A\x00F\x00D\x00 \x00T\x00c\x00p\x00i\x00p\x00 \x00[\x00T\x00C\x00P\x00/\x00I\x00P\x00]\x00]\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderInfo
data:
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\SupportedNameSpace
data: 37
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\PackedCatalogItem
data: C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00 \x06\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00f\x11L\x8f\xfe\xf2(L\xa3\xcc\xd4\xc3\x1a\x1d\xf1\x1e\xf5\x03\x00\x00\x02\x00\x00\x00\xf3\x03\x00\x00\xea\x03\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x02\x00\x00\x00\x10\x00\x00\x00\x10\x00\x00\x00\x02\x00\x00\x00\x11\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xf7\xff\x00\x00\x00\x00\x00\x00S\x00a\x00n\x00g\x00f\x00o\x00r\x00L\x00S\x00P\x00_\x00d\x00e\x00f\x00 \x00o\x00v\x00e\x00r\x00 \x00[\x00M\x00S\x00A\x00F\x00D\x00 \x00T\x00c\x00p\x00i\x00p\x00 \x00[\x00U\x00D\x00P\x00/\x00I\x00P\x00]\x00]\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013\PackedCatalogItem
data: %SystemRoot%\system32\mswsock.dll\x00\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00f \x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\xe0\xa9`\x9dz3\xd0\x11\xbd\x88\x00\x00\xc0\x82\xe6\x9a\xf0\x03\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x02\x00\x00\x00\x10\x00\x00\x00\x10\x00\x00\x00\x01\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00@\x00%\x00S\x00y\x00s\x00t\x00e\x00m\x00R\x00o\x00o\x00t\x00%\x00\\x00S\x00y\x00s\x00t\x00e\x00m\x003\x002\x00\\x00w\x00s\x00h\x00q\x00o\x00s\x00.\x00d\x00l\x00l\x00,\x00-\x001\x000\x001\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\0000002A
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\00000028
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\00000029
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\ProviderId
data: \xee7&;\x80\xe5\xcf\x11\xa5U\x00\xc0O\xd8\xd4\xac
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\ProtocolName
data: SangforLSP_def over [MSAFD Tcpip [RAW/IP]]
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\StoresServiceClassInfo
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\Enabled
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\SupportedNameSpace
data: 12
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderInfo
data:
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\ProtocolName
data: @%SystemRoot%\System32\wshqos.dll,-100
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString
data: @%SystemRoot%\system32\pnrpnsp.dll,-1001
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016\ProtocolName
data: SangforLSP_def
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\ProviderInfo
data:
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderInfo
data:
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\PackedCatalogItem
data: %SystemRoot%\system32\mswsock.dll\x00\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00f\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\xc0\xb0\xea\xf9\xd4&\xd0\x11\xbb\xbf\x00\xaa\x00l4\xe4\xec\x03\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x17\x00\x00\x00\x1c\x00\x00\x00\x1c\x00\x00\x00\x01\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00@\x00%\x00S\x00y\x00s\x00t\x00e\x00m\x00R\x00o\x00o\x00t\x00%\x00\\x00S\x00y\x00s\x00t\x00e\x00m\x003\x002\x00\\x00w\x00s\x00h\x00i\x00p\x006\x00.\x00d\x00l\x00l\x00,\x00-\x006\x000\x001\x000\x000\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderId
data: :$Bf\xa8;\xa6J\xba\xa5.\x0b\xd7\x1f\xdd\x83
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\0000000A
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\0000000B
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\DisplayString
data: Sangfor SSL Name Space Provider
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num
data: 43
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013\ProtocolName
data: @%SystemRoot%\System32\wshqos.dll,-101
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\ProtocolName
data: @%SystemRoot%\System32\wship6.dll,-60101
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\LibraryPath
data: %SystemRoot%\system32\pnrpnsp.dll
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Next_Catalog_Entry_ID
data: 1017
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\ProtocolName
data: SangforLSP_def over [MSAFD Tcpip [TCP/IP]]
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\SupportedNameSpace
data: 38
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\ProtocolName
data: @%SystemRoot%\System32\wship6.dll,-60102
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\ProtocolName
data: SangforLSP_def over [RSVP UDP \xe6\x9c\x8d\xe5\x8a\xa1\xe6\x8f\x90\xe4\xbe\x9b\xe5\x95\x86]
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\00000008
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\00000009
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\00000005
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\SupportedNameSpace
data: 39
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\PackedCatalogItem
data: C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00f \x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00[L\xea\x08e.\xefD\xbf\x8e^\xb7q\xe9\x8f\xe5\xf7\x03\x00\x00\x02\x00\x00\x00\xf3\x03\x00\x00\xf0\x03\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x02\x00\x00\x00\x10\x00\x00\x00\x10\x00\x00\x00\x01\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00S\x00a\x00n\x00g\x00f\x00o\x00r\x00L\x00S\x00P\x00_\x00d\x00e\x00f\x00 \x00o\x00v\x00e\x00r\x00 \x00[\x00R\x00S\x00V\x00P\x00 \x00T\x00C\x00P\x00 \x00 g\xa1R\xd0c\x9bOFU]\x00\x00\x001\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString
data: @%SystemRoot%\system32\wshtcpip.dll,-60103
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Version
data: 0
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Enabled
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Enabled
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\ProviderId
data: ~\xbd\xa2U0\xbb\xd2\x11\x91f\x00\xa0\xc9\xa7i\x01
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderId
data: @\x9d\x05"\x9e~\xcf\x11\xaeZ\x00\xaa\x00\xa7\x11+
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\LibraryPath
data: C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforNsp.dll
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\ProtocolName
data: @%SystemRoot%\System32\wship6.dll,-60100
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\LibraryPath
data: %SystemRoot%\System32\winrnr.dll
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\LibraryPath
data: %SystemRoot%\system32\NLAapi.dll
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\ProtocolName
data: SangforLSP_def over [MSAFD Tcpip [UDP/IP]]
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\ProtocolName
data: @%SystemRoot%\System32\wshtcpip.dll,-60100
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString
data: @%SystemRoot%\system32\pnrpnsp.dll,-1000
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Enabled
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\ProviderInfo
data:
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015\PackedCatalogItem
data: %SystemRoot%\system32\mswsock.dll\x00\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00 &\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\xe0\xa9`\x9dz3\xd0\x11\xbd\x88\x00\x00\xc0\x82\xe6\x9a\xf2\x03\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x02\x00\x00\x00\x10\x00\x00\x00\x10\x00\x00\x00\x02\x00\x00\x00\x11\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xf7\xff\x00\x00\x00\x00\x00\x00@\x00%\x00S\x00y\x00s\x00t\x00e\x00m\x00R\x00o\x00o\x00t\x00%\x00\\x00S\x00y\x00s\x00t\x00e\x00m\x003\x002\x00\\x00w\x00s\x00h\x00q\x00o\x00s\x00.\x00d\x00l\x00l\x00,\x00-\x001\x000\x003\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderInfo
data:
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\StoresServiceClassInfo
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\PackedCatalogItem
data: %SystemRoot%\system32\mswsock.dll\x00\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00 \x06\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\xa0\x1a\x0f\xe7\x8b\xab\xcf\x11\x8c\xa3\x00\x80_H\xa1\x92\xea\x03\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x02\x00\x00\x00\x10\x00\x00\x00\x10\x00\x00\x00\x02\x00\x00\x00\x11\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xf7\xff\x00\x00\x00\x00\x00\x00@\x00%\x00S\x00y\x00s\x00t\x00e\x00m\x00R\x00o\x00o\x00t\x00%\x00\\x00S\x00y\x00s\x00t\x00e\x00m\x003\x002\x00\\x00w\x00s\x00h\x00t\x00c\x00p\x00i\x00p\x00.\x00d\x00l\x00l\x00,\x00-\x006\x000\x001\x000\x001\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\StoresServiceClassInfo
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016\PackedCatalogItem
data: C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00f\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x04\x00\x00\x00\xd0\xbb\xfa\xc56\x97\xd1\x11\x93\x7f\x00\xc0O\xad\x86 \xf3\x03\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x02\x00\x00\x00\x10\x00\x00\x00\x10\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00S\x00a\x00n\x00g\x00f\x00o\x00r\x00L\x00S\x00P\x00_\x00d\x00e\x00f\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\Version
data: 0
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderId
data: \xcd\x89\xfe\x03mvvI\xb9\xc1\xbb\x9b\xc4,{M
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString
data: Sangfor SSL Name Space Provider
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\PackedCatalogItem
data: %SystemRoot%\system32\mswsock.dll\x00\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00f\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\xa0\x1a\x0f\xe7\x8b\xab\xcf\x11\x8c\xa3\x00\x80_H\xa1\x92\xe9\x03\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x02\x00\x00\x00\x10\x00\x00\x00\x10\x00\x00\x00\x01\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00@\x00%\x00S\x00y\x00s\x00t\x00e\x00m\x00R\x00o\x00o\x00t\x00%\x00\\x00S\x00y\x00s\x00t\x00e\x00m\x003\x002\x00\\x00w\x00s\x00h\x00t\x00c\x00p\x00i\x00p\x00.\x00d\x00l\x00l\x00,\x00-\x006\x000\x001\x000\x000\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\PackedCatalogItem
data: C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforTcp.dll\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00 &\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\xe1\x0ccP^&\xfaC\xa3@-7\x9e\xdbo\x9c\xf8\x03\x00\x00\x02\x00\x00\x00\xf3\x03\x00\x00\xf2\x03\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x02\x00\x00\x00\x10\x00\x00\x00\x10\x00\x00\x00\x02\x00\x00\x00\x11\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xf7\xff\x00\x00\x00\x00\x00\x00S\x00a\x00n\x00g\x00f\x00o\x00r\x00L\x00S\x00P\x00_\x00d\x00e\x00f\x00 \x00o\x00v\x00e\x00r\x00 \x00[\x00R\x00S\x00V\x00P\x00 \x00U\x00D\x00P\x00 \x00 g\xa1R\xd0c\x9bOFU]\x00\x00\x003\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Enabled
data: 1
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\00000006
data: unknown
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\LibraryPath
data: %SystemRoot%\system32\napinsp.dll
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Version
data: 0
key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderId
data: ~\xbd\xa2U0\xbb\xd2\x11\x91f\x00\xa0\xc9\xa7i\x00
模仿Windows系统文件的文件时间信息
mimic_dest: C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforNspX64.dll
mimic_source: C:\Windows\System32\ECPrivacyStatementEn.rtf
mimic_dest: C:\Program Files (x86)\Sangfor\SSL\ClientComponent\InstallControl.exe
mimic_source: C:\Windows\System32\ECPrivacyStatementEn.rtf
mimic_dest: C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SSOClientPrj.dll
mimic_source: C:\Windows\System32\ECPrivacyStatementEn.rtf
尝试创建或更改系统证书
尝试创建或修改一个Browser Helper Object(BHO)组件
可能是恶意的样本写入可疑的执行文件并混淆扩展名
Suspicious: c:\users\test\appdata\local\temp\nso14ba.tmp
Suspicious: c:\users\test\appdata\local\temp\nso14ba.tmp\bg.bmp
Suspicious: c:\users\test\appdata\local\temp\nso14ba.tmp\bg.bmp
Suspicious: c:\users\test\appdata\local\temp\nso14ba.tmp\bg.bmp
Suspicious: c:\users\test\appdata\local\temp\nso14ba.tmp\bg.bmp
Suspicious: c:\users\test\appdata\local\temp\nso14ba.tmp\bg.bmp
Suspicious: c:\users\test\appdata\local\temp\nso14ba.tmp\bg.bmp
Suspicious: c:\users\test\appdata\local\temp\nso14ba.tmp\bg.bmp
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nd_dkey_v2.cab
Suspicious: c:\users\test\appdata\local\temp\nsi4816.tmp
Suspicious: c:\users\test\appdata\local\temp\nsi4816.tmp
Suspicious: c:\users\test\appdata\local\temp\nsi4816.tmp
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\program files (x86)\sangfor\ssl\promote\$dpx$.tmp\428bb0b097d90146b7095fe59d6ab3ea.tmp
Suspicious: c:\program files (x86)\sangfor\ssl\promote\$dpx$.tmp\428bb0b097d90146b7095fe59d6ab3ea.tmp
Suspicious: c:\users\test\appdata\local\temp\nsi4816.tmp
Suspicious: c:\users\test\appdata\local\temp\nsi4816.tmp
Suspicious: c:\users\test\appdata\local\temp\nsi4816.tmp
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\program files (x86)\sangfor\ssl\promote\$dpx$.tmp\428bb0b097d90146b7095fe59d6ab3ea.tmp
Suspicious: c:\program files (x86)\sangfor\ssl\promote\$dpx$.tmp\428bb0b097d90146b7095fe59d6ab3ea.tmp
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsi4816.tmp
Suspicious: c:\users\test\appdata\local\temp\nsi4816.tmp
Suspicious: c:\users\test\appdata\local\temp\nsi4816.tmp
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nddkey\epsnd_m8.inf
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nddkey\epsnd_m8.inf
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nddkey\epsnd_m8.inf
Suspicious: c:\program files (x86)\sangfor\ssl\clientcomponent\nddkey\epsnd_m8.inf
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\program files (x86)\sangfor\ssl\sangforcsclient\mu vpn.ico
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\windows\system32\ecprivacystatementen.rtf
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\nso585c.tmp
Suspicious: c:\users\test\appdata\local\temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\set146e.tmp
Suspicious: c:\users\test\appdata\local\temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\set146e.tmp
Suspicious: c:\users\test\appdata\local\temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\set146e.tmp

运行截图

网络分析

TCP连接

IP地址 端口
23.12.40.160 80

UDP连接

IP地址 端口
192.168.122.1 53

HTTP请求

URL HTTP数据
http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip
GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1
Accept: */*
If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT
User-Agent: IPM
Host: acroipm.adobe.com
Connection: Keep-Alive
Cache-Control: no-cache

静态分析

PE 信息

初始地址 0x00400000
入口地址 0x004036a0
声明校验值 0x00dfbe7f
实际校验值 0x00dfbe7f
最低操作系统版本要求 4.0
编译时间 2009-12-06 06:53:18
载入哈希 dfb06052e74b26a42b0e490bd1c07959

版本信息

LegalCopyright: Copyright (C) 2018
FileVersion: 7.6.7.0
LegalTrademarks: Sangfor Technologies Inc.
ProductName: EasyConnect
ProductVersion: 7,6,7,0
FileDescription: EasyConnect
Translation: 0x0000 0x03a8

PE数据组成

名称 虚拟地址 虚拟大小 原始数据大小 特征 熵(Entropy)
.text 0x00001000 0x000061a4 0x00006200 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6.44
.rdata 0x00008000 0x000011e0 0x00001200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5.31
.data 0x0000a000 0x0001c3f8 0x00000c00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 5.13
.ndata 0x00027000 0x0000f000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0.00
.rsrc 0x00036000 0x0000de60 0x0000e000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 2.30

导入

库 KERNEL32.dll:
0x408060 - CompareFileTime
0x408064 - SearchPathA
0x408068 - GetShortPathNameA
0x40806c - GetFullPathNameA
0x408070 - MoveFileA
0x408074 - SetCurrentDirectoryA
0x408078 - GetFileAttributesA
0x40807c - GetLastError
0x408080 - CreateDirectoryA
0x408084 - SetFileAttributesA
0x408088 - Sleep
0x40808c - GetTickCount
0x408090 - CreateFileA
0x408094 - GetFileSize
0x408098 - GetModuleFileNameA
0x40809c - GetCurrentProcess
0x4080a0 - CopyFileA
0x4080a4 - ExitProcess
0x4080a8 - SetFileTime
0x4080ac - GetTempPathA
0x4080b0 - GetCommandLineA
0x4080b4 - SetErrorMode
0x4080b8 - LoadLibraryA
0x4080bc - lstrcpynA
0x4080c0 - GetDiskFreeSpaceA
0x4080c4 - GlobalUnlock
0x4080c8 - GlobalLock
0x4080cc - CreateThread
0x4080d0 - CreateProcessA
0x4080d4 - RemoveDirectoryA
0x4080d8 - GetTempFileNameA
0x4080dc - lstrlenA
0x4080e0 - lstrcatA
0x4080e4 - GetSystemDirectoryA
0x4080e8 - GetVersion
0x4080ec - CloseHandle
0x4080f0 - lstrcmpiA
0x4080f4 - lstrcmpA
0x4080f8 - ExpandEnvironmentStringsA
0x4080fc - GlobalFree
0x408100 - GlobalAlloc
0x408104 - WaitForSingleObject
0x408108 - GetExitCodeProcess
0x40810c - GetModuleHandleA
0x408110 - LoadLibraryExA
0x408114 - GetProcAddress
0x408118 - FreeLibrary
0x40811c - MultiByteToWideChar
0x408120 - WritePrivateProfileStringA
0x408124 - GetPrivateProfileStringA
0x408128 - WriteFile
0x40812c - ReadFile
0x408130 - SetFilePointer
0x408134 - MulDiv
0x408138 - FindClose
0x40813c - FindNextFileA
0x408140 - FindFirstFileA
0x408144 - DeleteFileA
0x408148 - GetWindowsDirectoryA
库 USER32.dll:
0x40816c - EndDialog
0x408170 - ScreenToClient
0x408174 - GetWindowRect
0x408178 - EnableMenuItem
0x40817c - GetSystemMenu
0x408180 - SetClassLongA
0x408184 - IsWindowEnabled
0x408188 - SetWindowPos
0x40818c - GetSysColor
0x408190 - GetWindowLongA
0x408194 - SetCursor
0x408198 - LoadCursorA
0x40819c - CheckDlgButton
0x4081a0 - GetAsyncKeyState
0x4081a4 - IsDlgButtonChecked
0x4081a8 - GetMessagePos
0x4081ac - LoadBitmapA
0x4081b0 - CallWindowProcA
0x4081b4 - IsWindowVisible
0x4081b8 - CloseClipboard
0x4081bc - SetClipboardData
0x4081c0 - RegisterClassA
0x4081c4 - OpenClipboard
0x4081c8 - TrackPopupMenu
0x4081cc - AppendMenuA
0x4081d0 - CreatePopupMenu
0x4081d4 - GetSystemMetrics
0x4081d8 - SetDlgItemTextA
0x4081dc - GetDlgItemTextA
0x4081e0 - MessageBoxIndirectA
0x4081e4 - CharPrevA
0x4081e8 - wvsprintfA
0x4081ec - DispatchMessageA
0x4081f0 - PeekMessageA
0x4081f4 - DestroyWindow
0x4081f8 - CreateDialogParamA
0x4081fc - SetTimer
0x408200 - SetWindowTextA
0x408204 - PostQuitMessage
0x408208 - ShowWindow
0x40820c - wsprintfA
0x408210 - SendMessageTimeoutA
0x408214 - FindWindowExA
0x408218 - SystemParametersInfoA
0x40821c - CreateWindowExA
0x408220 - GetClassInfoA
0x408224 - DialogBoxParamA
0x408228 - CharNextA
0x40822c - EmptyClipboard
0x408230 - ExitWindowsEx
0x408234 - IsWindow
0x408238 - GetDlgItem
0x40823c - SetWindowLongA
0x408240 - LoadImageA
0x408244 - GetDC
0x408248 - EnableWindow
0x40824c - InvalidateRect
0x408250 - SendMessageA
0x408254 - DefWindowProcA
0x408258 - BeginPaint
0x40825c - GetClientRect
0x408260 - FillRect
0x408264 - DrawTextA
0x408268 - EndPaint
0x40826c - SetForegroundWindow
库 GDI32.dll:
0x40803c - SetBkColor
0x408040 - GetDeviceCaps
0x408044 - DeleteObject
0x408048 - CreateBrushIndirect
0x40804c - CreateFontIndirectA
0x408050 - SetBkMode
0x408054 - SetTextColor
0x408058 - SelectObject
库 SHELL32.dll:
0x408150 - SHGetPathFromIDListA
0x408154 - SHBrowseForFolderA
0x408158 - SHGetFileInfoA
0x40815c - ShellExecuteA
0x408160 - SHFileOperationA
0x408164 - SHGetSpecialFolderLocation
库 ADVAPI32.dll:
0x408000 - RegQueryValueExA
0x408004 - RegSetValueExA
0x408008 - RegEnumKeyA
0x40800c - RegEnumValueA
0x408010 - RegOpenKeyExA
0x408014 - RegDeleteKeyA
0x408018 - RegDeleteValueA
0x40801c - RegCloseKey
0x408020 - RegCreateKeyExA
库 COMCTL32.dll:
0x408028 - ImageList_AddMasked
0x40802c - ImageList_Destroy
0x408030 - None
0x408034 - ImageList_Create
库 ole32.dll:
0x408284 - CoTaskMemFree
0x408288 - OleInitialize
0x40828c - OleUninitialize
0x408290 - CoCreateInstance
库 VERSION.dll:
0x408274 - GetFileVersionInfoSizeA
0x408278 - GetFileVersionInfoA
0x40827c - VerQueryValueA

投放文件

无信息

行为分析

互斥量(Mutexes)
  • Global\SSLUSR_LOGIN
  • Global\__EASYCONNECT_MUTEX__
  • Global\Sslvpn_Install_Mutext
  • Local\MSCTF.Asm.MutexDefault1
  • DBWinMutex
  • Global\Sangfor_CSClient_Mutex_Lock
  • Global\SSO_MUTEX_LOCKER_1
  • Global\SANGFOR_NSP_RULE_MUTEX
  • Global\WdsSetupLogInit
  • Global\SetupLog
  • Global\NetCfgWriteLock
  • Global\d3b1bbc7-c020-4056-9ded-7c6f40b5a2fc
执行的命令
  • "C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Uninstall.exe" -QUICKREPAIR -HIDE -NODELSESSION -SessionId=-1
  • "C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforCSClientInstaller.exe" -SessionId=-1
  • "C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforECPluginInstaller.exe" -ShowMode=DoNotShow -SessionId=-1
  • "C:\Program Files (x86)\Sangfor\SSL\ClientComponent\TcpDriverInstaller.exe" -SessionId=-1
  • "C:\Program Files (x86)\Sangfor\SSL\ClientComponent\DnsDriverInstaller.exe" -SessionId=-1
  • "C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SuperExeInstaller.exe" -SessionId=-1
  • "C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforServiceClientInstaller.exe" -SessionId=-1
  • "C:\Program Files (x86)\Sangfor\SSL\ClientComponent\VC2010RedistX86UInstaller.exe"
  • "C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SJobberInstaller.exe" -SessionId=-1
  • "C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforUpdateInstaller.exe" -SessionId=-1
  • "C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforRAppInstaller.exe" -SessionId=-1
  • "C:\Program Files (x86)\Sangfor\SSL\ClientComponent\InstallControl.exe" -SessionId=-1
  • "C:\Program Files (x86)\Sangfor\SSL\TcpDriver\Remove.exe"
  • "C:\Program Files (x86)\Sangfor\SSL\TcpDriver\Install.exe"
  • C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
  • "C:\Program Files (x86)\Sangfor\SSL\DnsDriver\Remove.exe"
  • "C:\Program Files (x86)\Sangfor\SSL\DnsDriver\Install.exe"
  • "expand.exe" -r "C:\Program Files (x86)\Sangfor\SSL\Promote\SangforPromote.CAB" "C:\Program Files (x86)\Sangfor\SSL\Promote"
  • "expand.exe" -r "C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\SangforServiceClient.CAB" "C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient"
  • "C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\ndiscleanup.x64.exe"
创建的服务
  • SangforTcpDrv_7,5,0,1
  • SangforDnsDrv_7,5,0,1
启动的服务
  • SangforTcpDrv_7,5,0,1
  • SangforDnsDrv_7,5,0,1
  • wudfsvc

进程

EasyConnectInstaller.exe PID: 2612, 上一级进程 PID: 2264

Uninstall.exe PID: 3060, 上一级进程 PID: 2612

SangforCSClientInstaller.exe PID: 2400, 上一级进程 PID: 2612

TcpDriverInstaller.exe PID: 2716, 上一级进程 PID: 2612

Remove.exe PID: 2924, 上一级进程 PID: 2716

Install.exe PID: 2360, 上一级进程 PID: 2716

services.exe PID: 424, 上一级进程 PID: 328

DnsDriverInstaller.exe PID: 2188, 上一级进程 PID: 2612

Remove.exe PID: 2184, 上一级进程 PID: 2188

Install.exe PID: 2556, 上一级进程 PID: 2188

SuperExeInstaller.exe PID: 2756, 上一级进程 PID: 2612

expand.exe PID: 2976, 上一级进程 PID: 2756

SangforServiceClientInstaller.exe PID: 2288, 上一级进程 PID: 2612

expand.exe PID: 2536, 上一级进程 PID: 2288

VC2010RedistX86UInstaller.exe PID: 2528, 上一级进程 PID: 2612

SJobberInstaller.exe PID: 2440, 上一级进程 PID: 2612

SangforUpdateInstaller.exe PID: 2968, 上一级进程 PID: 2612

SangforRAppInstaller.exe PID: 3044, 上一级进程 PID: 2612

InstallControl.exe PID: 2572, 上一级进程 PID: 2612

VNICInstaller_X64.exe PID: 2636, 上一级进程 PID: 2612

ndiscleanup.x64.exe PID: 2984, 上一级进程 PID: 2636

vacon.exe PID: 3032, 上一级进程 PID: 2636

svchost.exe PID: 1116, 上一级进程 PID: 424

访问的文件
  • \Device\KsecDD
  • C:\Users\test\AppData\Local\Temp\SHFOLDER.DLL
  • C:\Windows\System32\shfolder.dll
  • \??\MountPointManager
  • C:\Users\test\AppData\Local\Temp\
  • C:\Users\test\AppData\Local\Temp
  • C:\Users\test\AppData\Local\Temp\nsy1370.tmp
  • C:\Users\test\AppData\Local\Temp\EasyConnectInstaller.exe
  • C:\Users
  • C:\Users\test
  • C:\Users\test\AppData
  • C:\Users\test\AppData\Local
  • C:\Users\test\AppData\Local\Temp\nsy14A9.tmp
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\install.log
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\System.dll
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\bg.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\progress_b.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\progress_h.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\btn_close.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\btn_mini.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\btn_finish_en.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\btn_finish_cn.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\SkinBtn.dll
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\MSIMG32.dll
  • C:\Windows\System32\msimg32.dll
  • C:\Windows
  • C:\Windows\System32
  • C:\Windows\System32\SangforInstallHelper.dll.old
  • C:\
  • C:\Windows\System32\SangforInstallHelper.dll
  • C:\Windows\System32\SangforInstallHelper.dll\*.*
  • C:\Windows\System32\SangforInstallHelper.dll.old\*.*
  • C:\Windows\System32\ECPrivacyStatementEn.rtf
  • C:\Windows\System32\ECPrivacyStatementCn.rtf
  • C:\Windows\win.ini
  • C:\Windows\SysWOW64\ECPrivacyStatementCn.rtf
  • C:\Windows\Fonts\staticcache.dat
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\dbdStaticCtrl.dll
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\SkinProgress.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent
  • C:\Program Files (x86)
  • C:\Program Files (x86)\Sangfor
  • C:\Program Files (x86)\Sangfor\SSL
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Uninstall.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\nd_dkey_v2.CAB
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\nd_dkey_v2_win8.CAB
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\InstallControl.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SuperExeInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SuperServiceInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforServiceClientInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforCSClientInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\VNICInstaller_X64.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\VNICInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforL3Vpn.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforNsp.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforNspX64.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforSddn.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforTcp.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\CSClientManagerPrj.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforCore.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforBHO.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SSOClientPrj.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SJobberInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforUpdateInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforRAppInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\UrlWarrent.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\VC2010RedistX86UInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\ComHelperX64.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforCDC.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\TcpDriverInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\ECBaseInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\ECAgentInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\DnsDriverInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\MFC42.DLL
  • C:\Windows\System32\mfc42.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\ODBC32.dll
  • C:\Windows\System32\odbc32.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\OLEPRO32.DLL
  • C:\Windows\System32\olepro32.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\MSVCP60.dll
  • C:\Windows\System32\msvcp60.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\iphlpapi.dll
  • C:\Windows\System32\IPHLPAPI.DLL
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\WINNSI.DLL
  • C:\Windows\System32\winnsi.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\WINHTTP.dll
  • C:\Windows\System32\winhttp.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\webio.dll
  • C:\Windows\System32\webio.dll
  • C:\Windows\winsxs\FileMaps\program_files_x86_sangfor_ssl_clientcomponent_2998b44ff547c156.cdf-ms
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\CABINET.DLL
  • C:\Windows\System32\cabinet.dll
  • C:\Users\test\AppData\Roaming\Sangfor\SSL\Log\SangforCore.dll.log
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\dbghelp.dll
  • C:\Windows\System32\dbghelp.dll
  • \Device\NamedPipe\
  • \Device\NamedPipe\\WINSOCK2\CATALOGCHANGELISTENER-*-*
  • \Device\NamedPipe\Winsock2\CatalogChangeListener-264-0
  • \Device\NamedPipe\Winsock2\CatalogChangeListener-148-0
  • \Device\NamedPipe\Winsock2\CatalogChangeListener-2bc-0
  • \Device\NamedPipe\Winsock2\CatalogChangeListener-314-0
  • \Device\NamedPipe\Winsock2\CatalogChangeListener-1b0-0
  • \Device\NamedPipe\Winsock2\CatalogChangeListener-1a8-0
  • C:\Windows\System32\nlasvc.dll
  • C:\Windows\System32\nlasvc.dll.DLL
  • C:\Windows\sysnative\nlasvc.dll
  • C:\Windows\System32\NapiNSP.dll
  • C:\Windows\System32\pnrpnsp.dll
  • C:\Windows\System32\WSHTCPIP.DLL
  • C:\Windows\System32\tzres.dll
  • C:\Windows\System32\wship6.dll
  • C:\Windows\System32\wshqos.dll
  • C:\Users\test\AppData\Roaming\Sangfor\SSL\Log\SangforL3Vpn.dll.log
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\IPHLPAPI.DLL
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\ATL100.DLL
  • C:\Windows\System32\ATL100.DLL
  • C:\Windows\system\ATL100.DLL
  • C:\Windows\ATL100.DLL
  • C:\ProgramData\Oracle\Java\javapath\ATL100.DLL
  • C:\Windows\System32\wbem\ATL100.DLL
  • C:\Windows\System32\WindowsPowerShell\v1.0\ATL100.DLL
  • C:\Program Files (x86)\WinRAR\ATL100.DLL
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforECPluginInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforECPluginInstaller.exe.exe
  • \??\Global\.tap
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SHFOLDER.DLL
  • C:\Users\test\AppData\Local\Temp\nso42BA.tmp
  • C:\Users\test\AppData\Local\Temp\nst42DA.tmp
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\SangforCSClient.exe.old
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\SangforCSClient.exe
  • C:\Users\test\AppData\Local\Temp\nsi42EA.tmp
  • C:\Users\test\AppData\Local\Temp\nsi42EA.tmp\KillProcDLL.dll
  • C:\Windows\System32\SangforVpnLibeay32.dll.old
  • C:\Windows\System32\SangforVpnSsleay32.dll.old
  • C:\Windows\System32\SangforVpnLibeay32.dll
  • C:\Windows\System32\SangforVpnSsleay32.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\SangforVpnLibeay32.dll.old
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\SangforVpnSsleay32.dll.old
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\SangforVpnLibeay32.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\SangforVpnSsleay32.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\epass.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\MU VPN.ico
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\Offline.ico
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\LogoutTimeOut.exe
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\Uninstall.exe
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\FT_ND_API.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\USBKeyManager.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\SangforDKeyMonitor.exe
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\ShuttleCsp11_3000GM.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\SangforCSClientUninstaller.exe
  • C:\Users\test\AppData\Local\Temp\nsi42EA.tmp\System.dll
  • C:\Users\Public\Desktop\MU VPN.lnk
  • C:\Users\Public\Desktop
  • C:\Users\Public
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MU VPN\\xe5\x90\xaf\xe5\x8a\xa8MU VPN.lnk
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MU VPN
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs
  • C:\ProgramData\Microsoft\Windows\Start Menu
  • C:\ProgramData\Microsoft\Windows
  • C:\ProgramData\Microsoft
  • C:\ProgramData
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MU VPN\\xe5\x8d\xb8\xe8\xbd\xbdMU VPN.lnk
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSLVPN\xe7\x99\xbb\xe5\xbd\x95\xe5\xae\xa2\xe6\x88\xb7\xe7\xab\xaf\\xe5\x90\xaf\xe5\x8a\xa8MU VPN.lnk
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSLVPN\xe7\x99\xbb\xe5\xbd\x95\xe5\xae\xa2\xe6\x88\xb7\xe7\xab\xaf
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSLVPN\xe7\x99\xbb\xe5\xbd\x95\xe5\xae\xa2\xe6\x88\xb7\xe7\xab\xaf\\xe5\x8d\xb8\xe8\xbd\xbdMU VPN.lnk
  • \??\PIPE\srvsvc
  • C:\DosDevices\pipe\
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\
  • C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
  • C:\Windows\SysWOW64\propsys.dll
  • C:\Windows\sysnative\propsys.dll
  • C:\Users\test\AppData\Local\Temp\nsi42EA.tmp\*.*
  • C:\Users\test\AppData\Local\Temp\nsi42EA.tmp\
  • C:\Users\test\AppData\Local\Temp\nsi4816.tmp
  • C:\Users\test\AppData\Local\Temp\nsy4837.tmp
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrv.sys
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrvX64.sys
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrv_win7.sys
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrv_win7X64.sys
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrv_ARM64.sys
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\Install.exe
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\Remove.exe
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\SangforTcpDrv.sys
  • C:\Users\test\AppData\Local\Temp\nsd497F.tmp
  • C:\Users\test\AppData\Local\Temp\nsd497F.tmp\System.dll
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\TcpDriverUnInstaller.exe
  • C:\Users\test\AppData\Local\Temp\nsd497F.tmp\*.*
  • C:\Users\test\AppData\Local\Temp\nsd497F.tmp\
  • C:\Windows\Temp
  • C:\Users\test\AppData\Local\Temp\nso585C.tmp
  • C:\Users\test\AppData\Local\Temp\nsi588B.tmp
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\DnsDrv.sys
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\DnsDrvx64.sys
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\DnsDrv_ARM64.sys
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\Install.exe
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\Remove.exe
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\SangforDnsDrv.sys
  • C:\Users\test\AppData\Local\Temp\nst5A51.tmp
  • C:\Users\test\AppData\Local\Temp\nst5A51.tmp\System.dll
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\UnDnsDriverInstaller.exe
  • C:\Users\test\AppData\Local\Temp\nst5A51.tmp\*.*
  • C:\Users\test\AppData\Local\Temp\nst5A51.tmp\
  • C:\Users\test\AppData\Local\Temp\nsd5DE7.tmp
  • C:\Users\test\AppData\Local\Temp\nsi5E07.tmp
  • C:\Program Files (x86)\Sangfor\SSL\Promote
  • C:\Program Files (x86)\Sangfor\SSL\Promote\SangforPromote.exe.old
  • C:\Program Files (x86)\Sangfor\SSL\Promote\SangforPromote.exe
  • C:\Program Files (x86)\Sangfor\SSL\Promote\SangforPromote.CAB
  • C:\Users\test\AppData\Local\Temp\nsd5E37.tmp
  • C:\Users\test\AppData\Local\Temp\nsd5E37.tmp\nsExec.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\expand.exe
  • C:\Program Files (x86)\Sangfor\SSL\Promote\expand.exe
  • C:\Windows\System32\expand.exe
  • C:\Program Files (x86)\Sangfor\SSL\Promote\msvcp60.dll
  • C:\Program Files (x86)\Sangfor\SSL\Promote\PromoteUninstall.exe
  • C:\Users\test\AppData\Local\Temp\nsd5E37.tmp\*.*
  • C:\Users\test\AppData\Local\Temp\nsd5E37.tmp\
  • C:\program files (x86)\Sangfor\SSL\Promote\sangforpromote.cab
  • C:\Windows\Logs\DPX
  • C:\Windows\Logs\DPX\setupact.log
  • C:\Windows\Logs\DPX\setuperr.log
  • C:\Windows\Logs\DPX\setuplog.cfg
  • C:\Program Files (x86)\Sangfor\SSL\Promote\$dpx$.tmp
  • C:\Program Files (x86)\Sangfor\SSL\Promote\$dpx$.tmp\*.tmp
  • C:\Program Files (x86)\Sangfor\SSL\Promote\$dpx$.tmp\job.xml
  • C:\Program Files (x86)\Sangfor\SSL\Promote\$dpx$.tmp\428bb0b097d90146b7095fe59d6ab3ea.tmp
  • C:\Users\test\AppData\Local\Temp\nso6306.tmp
  • C:\Users\test\AppData\Local\Temp\nst6326.tmp
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\SangforServiceClient.CAB
  • C:\Users\test\AppData\Local\Temp\nsy6346.tmp
  • C:\Users\test\AppData\Local\Temp\nsy6346.tmp\nsExec.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\expand.exe
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\SangforServiceClientUninstaller.exe
  • C:\Users\test\AppData\Local\Temp\nsy6346.tmp\*.*
  • C:\Users\test\AppData\Local\Temp\nsy6346.tmp\
  • C:\program files (x86)\Sangfor\SSL\sangforserviceclient\sangforserviceclient.cab
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\$dpx$.tmp
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\$dpx$.tmp\*.tmp
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\$dpx$.tmp\job.xml
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\$dpx$.tmp\ac02676b1b7e4a4883646cdb7cc03183.tmp
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\SangforServiceClient.exe
  • C:\Users\test\AppData\Local\Temp\nsi6814.tmp
  • C:\Users\test\AppData\Local\Temp\nsd6844.tmp
  • C:\Windows\System32\atl100.dll
  • C:\Windows\System32\mfc100chs.dll
  • C:\Windows\System32\mfc100u.dll
  • C:\Windows\System32\msvcp100.dll
  • C:\Windows\System32\msvcr100.dll
  • C:\Users\test\AppData\Local\Temp\nsy6D04.tmp
  • C:\Users\test\AppData\Local\Temp\nsd6D24.tmp
  • C:\Program Files (x86)\Sangfor\SSL\SvpnJobber
  • C:\Program Files (x86)\Sangfor\SSL\SvpnJobber\SvpnJobber.exe
  • C:\Program Files (x86)\Sangfor\SSL\SvpnJobber\SJobberUninstaller.exe
  • C:\Users\test\AppData\Local\Temp\nsj6F65.tmp
  • C:\Users\test\AppData\Local\Temp\nso6F85.tmp
  • C:\Program Files (x86)\Sangfor\SSL\SangforUpdate
  • C:\Program Files (x86)\Sangfor\SSL\SangforUpdate\SangforUD.exe.old
  • C:\Program Files (x86)\Sangfor\SSL\SangforUpdate\SangforUD.exe
  • C:\Program Files (x86)\Sangfor\SSL\SangforUpdate\Uninstaller.exe
  • C:\Users\test\AppData\Local\Temp\nso72DE.tmp
  • C:\Users\test\AppData\Local\Temp\nsd733C.tmp
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\SfRemoteAppClient.exe
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\SfRemoteAppClientHost.exe
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\SangforPDF.exe
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\SfRemoteAppSession.exe
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\mstscax.dll
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\libsrapc.dll
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\libngs.dll
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\SRAPSession.exe
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\librdpclip.dll
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\librdpdr.dll
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\librdpsnd.dll
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\en-US
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\en-US\mstscax.dll.mui
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\zh-CN
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\zh-CN\mstscax.dll.mui
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\SfRemoteAppClientHook.dll
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\Uninstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\*
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\nd_dkey_v2.cab
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\
  • C:\Windows\inf\
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\epsnd_m8.inf
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\FT_ND_API.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\FT_ND_FULL.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\FT_ND_MOD.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\FT_ND_SC.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\HID.DLL
  • C:\Windows\System32\hid.dll
  • C:\Windows\winsxs\FileMaps\program_files_x86_sangfor_ssl_clientcomponent_nddkey_01822eea1dd58e17.cdf-ms
  • C:\Users\test\AppData\Local\Temp\nso821A.tmp
  • C:\Users\test\AppData\Local\Temp\nst823A.tmp
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\install.log
  • C:\Program Files (x86)\Sangfor\SSL\CSClient
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic.inf
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic2003.inf
  • C:\Users\test\AppData\Local\Temp\nsj8299.tmp
  • C:\Users\test\AppData\Local\Temp\nsj8299.tmp\System.dll
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic.cat
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic2003.cat
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic.sys
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\vacon.exe
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SetIPTime.exe
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforCertificate.cer
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforCertificate256.cer
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\ndiscleanup.x64.exe
  • C:\Users\test\AppData\Local\Temp\nsj8299.tmp\nsExec.dll
  • \Device\NamedPipe
  • \??\Nsi
  • C:\Users\test\AppData\Roaming\Sangfor\SSL\Log
  • C:\Windows\sysnative\DriverStore\infpub.dat
  • C:\Windows\sysnative\DriverStore\infstor.dat
  • C:\Windows\sysnative\DriverStore\infstrng.dat
  • C:\Windows\sysnative\DriverStore\drvindex.dat
  • C:\Windows\sysnative\DriverStore\INFCACHE.0
  • C:\Windows\sysnative\DriverStore\INFCACHE.1
  • C:\Windows\sysnative\DriverStore\INFCACHE.2
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVNIC.inf
  • C:\Windows\inf\setupapi.app.log
  • C:\Windows\sysnative\netcfgx.dll
  • C:\Windows\sysnative\NetCfgx.dll.Manifest
  • C:\Windows\sysnative\nci.dll
  • C:\Windows\sysnative\nci.dll.Manifest
  • C:\Windows\sysnative\wlaninst.dll
  • C:\Windows\sysnative\wlaninst.dll.Manifest
  • C:\Windows\sysnative\wwaninst.dll
  • C:\Windows\sysnative\wwaninst.dll.Manifest
  • C:\Windows\inf\setupapi.dev.log
  • C:\program files (x86)\Sangfor\SSL\CSClient\VNIC\sangforvnic.inf
  • C:\program files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic.cat
  • C:\Windows\inf\oem*.inf
  • C:\Windows\inf\sangforvnic.inf
  • C:\Windows\sysnative\DriverStore
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SangforVnic.cat
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\sangforvnic.inf
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SangforVnic.sys
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\
  • C:\program files (x86)\Sangfor\SSL\CSClient\VNIC\
  • C:\program files (x86)
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SET146E.tmp
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\sangforvnic.inf
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SET1598.tmp
  • C:\program files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic.sys
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SET16C1.tmp
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\*
  • C:\Windows\sysnative\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\
  • C:\Windows\sysnative\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\
  • C:\Windows\sysnative\catroot2\dberr.txt
  • C:\Windows\sysnative\catroot
  • C:\Windows\sysnative\catroot2
  • C:\Windows\inf\oem2.inf
  • C:\Windows\sysnative\DriverStore\FileRepository\sangforvnic.inf_amd64_neutral_9183b83f3b2f3cd1\sangforvnic.inf
  • C:\Windows\sysnative\DriverStore\FileRepository\sangforvnic.inf_amd64_neutral_9183b83f3b2f3cd1\sangforvnic.PNF
  • C:\Windows\sysnative\DriverStore\FileRepository\sangforvnic.inf_amd64_neutral_9183b83f3b2f3cd1\SangforVnic.cat
  • C:\Users\test\AppData\LocalLow
  • C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_*
  • C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9A19ADAD9D098E039450ABBEDD5616EB_*
  • C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B90B117906B8A74C79D1BC450C2B94B1_*
  • C:\Windows\system32\LogFiles\WUDF
读取的文件
  • \Device\KsecDD
  • C:\Windows\System32\shfolder.dll
  • C:\Users\test\AppData\Local\Temp\nsy1370.tmp
  • C:\Users\test\AppData\Local\Temp\EasyConnectInstaller.exe
  • C:\Users\test\AppData\Local\Temp\nsy14A9.tmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\System.dll
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\SkinBtn.dll
  • C:\Windows\System32\msimg32.dll
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\btn_close.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\btn_mini.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\btn_finish_en.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\btn_finish_cn.bmp
  • C:\Windows\win.ini
  • C:\Windows\SysWOW64\ECPrivacyStatementCn.rtf
  • C:\Windows\Fonts\staticcache.dat
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\dbdStaticCtrl.dll
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\SkinProgress.dll
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\progress_h.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\progress_b.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\bg.bmp
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\CSClientManagerPrj.dll
  • C:\Windows\System32\mfc42.dll
  • C:\Windows\System32\odbc32.dll
  • C:\Windows\System32\olepro32.dll
  • C:\Windows\System32\msvcp60.dll
  • C:\Windows\System32\IPHLPAPI.DLL
  • C:\Windows\System32\winnsi.dll
  • C:\Windows\System32\winhttp.dll
  • C:\Windows\System32\webio.dll
  • C:\Windows\winsxs\FileMaps\program_files_x86_sangfor_ssl_clientcomponent_2998b44ff547c156.cdf-ms
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforCore.dll
  • C:\Windows\System32\cabinet.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforBHO.dll
  • C:\Windows\System32\dbghelp.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SSOClientPrj.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforNsp.dll
  • \Device\NamedPipe\
  • C:\Windows\sysnative\nlasvc.dll
  • C:\Windows\System32\NapiNSP.dll
  • C:\Windows\System32\pnrpnsp.dll
  • C:\Windows\System32\WSHTCPIP.DLL
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforTcp.dll
  • C:\Windows\System32\tzres.dll
  • C:\Windows\System32\wship6.dll
  • C:\Windows\System32\wshqos.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforL3Vpn.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforSddn.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\UrlWarrent.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforCDC.dll
  • \??\Global\.tap
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Users\test\AppData\Local\Temp\nso42BA.tmp
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforCSClientInstaller.exe
  • C:\Users\test\AppData\Local\Temp\nst42DA.tmp
  • C:\Users\test\AppData\Local\Temp\nsi42EA.tmp
  • C:\Users\test\AppData\Local\Temp\nsi42EA.tmp\KillProcDLL.dll
  • C:\Users\test\AppData\Local\Temp\nsi42EA.tmp\System.dll
  • C:\
  • C:\Program Files (x86)
  • C:\Program Files (x86)\Sangfor
  • C:\Program Files (x86)\Sangfor\SSL
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient
  • \??\PIPE\srvsvc
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\SangforCSClient.exe
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MU VPN\\xe5\x90\xaf\xe5\x8a\xa8MU VPN.lnk
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\SangforCSClientUninstaller.exe
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MU VPN\\xe5\x8d\xb8\xe8\xbd\xbdMU VPN.lnk
  • C:\Users\Public\Desktop\MU VPN.lnk
  • C:\Users\test\AppData\Local\Temp\nsi4816.tmp
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\TcpDriverInstaller.exe
  • C:\Users\test\AppData\Local\Temp\nsy4837.tmp
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrv_win7.sys
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrv_win7X64.sys
  • C:\Users\test\AppData\Local\Temp\nsd497F.tmp
  • C:\Users\test\AppData\Local\Temp\nsd497F.tmp\System.dll
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrvX64.sys
  • C:\Users\test\AppData\Local\Temp\nso585C.tmp
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\DnsDriverInstaller.exe
  • C:\Users\test\AppData\Local\Temp\nsi588B.tmp
  • C:\Users\test\AppData\Local\Temp\nst5A51.tmp
  • C:\Users\test\AppData\Local\Temp\nst5A51.tmp\System.dll
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\DnsDrvx64.sys
  • C:\Users\test\AppData\Local\Temp\nsd5DE7.tmp
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SuperExeInstaller.exe
  • C:\Users\test\AppData\Local\Temp\nsi5E07.tmp
  • C:\Users\test\AppData\Local\Temp\nsd5E37.tmp
  • C:\Users\test\AppData\Local\Temp\nsd5E37.tmp\nsExec.dll
  • C:\program files (x86)\Sangfor\SSL\Promote\sangforpromote.cab
  • C:\Windows\Logs\DPX\setupact.log
  • C:\Windows\Logs\DPX\setuperr.log
  • C:\Windows\Logs\DPX\setuplog.cfg
  • C:\Users\test\AppData\Local\Temp\nso6306.tmp
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforServiceClientInstaller.exe
  • C:\Users\test\AppData\Local\Temp\nst6326.tmp
  • C:\Users\test\AppData\Local\Temp\nsy6346.tmp
  • C:\Users\test\AppData\Local\Temp\nsy6346.tmp\nsExec.dll
  • C:\program files (x86)\Sangfor\SSL\sangforserviceclient\sangforserviceclient.cab
  • C:\Users\test\AppData\Local\Temp\nsi6814.tmp
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\VC2010RedistX86UInstaller.exe
  • C:\Users\test\AppData\Local\Temp\nsd6844.tmp
  • C:\Users\test\AppData\Local\Temp\nsy6D04.tmp
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SJobberInstaller.exe
  • C:\Users\test\AppData\Local\Temp\nsd6D24.tmp
  • C:\Users\test\AppData\Local\Temp\nsj6F65.tmp
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforUpdateInstaller.exe
  • C:\Users\test\AppData\Local\Temp\nso6F85.tmp
  • C:\Users\test\AppData\Local\Temp\nso72DE.tmp
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforRAppInstaller.exe
  • C:\Users\test\AppData\Local\Temp\nsd733C.tmp
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\nd_dkey_v2.CAB
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\epsnd_m8.inf
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\FT_ND_API.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\FT_ND_FULL.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\FT_ND_MOD.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\FT_ND_SC.dll
  • C:\Windows\System32\hid.dll
  • C:\Windows\winsxs\FileMaps\program_files_x86_sangfor_ssl_clientcomponent_nddkey_01822eea1dd58e17.cdf-ms
  • C:\Users\test\AppData\Local\Temp\nso821A.tmp
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\VNICInstaller_X64.exe
  • C:\Users\test\AppData\Local\Temp\nst823A.tmp
  • C:\Users\test\AppData\Local\Temp\nsj8299.tmp
  • C:\Users\test\AppData\Local\Temp\nsj8299.tmp\System.dll
  • C:\Users\test\AppData\Local\Temp\nsj8299.tmp\nsExec.dll
  • C:\Program Files (x86)\Sangfor\SSL\CSClient
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic2003.inf
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic.inf
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic2003.cat
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic.cat
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforCertificate.cer
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforCertificate256.cer
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVNIC.inf
  • C:\Windows\inf\setupapi.app.log
  • C:\Windows\sysnative\netcfgx.dll
  • C:\Windows\sysnative\nci.dll
  • C:\Windows\sysnative\wlaninst.dll
  • C:\Windows\sysnative\wwaninst.dll
  • C:\Windows\inf\setupapi.dev.log
  • C:\program files (x86)\Sangfor\SSL\CSClient\VNIC\sangforvnic.inf
  • C:\program files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic.cat
  • C:\Windows\sysnative\DriverStore\infpub.dat
  • C:\Windows\sysnative\DriverStore\infstrng.dat
  • C:\Windows\sysnative\DriverStore\infstor.dat
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SET146E.tmp
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SET1598.tmp
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic.sys
  • C:\program files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic.sys
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SET16C1.tmp
  • C:\Windows\sysnative\catroot2\dberr.txt
  • C:\Windows\sysnative\DriverStore\FileRepository\sangforvnic.inf_amd64_neutral_9183b83f3b2f3cd1\sangforvnic.PNF
  • C:\Windows\sysnative\DriverStore\FileRepository\sangforvnic.inf_amd64_neutral_9183b83f3b2f3cd1\sangforvnic.inf
  • C:\Windows\sysnative\DriverStore\FileRepository\sangforvnic.inf_amd64_neutral_9183b83f3b2f3cd1\SangforVnic.cat
修改的文件
  • C:\Users\test\AppData\Local\Temp\nsy14A9.tmp
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\install.log
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\System.dll
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\bg.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\progress_b.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\progress_h.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\btn_close.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\btn_mini.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\btn_finish_en.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\btn_finish_cn.bmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\SkinBtn.dll
  • C:\Windows\System32\SangforInstallHelper.dll
  • C:\Windows\System32\ECPrivacyStatementEn.rtf
  • C:\Windows\System32\ECPrivacyStatementCn.rtf
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\dbdStaticCtrl.dll
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp\SkinProgress.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Uninstall.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\nd_dkey_v2.CAB
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\nd_dkey_v2_win8.CAB
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\InstallControl.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SuperExeInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SuperServiceInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforServiceClientInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforCSClientInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\VNICInstaller_X64.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\VNICInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforL3Vpn.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforNsp.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforNspX64.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforSddn.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforTcp.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\CSClientManagerPrj.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforCore.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforBHO.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SSOClientPrj.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SJobberInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforUpdateInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforRAppInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\UrlWarrent.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\VC2010RedistX86UInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\ComHelperX64.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforCDC.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\TcpDriverInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\ECBaseInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\ECAgentInstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\DnsDriverInstaller.exe
  • C:\Users\test\AppData\Roaming\Sangfor\SSL\Log\SangforCore.dll.log
  • \Device\NamedPipe\Winsock2\CatalogChangeListener-264-0
  • \Device\NamedPipe\Winsock2\CatalogChangeListener-148-0
  • \Device\NamedPipe\Winsock2\CatalogChangeListener-2bc-0
  • \Device\NamedPipe\Winsock2\CatalogChangeListener-314-0
  • \Device\NamedPipe\Winsock2\CatalogChangeListener-1b0-0
  • \Device\NamedPipe\Winsock2\CatalogChangeListener-1a8-0
  • C:\Users\test\AppData\Roaming\Sangfor\SSL\Log\SangforL3Vpn.dll.log
  • C:\Users\test\AppData\Local\Temp\nst42DA.tmp
  • C:\Users\test\AppData\Local\Temp\nsi42EA.tmp\KillProcDLL.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\MU VPN.ico
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\Offline.ico
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\SangforCSClient.exe
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\LogoutTimeOut.exe
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\SangforVpnLibeay32.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\SangforVpnSsleay32.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\Uninstall.exe
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\FT_ND_API.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\USBKeyManager.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\SangforDKeyMonitor.exe
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\epass.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\ShuttleCsp11_3000GM.dll
  • C:\Windows\System32\SangforVpnLibeay32.dll
  • C:\Windows\System32\SangforVpnSsleay32.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforCSClient\SangforCSClientUninstaller.exe
  • C:\Users\test\AppData\Local\Temp\nsi42EA.tmp\System.dll
  • \??\PIPE\srvsvc
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MU VPN\\xe5\x90\xaf\xe5\x8a\xa8MU VPN.lnk
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MU VPN\\xe5\x8d\xb8\xe8\xbd\xbdMU VPN.lnk
  • C:\Users\Public\Desktop\MU VPN.lnk
  • C:\Users\test\AppData\Local\Temp\nsy4837.tmp
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrv.sys
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrvX64.sys
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrv_win7.sys
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrv_win7X64.sys
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrv_ARM64.sys
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\Install.exe
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\Remove.exe
  • C:\Users\test\AppData\Local\Temp\nsd497F.tmp\System.dll
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\SangforTcpDrv.sys
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\TcpDriverUnInstaller.exe
  • C:\Users\test\AppData\Local\Temp\nsi588B.tmp
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\DnsDrv.sys
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\DnsDrvx64.sys
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\DnsDrv_ARM64.sys
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\Install.exe
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\Remove.exe
  • C:\Users\test\AppData\Local\Temp\nst5A51.tmp\System.dll
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\SangforDnsDrv.sys
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\UnDnsDriverInstaller.exe
  • C:\Users\test\AppData\Local\Temp\nsi5E07.tmp
  • C:\Program Files (x86)\Sangfor\SSL\Promote\SangforPromote.CAB
  • C:\Users\test\AppData\Local\Temp\nsd5E37.tmp\nsExec.dll
  • C:\Program Files (x86)\Sangfor\SSL\Promote\msvcp60.dll
  • C:\Program Files (x86)\Sangfor\SSL\Promote\PromoteUninstall.exe
  • C:\Windows\Logs\DPX\setupact.log
  • C:\Windows\Logs\DPX\setuperr.log
  • C:\Program Files (x86)\Sangfor\SSL\Promote\$dpx$.tmp\428bb0b097d90146b7095fe59d6ab3ea.tmp
  • C:\Program Files (x86)\Sangfor\SSL\Promote\SangforPromote.exe
  • C:\Users\test\AppData\Local\Temp\nst6326.tmp
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\SangforServiceClient.CAB
  • C:\Users\test\AppData\Local\Temp\nsy6346.tmp\nsExec.dll
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\SangforServiceClientUninstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\$dpx$.tmp\ac02676b1b7e4a4883646cdb7cc03183.tmp
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\SangforServiceClient.exe
  • C:\Users\test\AppData\Local\Temp\nsd6844.tmp
  • C:\Windows\System32\atl100.dll
  • C:\Windows\System32\mfc100chs.dll
  • C:\Windows\System32\mfc100u.dll
  • C:\Windows\System32\msvcp100.dll
  • C:\Windows\System32\msvcr100.dll
  • C:\Users\test\AppData\Local\Temp\nsd6D24.tmp
  • C:\Program Files (x86)\Sangfor\SSL\SvpnJobber\SvpnJobber.exe
  • C:\Program Files (x86)\Sangfor\SSL\SvpnJobber\SJobberUninstaller.exe
  • C:\Users\test\AppData\Local\Temp\nso6F85.tmp
  • C:\Program Files (x86)\Sangfor\SSL\SangforUpdate\SangforUD.exe
  • C:\Program Files (x86)\Sangfor\SSL\SangforUpdate\Uninstaller.exe
  • C:\Users\test\AppData\Local\Temp\nsd733C.tmp
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\SfRemoteAppClient.exe
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\SfRemoteAppClientHost.exe
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\SangforPDF.exe
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\SfRemoteAppSession.exe
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\mstscax.dll
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\libsrapc.dll
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\libngs.dll
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\SRAPSession.exe
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\librdpclip.dll
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\librdpdr.dll
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\librdpsnd.dll
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\en-US\mstscax.dll.mui
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\zh-CN\mstscax.dll.mui
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\SfRemoteAppClientHook.dll
  • C:\Program Files (x86)\Sangfor\SSL\RemoteAppClient\Uninstaller.exe
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\epsnd_m8.inf
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\FT_ND_API.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\FT_ND_FULL.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\FT_ND_MOD.dll
  • C:\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\FT_ND_SC.dll
  • C:\Users\test\AppData\Local\Temp\nst823A.tmp
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\install.log
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic.inf
  • C:\Users\test\AppData\Local\Temp\nsj8299.tmp\System.dll
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic2003.inf
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic.cat
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic2003.cat
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforVnic.sys
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\vacon.exe
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SetIPTime.exe
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforCertificate.cer
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\SangforCertificate256.cer
  • C:\Program Files (x86)\Sangfor\SSL\CSClient\VNIC\ndiscleanup.x64.exe
  • C:\Users\test\AppData\Local\Temp\nsj8299.tmp\nsExec.dll
  • \Device\NamedPipe
  • C:\Windows\inf\setupapi.app.log
  • C:\Windows\inf\setupapi.dev.log
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SET146E.tmp
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SangforVnic.cat
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SET1598.tmp
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\sangforvnic.inf
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SET16C1.tmp
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SangforVnic.sys
  • C:\Windows\sysnative\catroot2\dberr.txt
  • C:\Windows\sysnative\DriverStore\infpub.dat
  • C:\Windows\sysnative\DriverStore\infstrng.dat
删除的文件
  • C:\Users\test\AppData\Local\Temp\nsy1370.tmp
  • C:\Users\test\AppData\Local\Temp\nso14BA.tmp
  • C:\Windows\System32\ECPrivacyStatementCn.rtf
  • C:\Windows\System32\ECPrivacyStatementEn.rtf
  • C:\Users\test\AppData\Local\Temp\nso42BA.tmp
  • C:\Users\test\AppData\Local\Temp\nsi42EA.tmp
  • C:\Users\test\AppData\Local\Temp\nsi42EA.tmp\KillProcDLL.dll
  • C:\Users\test\AppData\Local\Temp\nsi42EA.tmp\System.dll
  • C:\Users\test\AppData\Local\Temp\nsi42EA.tmp\
  • C:\Users\test\AppData\Local\Temp\nsi4816.tmp
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrv.sys
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrvX64.sys
  • C:\Users\test\AppData\Local\Temp\nsd497F.tmp
  • C:\Program Files (x86)\Sangfor\SSL\TcpDriver\WfpDrv_ARM64.sys
  • C:\Users\test\AppData\Local\Temp\nsd497F.tmp\System.dll
  • C:\Users\test\AppData\Local\Temp\nsd497F.tmp\
  • C:\Users\test\AppData\Local\Temp\nso585C.tmp
  • C:\Users\test\AppData\Local\Temp\nst5A51.tmp
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\DnsDrv.sys
  • C:\Program Files (x86)\Sangfor\SSL\DnsDriver\DnsDrv_ARM64.sys
  • C:\Users\test\AppData\Local\Temp\nst5A51.tmp\System.dll
  • C:\Users\test\AppData\Local\Temp\nst5A51.tmp\
  • C:\Users\test\AppData\Local\Temp\nsd5DE7.tmp
  • C:\Users\test\AppData\Local\Temp\nsd5E37.tmp
  • C:\Program Files (x86)\Sangfor\SSL\Promote\SangforPromote.CAB
  • C:\Users\test\AppData\Local\Temp\nsd5E37.tmp\nsExec.dll
  • C:\Users\test\AppData\Local\Temp\nsd5E37.tmp\
  • C:\Program Files (x86)\Sangfor\SSL\Promote\$dpx$.tmp\428bb0b097d90146b7095fe59d6ab3ea.tmp
  • C:\Program Files (x86)\Sangfor\SSL\Promote\$dpx$.tmp
  • C:\Users\test\AppData\Local\Temp\nso6306.tmp
  • C:\Users\test\AppData\Local\Temp\nsy6346.tmp
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\SangforServiceClient.CAB
  • C:\Users\test\AppData\Local\Temp\nsy6346.tmp\nsExec.dll
  • C:\Users\test\AppData\Local\Temp\nsy6346.tmp\
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\$dpx$.tmp\ac02676b1b7e4a4883646cdb7cc03183.tmp
  • C:\Program Files (x86)\Sangfor\SSL\SangforServiceClient\$dpx$.tmp
  • C:\Users\test\AppData\Local\Temp\nsi6814.tmp
  • C:\Users\test\AppData\Local\Temp\nsy6D04.tmp
  • C:\Users\test\AppData\Local\Temp\nsj6F65.tmp
  • C:\Users\test\AppData\Local\Temp\nso72DE.tmp
  • C:\Users\test\AppData\Local\Temp\nso821A.tmp
  • C:\Users\test\AppData\Local\Temp\nsj8299.tmp
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SET146E.tmp
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SET1598.tmp
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SET16C1.tmp
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SangforVnic.cat
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\sangforvnic.inf
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}\SangforVnic.sys
  • C:\Users\test\AppData\Local\Temp\{506e45d1-0ac5-3185-655d-6048198f9f5b}
注册表键
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\UseFilter
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\System.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SkinBtn.dll
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a
  • HKEY_CURRENT_USER
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\\xe5\xae\x8b\xe4\xbd\x93
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helvetica
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg 2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tahoma Armenian
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helv
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tms Rmn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\David Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Miriam Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Fixed Miriam Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Rod Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\FangSong_GB2312
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\KaiTi_GB2312
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\EasyConnectInstaller.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3FC47A08-E5C9-4BCA-A2C7-BC9A282AED14}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
  • HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\MS Shell Dlg 2
  • HKEY_CURRENT_USER\Software\Microsoft\CTF\LayoutIcon\0804\00000804
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\PrivacyAccepted
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
  • HKEY_CURRENT_USER\Control Panel\Desktop
  • HKEY_CURRENT_USER\Control Panel\Desktop\SmoothScroll
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewAlphaSelect
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewShadow
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AccListViewV6
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\UseDoubleClickTimer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CurrentVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SkinProgress.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\\xe5\xbe\xae\xe8\xbd\xaf\xe9\x9b\x85\xe9\xbb\x91
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\VPN\Sessions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\VPN\Sessions\IDTable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\SangforCSClient
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\SangforUpdate\TcpModule\InstallWhiteList
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforUpdate\TcpModule\InstallWhiteList\LSPNames
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforUpdate\TcpModule\InstallWhiteList\Enable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\CSClientManagerPrj.dll
  • HKEY_LOCAL_MACHINE\System\Setup
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\PnpLockdownFiles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\CSClientManagerPrj.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F257CF85-8E97-4C9B-8407-459B28007630}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{F257CF85-8E97-4C9B-8407-459B28007630}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{F257CF85-8E97-4C9B-8407-459B28007630}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{F257CF85-8E97-4C9B-8407-459B28007630}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{F257CF85-8E97-4C9B-8407-459B28007630}\iexplore\AllowedDomains\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SangforCore.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\SANGFOR\SSL\LogSystem\SangforCore.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\LogType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\TIMING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\TIMEOUT
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\TRACE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\MEMORY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\LOCKING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\ERROR
  • HKEY_LOCAL_MACHINE\SOFTWARE\SANGFOR\SSL\LogSystem\GLOBAL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\TIMING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\TIMEOUT
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\TRACE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\MEMORY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\LOCKING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\ERROR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforCore.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SangforBHO.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforBHO.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{FFD2FD1F-C991-4A2F-8557-CDB11E277500}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\iexplore\AllowedDomains\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SSOClientPrj.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SSOClientPrj.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E39B98A8-34A7-4D92-A979-920C48817110}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E39B98A8-34A7-4D92-A979-920C48817110}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E39B98A8-34A7-4D92-A979-920C48817110}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E39B98A8-34A7-4D92-A979-920C48817110}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E39B98A8-34A7-4D92-A979-920C48817110}\iexplore\AllowedDomains\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E39B98A8-34A7-4D92-A979-920C48817110}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{2A39CB63-CC0C-4EDD-82D0-4559C5087110}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\iexplore\AllowedDomains\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E6316651-CC1B-4FB9-A985-4796DC6B7110}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E6316651-CC1B-4FB9-A985-4796DC6B7110}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E6316651-CC1B-4FB9-A985-4796DC6B7110}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E6316651-CC1B-4FB9-A985-4796DC6B7110}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E6316651-CC1B-4FB9-A985-4796DC6B7110}\iexplore\AllowedDomains\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SangforNsp.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforNsp.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A5A85624-037B-446E-9090-EEA49DFD5900}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{A5A85624-037B-446E-9090-EEA49DFD5900}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{A5A85624-037B-446E-9090-EEA49DFD5900}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{A5A85624-037B-446E-9090-EEA49DFD5900}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{A5A85624-037B-446E-9090-EEA49DFD5900}\iexplore\AllowedDomains\*
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSock2\Parameters
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\WinSock_Registry_Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\00000028
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Num_Catalog_Entries
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\AddressFamily
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\AddressFamily
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\AddressFamily
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\AddressFamily
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\AddressFamily
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\AddressFamily
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderInfo
  • HKEY_CLASSES_ROOT\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\InprocServer32
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Current_NameSpace_Catalog
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\00000029
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\AddressFamily
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\0000002A
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\AddressFamily
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SangforTcp.dll
  • HKEY_LOCAL_MACHINE\STest
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforTcp.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{D37E99E3-20EB-4838-8BDF-89D0D35FF043}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\iexplore\AllowedDomains\*
  • HKEY_CLASSES_ROOT\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\InprocServer32
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Current_Protocol_Catalog
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\00000005
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Next_Catalog_Entry_ID
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Num_Catalog_Entries
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\00000006
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\LspCategories
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\00000007
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\00000008
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\00000009
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\0000000A
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\0000000B
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SangforL3Vpn.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\SANGFOR\SSL\LogSystem\SangforL3Vpn.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\LogType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\TIMING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\TIMEOUT
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\TRACE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\MEMORY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\LOCKING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\ERROR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforL3Vpn.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforSddn.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SangforCDC.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforCDC.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\Properties
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\Uninstall.exe
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sinfor\SSL\CSClient
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\CSClient
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sinfor\SSL\Promote
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\Promote
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sinfor\SSL\UCP
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\UCP
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sinfor\SSL\HTPINFO
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\SOFTWARE\Sangfor\SSL\HTPINFO
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sinfor\SSL\SinforSDUI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\SinforSDUI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\SangforSDUI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\SvpnJobber
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\SCache
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\SangforServiceClient
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\SangforUpdate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\RemoteAppClient
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\SangforECPlugin
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\ECAgent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\TcpDriver
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\DnsDriver
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\SangforCSClient\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\KillProcDLL.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\SangforCSClientPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\SangforCSClientUninstallPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\SangforCSClientVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\EnableShortCut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\EnableNotShowRc
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\CSClientIcon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\CSClientShortCut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\SangforCSClientPort
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\USBKEYManagerPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\DkeyAutoLogin
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\MU VPN
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MU VPN\DisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MU VPN\UninstallString
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MU VPN\Publisher
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MU VPN\DisplayVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MU VPN\DisplayIcon
  • HKEY_CLASSES_ROOT\sslvpn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sslvpn\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sslvpn\URL Protocol
  • HKEY_CLASSES_ROOT\sslvpn\DefaultIcon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sslvpn\DefaultIcon\(Default)
  • HKEY_CLASSES_ROOT\sslvpn\Shell\Open\command
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sslvpn\Shell\Open\command\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Isolation
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Personal
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Pictures
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Music
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Video
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\Common Documents
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\CommonPictures
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\CommonMusic
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\CommonVideo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Favorites
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{DE92C1C7-837F-4F69-A3BB-86E631204A23}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{374DE290-123F-4565-9164-39C4925E467B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\PropertyBag
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProfilesDirectory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\Common Startup
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{56784854-C6CB-462B-8169-88E350ACB882}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000\ProfileImagePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\SangforCSClientInstaller.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\SangforCSClientInstaller.exe
  • HKEY_CLASSES_ROOT\.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
  • HKEY_CLASSES_ROOT\.exe\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\UserChoice
  • HKEY_CLASSES_ROOT\exefile
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\ShellEx\IconHandler
  • HKEY_CLASSES_ROOT\SystemFileAssociations\.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\ShellEx\IconHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\Content Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NormalizeLinkNetPidls
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NormalizeLinkNetPidls
  • HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.NamespaceCLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CurrentMajorVersionNumber
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\TcpDriver\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\TcpDriver\UnInstall
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\TcpDriver\Path
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\TcpDriver\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\TcpDriver\Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\TcpDriver\UnInsPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\TcpDriver\Enable
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforTcpDrv_7,5,0,1
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforTcpDrv_7,5,0,1\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\ErrorControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\DisplayName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\Tag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\DependOnService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\DependOnGroup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\Group
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ErrorControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Tag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\DependOnService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\DependOnGroup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Group
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WudfPf
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WudfPf\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PlugPlay
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PlugPlay\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
  • HKEY_USERS\S-1-5-18
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
  • HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
  • HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
  • HKEY_USERS\.DEFAULT\Environment
  • HKEY_USERS\.DEFAULT\Volatile Environment
  • HKEY_USERS\.DEFAULT\Volatile Environment\0
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Environment
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\DnsDriver\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\DnsDriver\UnInstall
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\DnsDriver\Path
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\DnsDriver\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\DnsDriver\Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\DnsDriver\UnInsPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\DnsDriver\Enable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\DbgLevel
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\Promote\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\nsExec.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\Promote\SuperExeUninstall
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\Promote\SuperExe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\Promote\SuperExeVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Component Based Servicing\EnableDpxLog
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\SangforServiceClient\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforServiceClient\SangforServiceClientUninstallPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforServiceClient\SangforServicelientPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforServiceClient\SangforServiceClientVersion
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\SvpnJobber\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SvpnJobber\SvpnJobberPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SvpnJobber\SvpnJobberVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SvpnJobber\SJobberUninstallPath
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\SangforUpdate\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforUpdate\UninstallPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforUpdate\SangforUpdatePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforUpdate\SangforUpdateVersion
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\RemoteAppClient\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\RAppHookPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\UninstallPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\Path
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\ClientCheckPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\SumatraPDFReader
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\SrapcLogLevel
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\RemoteAppClient\SRAPOption
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\SRAPOption\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\DeviceRedirectMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\SumatraPrintMode
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogMaxFileSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\FT_ND_SC.dll
  • HKEY_CLASSES_ROOT\FT_ND_SC.ePsM8SC.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC.1\CLSID\(Default)
  • HKEY_CLASSES_ROOT\FT_ND_SC.ePsM8SC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC\CurVer\(Default)
  • HKEY_CLASSES_ROOT\CLSID
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
  • HKEY_CURRENT_USER\Software\Classes\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\FLAGS
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\FLAGS\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\0\win32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\0\win32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\HELPDIR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\HELPDIR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\HELPDIR\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\NoFileFolderConnection
  • HKEY_CLASSES_ROOT\.inf
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf\(Default)
  • HKEY_CLASSES_ROOT\.inf\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inf\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inf
  • HKEY_CLASSES_ROOT\inffile
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\ShellEx\IconHandler
  • HKEY_CLASSES_ROOT\SystemFileAssociations\.inf
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf\PerceivedType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf\Content Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\NeverShowExt
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\PropertySystem\PropertyHandlers\.inf
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\ShellEx\PropertyHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf\ShellEx\PropertyHandler
  • HKEY_CLASSES_ROOT\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\ShellEx\PropertyHandler
  • HKEY_CLASSES_ROOT\AllFilesystemObjects
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\PropertyHandler
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Directory\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory
  • HKEY_CLASSES_ROOT\Directory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ShellEx\PropertyHandler
  • HKEY_CLASSES_ROOT\Folder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\PropertyHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MaxUndoItems
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Advanced\MaxUndoItems
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\VNICInstaller_X64.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\VNICInstaller_X64.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ShellEx\{2F711B17-773C-41D4-93FA-7F23EDCECB66}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\{2F711B17-773C-41D4-93FA-7F23EDCECB66}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\{2F711B17-773C-41D4-93FA-7F23EDCECB66}
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\CopyFileBufferedSynchronousIo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\CopyFileChunkSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\CopyFileOverlappedCount
  • HKEY_CLASSES_ROOT\.cat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cat\(Default)
  • HKEY_CLASSES_ROOT\.cat\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cat\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cat
  • HKEY_CLASSES_ROOT\CATFile
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CATFile\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CATFile\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CATFile\ShellEx\IconHandler
  • HKEY_CLASSES_ROOT\SystemFileAssociations\.cat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cat\PerceivedType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CATFile\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CATFile\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cat\Content Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CATFile\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CATFile\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CATFile\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CATFile\NeverShowExt
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\PropertySystem\PropertyHandlers\.cat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CATFile\ShellEx\PropertyHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cat\ShellEx\PropertyHandler
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Network
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\NetCfgLockHolder
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\NetCfgLockHolder\(Default)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\Config
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPublisher\PhysicalStores
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPublisher
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPublisher\Safer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPublisher\PhysicalStores
  • HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPublisher
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2EFD69CD8052055D6DC5EAC7631A27A45E102A8B
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2EFD69CD8052055D6DC5EAC7631A27A45E102A8B\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\5CEA91B309BE5E0A5EE4DA8FD8C162847787B3CA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\5CEA91B309BE5E0A5EE4DA8FD8C162847787B3CA\Blob
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus\setupapi.app.log
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus\setupapi.dev.log
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\D592E1B9
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\133121
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\DeviceInstall
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\State
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\Safety Warning Level
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\AuthRoot
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot\DisableRootAutoUpdate
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetCachedOcspSwitchToCrlCount
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetMaxCachedOcspPerCrlCount
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugFlags
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\Certificates
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CRLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CTLs
  • HKEY_CURRENT_USER\
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Disallowed
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores
  • HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\PhysicalStores
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs
  • HKEY_LOCAL_MACHINE\SYSTEM
  • HKEY_LOCAL_MACHINE\SOFTWARE
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CoDeviceInstallers
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0012
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\ShowIsdnPages
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Ndi\Interfaces
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Ndi\Interfaces\LowerRange
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\CoInitializeSecurityParam
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\AuthenticationLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\ImpersonationLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\AuthenticationCapabilities
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\CoInitializeSecurityAppID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\DeferredCoInitializeSecurityServices
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\DefaultRpcStackSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\SystemCritical
  • HKEY_LOCAL_MACHINE\Software\Classes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\svchost.exe
  • HKEY_USERS\.DEFAULT\Control Panel\International
  • HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
  • HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
  • HKEY_USERS\.DEFAULT\Control Panel\International\sList
  • HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
  • HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
  • HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
  • HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
  • HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
  • HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
  • HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
  • HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
  • HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
  • HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
  • HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
  • HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
  • HKEY_USERS\.DEFAULT\Control Panel\International\s1159
  • HKEY_USERS\.DEFAULT\Control Panel\International\s2359
  • HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
  • HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
  • HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
  • HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
  • HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
  • HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
  • HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
  • HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
  • HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
  • HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
  • HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
  • HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
  • HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
  • HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
  • HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
  • HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WUDFSvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Parameters
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Parameters\ServiceDll
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Parameters\ServiceManifest
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Parameters\ServiceMain
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\LogEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\LogStartNewSession
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\Logkd
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\LogFlushPeriodSeconds
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\LogLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\LogFlags
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MiniNT
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\NumDeviceStacksMax
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\AutoRestartDeviceCountLimit
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\DefaultHostProcessGUID
读取的注册表键
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\UseFilter
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\System.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SkinBtn.dll
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\\xe5\xae\x8b\xe4\xbd\x93
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helvetica
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg 2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tahoma Armenian
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helv
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tms Rmn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\David Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Miriam Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Fixed Miriam Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Rod Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\FangSong_GB2312
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\KaiTi_GB2312
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
  • HKEY_CURRENT_USER\Control Panel\Desktop\SmoothScroll
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewAlphaSelect
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewShadow
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AccListViewV6
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\UseDoubleClickTimer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CurrentVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SkinProgress.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\CSClientManagerPrj.dll
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\CSClientManagerPrj.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SangforCore.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\LogType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\TIMING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\TIMEOUT
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\TRACE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\MEMORY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\LOCKING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\ERROR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\TIMING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\TIMEOUT
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\TRACE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\MEMORY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\LOCKING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\ERROR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforCore.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SangforBHO.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforBHO.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SSOClientPrj.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SSOClientPrj.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SangforNsp.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforNsp.dll
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\WinSock_Registry_Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Num_Catalog_Entries
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\AddressFamily
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\AddressFamily
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\AddressFamily
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\AddressFamily
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\AddressFamily
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\AddressFamily
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderInfo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Current_NameSpace_Catalog
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\AddressFamily
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\AddressFamily
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\ProviderInfo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SangforTcp.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforTcp.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforUpdate\TcpModule\InstallWhiteList\LSPNames
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Current_Protocol_Catalog
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Next_Catalog_Entry_ID
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Num_Catalog_Entries
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\LspCategories
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SangforL3Vpn.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\LogType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\TIMING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\TIMEOUT
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\TRACE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\MEMORY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\LOCKING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\ERROR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforL3Vpn.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforSddn.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\SangforCDC.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforCDC.dll
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\ComponentId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\KillProcDLL.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\InitFolderHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\InitFolderHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Personal
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\InitFolderHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Pictures
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\InitFolderHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Music
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\InitFolderHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Video
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\Common Documents
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\CommonPictures
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\CommonMusic
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\CommonVideo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InitFolderHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Favorites
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\InitFolderHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{DE92C1C7-837F-4F69-A3BB-86E631204A23}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\InitFolderHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{374DE290-123F-4565-9164-39C4925E467B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProfilesDirectory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\Common Startup
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\InitFolderHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{56784854-C6CB-462B-8169-88E350ACB882}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000\ProfileImagePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\InitFolderHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\Content Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NormalizeLinkNetPidls
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NormalizeLinkNetPidls
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.NamespaceCLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CurrentMajorVersionNumber
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\TcpDriver\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforTcpDrv_7,5,0,1\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\ErrorControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\Tag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\DependOnService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\DependOnGroup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\Group
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ErrorControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Tag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\DependOnService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\DependOnGroup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Group
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WudfPf\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PlugPlay\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
  • HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Environment
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\DnsDriver\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\nsExec.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Component Based Servicing\EnableDpxLog
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogMaxFileSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemDrive%\Program Files (x86)\Sangfor\SSL\ClientComponent\Nddkey\FT_ND_SC.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\FLAGS\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\0\win32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\HELPDIR\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\NoFileFolderConnection
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf\PerceivedType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf\Content Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\NeverShowExt
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MaxUndoItems
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Advanced\MaxUndoItems
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\CopyFileBufferedSynchronousIo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\CopyFileChunkSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\CopyFileOverlappedCount
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cat\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cat\PerceivedType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CATFile\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CATFile\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cat\Content Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CATFile\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CATFile\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CATFile\NeverShowExt
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\Config
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\NetCfgLockHolder\(Default)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2EFD69CD8052055D6DC5EAC7631A27A45E102A8B\Blob
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus\setupapi.app.log
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus\setupapi.dev.log
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\D592E1B9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\133121
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\State
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\Safety Warning Level
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot\DisableRootAutoUpdate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetCachedOcspSwitchToCrlCount
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetMaxCachedOcspPerCrlCount
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugFlags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\5CEA91B309BE5E0A5EE4DA8FD8C162847787B3CA\Blob
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\ShowIsdnPages
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Ndi\Interfaces\LowerRange
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\CoInitializeSecurityParam
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\AuthenticationLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\ImpersonationLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\AuthenticationCapabilities
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\CoInitializeSecurityAppID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\DeferredCoInitializeSecurityServices
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\DefaultRpcStackSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted\SystemCritical
  • HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
  • HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
  • HKEY_USERS\.DEFAULT\Control Panel\International\sList
  • HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
  • HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
  • HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
  • HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
  • HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
  • HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
  • HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
  • HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
  • HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
  • HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
  • HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
  • HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
  • HKEY_USERS\.DEFAULT\Control Panel\International\s1159
  • HKEY_USERS\.DEFAULT\Control Panel\International\s2359
  • HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
  • HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
  • HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
  • HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
  • HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
  • HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
  • HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
  • HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
  • HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
  • HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
  • HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
  • HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
  • HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
  • HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
  • HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
  • HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Parameters\ServiceDll
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Parameters\ServiceManifest
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Parameters\ServiceMain
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\LogEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\LogStartNewSession
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\Logkd
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\LogFlushPeriodSeconds
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\LogLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\LogFlags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\NumDeviceStacksMax
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\AutoRestartDeviceCountLimit
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\DefaultHostProcessGUID
修改的注册表键
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\PrivacyAccepted
  • HKEY_LOCAL_MACHINE\SOFTWARE\Sangfor\SSL\SangforUpdate\TcpModule\InstallWhiteList
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforUpdate\TcpModule\InstallWhiteList\LSPNames
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforUpdate\TcpModule\InstallWhiteList\Enable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CSClientManagerPrj.CSClientManager.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F257CF85-8E97-4C9B-8407-459B28007630}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F257CF85-8E97-4C9B-8407-459B28007630}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{F257CF85-8E97-4C9B-8407-459B28007630}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{F257CF85-8E97-4C9B-8407-459B28007630}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{F257CF85-8E97-4C9B-8407-459B28007630}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{F257CF85-8E97-4C9B-8407-459B28007630}\iexplore\AllowedDomains\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\SANGFOR\SSL\LogSystem\SangforCore.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\LogType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\TIMING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\TIMEOUT
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\TRACE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\MEMORY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\LOCKING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforCore.dll\ERROR
  • HKEY_LOCAL_MACHINE\SOFTWARE\SANGFOR\SSL\LogSystem\GLOBAL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\TIMING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\TIMEOUT
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\TRACE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\MEMORY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\LOCKING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\GLOBAL\ERROR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCore.SangforCoreCom.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{92AFA1EA-8651-4152-9D42-7A417A327100}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforIEBHO.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{FFD2FD1F-C991-4A2F-8557-CDB11E277500}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{FFD2FD1F-C991-4A2F-8557-CDB11E277500}\iexplore\AllowedDomains\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFD2FD1F-C991-4A2F-8557-CDB11E277500}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforBHO.SangforHelper.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOClientBHO.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39B98A8-34A7-4D92-A979-920C48817110}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E39B98A8-34A7-4D92-A979-920C48817110}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E39B98A8-34A7-4D92-A979-920C48817110}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E39B98A8-34A7-4D92-A979-920C48817110}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E39B98A8-34A7-4D92-A979-920C48817110}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E39B98A8-34A7-4D92-A979-920C48817110}\iexplore\AllowedDomains\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E39B98A8-34A7-4D92-A979-920C48817110}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.SSOHtmlElementEvent.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2A39CB63-CC0C-4EDD-82D0-4559C5087110}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{2A39CB63-CC0C-4EDD-82D0-4559C5087110}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{2A39CB63-CC0C-4EDD-82D0-4559C5087110}\iexplore\AllowedDomains\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSOClientPrj.Web2Client.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6316651-CC1B-4FB9-A985-4796DC6B7110}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E6316651-CC1B-4FB9-A985-4796DC6B7110}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E6316651-CC1B-4FB9-A985-4796DC6B7110}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E6316651-CC1B-4FB9-A985-4796DC6B7110}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E6316651-CC1B-4FB9-A985-4796DC6B7110}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{E6316651-CC1B-4FB9-A985-4796DC6B7110}\iexplore\AllowedDomains\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ClientNSPPrj.ClientNSP.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5A85624-037B-446E-9090-EEA49DFD5900}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A5A85624-037B-446E-9090-EEA49DFD5900}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{A5A85624-037B-446E-9090-EEA49DFD5900}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{A5A85624-037B-446E-9090-EEA49DFD5900}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{A5A85624-037B-446E-9090-EEA49DFD5900}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{A5A85624-037B-446E-9090-EEA49DFD5900}\iexplore\AllowedDomains\*
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\00000028
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Num_Catalog_Entries
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\00000029
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\LibraryPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\DisplayString
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\ProviderId
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\SupportedNameSpace
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\StoresServiceClassInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008\ProviderInfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\0000002A
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProxyIE.CSProxy.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D37E99E3-20EB-4838-8BDF-89D0D35FF043}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{D37E99E3-20EB-4838-8BDF-89D0D35FF043}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{D37E99E3-20EB-4838-8BDF-89D0D35FF043}\iexplore\AllowedDomains\*
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\00000005
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Num_Catalog_Entries
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Next_Catalog_Entry_ID
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\00000006
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\00000007
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\00000008
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\00000009
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\0000000A
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016\PackedCatalogItem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016\ProtocolName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\0000000B
  • HKEY_LOCAL_MACHINE\SOFTWARE\SANGFOR\SSL\LogSystem\SangforL3Vpn.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\LogType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\TIMING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\TIMEOUT
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\TRACE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\MEMORY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\LOCKING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\LogSystem\SangforL3Vpn.dll\ERROR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforL3Vpn.L3Vpn.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{964865DB-CC7E-4F11-88BA-1445A7947102}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforSddn.Sddn.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{013B354E-96FF-4675-8942-B6CB50889543}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server\CurVer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SangforCDC.Server.1\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C5BC3F7A-3F33-4CA1-B5AF-4540987C7100}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\SangforCSClient\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\SangforCSClientPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\SangforCSClientUninstallPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\SangforCSClientVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\EnableShortCut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\EnableNotShowRc
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\CSClientIcon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\CSClientShortCut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\SangforCSClientPort
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\USBKEYManagerPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforCSClient\DkeyAutoLogin
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\MU VPN
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MU VPN\DisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MU VPN\UninstallString
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MU VPN\Publisher
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MU VPN\DisplayVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MU VPN\DisplayIcon
  • HKEY_CLASSES_ROOT\sslvpn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sslvpn\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sslvpn\URL Protocol
  • HKEY_CLASSES_ROOT\sslvpn\DefaultIcon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sslvpn\DefaultIcon\(Default)
  • HKEY_CLASSES_ROOT\sslvpn\Shell\Open\command
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sslvpn\Shell\Open\command\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Isolation
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\TcpDriver\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\TcpDriver\UnInstall
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\TcpDriver\Path
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\TcpDriver\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\TcpDriver\Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\TcpDriver\UnInsPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\TcpDriver\Enable
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\ErrorControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\DisplayName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SangforDnsDrv_7,5,0,1\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Type
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\DnsDriver\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\DnsDriver\UnInstall
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\DnsDriver\Path
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\DnsDriver\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\DnsDriver\Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\DnsDriver\UnInsPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\DnsDriver\Enable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\DbgLevel
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\Promote\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\Promote\SuperExeUninstall
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\Promote\SuperExe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\Promote\SuperExeVersion
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\SangforServiceClient\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforServiceClient\SangforServiceClientUninstallPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforServiceClient\SangforServicelientPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforServiceClient\SangforServiceClientVersion
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\SvpnJobber\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SvpnJobber\SvpnJobberPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SvpnJobber\SvpnJobberVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SvpnJobber\SJobberUninstallPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforUpdate\UninstallPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforUpdate\SangforUpdatePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforUpdate\SangforUpdateVersion
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\RemoteAppClient\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\RAppHookPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\UninstallPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\Path
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\ClientCheckPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\SumatraPDFReader
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\SrapcLogLevel
  • HKEY_LOCAL_MACHINE\Software\Sangfor\SSL\RemoteAppClient\SRAPOption
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\SRAPOption\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\DeviceRedirectMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\RemoteAppClient\SumatraPrintMode
  • HKEY_CLASSES_ROOT\FT_ND_SC.ePsM8SC.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC.1\CLSID\(Default)
  • HKEY_CLASSES_ROOT\FT_ND_SC.ePsM8SC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FT_ND_SC.ePsM8SC\CurVer\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0272DA76-96FB-449E-8298-178876E0EA89}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\FLAGS
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\FLAGS\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\0\win32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\0\win32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\HELPDIR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F4A90D77-027F-4096-8D94-8FA4A4E1F235}\1.0\HELPDIR\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D372A52D-D08B-4336-B561-E00028877FAB}\TypeLib\Version
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\NetCfgLockHolder
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\NetCfgLockHolder\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2EFD69CD8052055D6DC5EAC7631A27A45E102A8B
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2EFD69CD8052055D6DC5EAC7631A27A45E102A8B\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\5CEA91B309BE5E0A5EE4DA8FD8C162847787B3CA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\5CEA91B309BE5E0A5EE4DA8FD8C162847787B3CA\Blob
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus\setupapi.dev.log
删除的注册表键
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforUpdate\UninstallPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforUpdate\SangforUpdatePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sangfor\SSL\SangforUpdate\SangforUpdateVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2EFD69CD8052055D6DC5EAC7631A27A45E102A8B
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\5CEA91B309BE5E0A5EE4DA8FD8C162847787B3CA
API解析
  • cryptbase.dll.SystemFunction036
  • shfolder.dll.SHGetFolderPathA
  • setupapi.dll.CM_Get_Device_Interface_List_Size_ExW
  • setupapi.dll.CM_Get_Device_Interface_List_ExW
  • comctl32.dll.#386
  • kernel32.dll.GetUserDefaultUILanguage
  • system.dll.Call
  • kernel32.dll.CreateMutexA
  • kernel32.dll.CloseHandle
  • system.dll.Alloc
  • kernel32.dll.GetVersionExA
  • system.dll.Free
  • skinbtn.dll.Init
  • sangforinstallhelper.dll.ShowPrivacyLicensePage
  • kernel32.dll.QueryActCtxW
  • kernel32.dll.ActivateActCtx
  • kernel32.dll.FindActCtxSectionStringW
  • kernel32.dll.DeactivateActCtx
  • comctl32.dll.InitCommonControlsEx
  • shell32.dll.InitNetworkAddressControl
  • comctl32.dll.RegisterClassNameW
  • uxtheme.dll.EnableThemeDialogTexture
  • uxtheme.dll.OpenThemeData
  • ole32.dll.OleInitialize
  • ole32.dll.OleUninitialize
  • ole32.dll.RegisterDragDrop
  • kernel32.dll.SetThreadUILanguage
  • ole32.dll.CoInitializeEx
  • ole32.dll.CoUninitialize
  • ole32.dll.CoRegisterInitializeSpy
  • ole32.dll.CoRevokeInitializeSpy
  • uxtheme.dll.BufferedPaintInit
  • uxtheme.dll.BeginBufferedPaint
  • gdi32.dll.GetLayout
  • gdi32.dll.GdiRealizationInfo
  • gdi32.dll.FontIsLinked
  • advapi32.dll.RegOpenKeyExW
  • advapi32.dll.RegQueryInfoKeyW
  • gdi32.dll.GetTextFaceAliasW
  • advapi32.dll.RegEnumValueW
  • advapi32.dll.RegCloseKey
  • advapi32.dll.RegQueryValueExW
  • advapi32.dll.RegQueryValueExA
  • advapi32.dll.RegEnumKeyExW
  • gdi32.dll.GetTextExtentExPointWPri
  • uxtheme.dll.EndBufferedPaint
  • oleaut32.dll.SysAllocString
  • oleaut32.dll.SysStringLen
  • oleaut32.dll.SysFreeString
  • ole32.dll.RevokeDragDrop
  • user32.dll.SetWindowLongA
  • user32.dll.MoveWindow
  • user32.dll.SetWindowPos
  • user32.dll.GetWindowLongA
  • user32.dll.SetLayeredWindowAttributes
  • kernel32.dll.FlsAlloc
  • kernel32.dll.FlsGetValue
  • kernel32.dll.FlsSetValue
  • kernel32.dll.FlsFree
  • dbdstaticctrl.dll.BindRootDlg
  • user32.dll.UpdateLayeredWindow
  • dwmapi.dll.DwmIsCompositionEnabled
  • imm32.dll.ImmIsIME
  • dbdstaticctrl.dll.Init
  • skinbtn.dll.Set
  • skinbtn.dll.onClick
  • skinprogress.dll.Set
  • user32.dll.LoadImageA
  • sangforinstallhelper.dll.AllocateSslvpnSessionId
  • sangforinstallhelper.dll.UninstallEasyConnect
  • sangforinstallhelper.dll.WriteDefaultLspWhiteList
  • kernel32.dll.RegOpenKeyExW
  • kernel32.dll.RegCloseKey
  • devrtl.dll.DevRtlGetThreadLogToken
  • setupapi.dll.PnpIsFilePnpDriver
  • csclientmanagerprj.dll.DllRegisterServer
  • advapi32.dll.AddMandatoryAce
  • sangforcore.dll.DllRegisterServer
  • sangforbho.dll.DllRegisterServer
  • ssoclientprj.dll.DllRegisterServer
  • sangfornsp.dll.DllRegisterServer
  • ws2_32.dll.WSCWriteNameSpaceOrder
  • sangfortcp.dll.DllRegisterServer
  • ws2_32.dll.WSCUpdateProvider
  • sangfortcp.dll.WSPStartup
  • sangforl3vpn.dll.DllRegisterServer
  • uxtheme.dll.DrawThemeParentBackground
  • uxtheme.dll.DrawThemeTextEx
  • uxtheme.dll.BufferedPaintUnInit
  • dwmapi.dll.DwmExtendFrameIntoClientArea
  • dwmapi.dll.DwmDefWindowProc
  • comctl32.dll.DllGetVersion
  • sangforsddn.dll.DllRegisterServer
  • sangforcdc.dll.DllRegisterServer
  • sangforinstallhelper.dll.IsVnicInstalled
  • sangforinstallhelper.dll.GetSystemType
  • kernel32.dll.GetNativeSystemInfo
  • kernel32.dll.SortGetHandle
  • kernel32.dll.SortCloseHandle
  • imm32.dll.ImmAssociateContext
  • user32.dll.ChangeWindowMessageFilterEx
  • comctl32.dll.ImageList_LoadImageA
  • oleaut32.dll.#500
  • comctl32.dll.ImageList_Destroy
  • killprocdll.dll.KillProc
  • psapi.dll.EnumProcesses
  • psapi.dll.EnumProcessModules
  • psapi.dll.GetModuleBaseNameA
  • kernel32.dll.GetCurrentProcess
  • kernel32.dll.IsWow64Process
  • propsys.dll.PSCreateMemoryPropertyStore
  • ole32.dll.CoTaskMemFree
  • linkinfo.dll.CreateLinkInfoW
  • user32.dll.IsCharAlphaW
  • user32.dll.CharPrevW
  • ntshrui.dll.GetNetResourceFromLocalPathW
  • srvcli.dll.NetShareEnum
  • cscapi.dll.CscNetApiGetInterface
  • slc.dll.SLGetWindowsInformationDWORD
  • shlwapi.dll.PathRemoveFileSpecW
  • linkinfo.dll.DestroyLinkInfo
  • ntdll.dll.RtlDllShutdownInProgress
  • comctl32.dll.#329
  • linkinfo.dll.IsValidLinkInfo
  • propsys.dll.#407
  • propsys.dll.PropVariantToGUID
  • ole32.dll.PropVariantClear
  • oleaut32.dll.#9
  • propsys.dll.#417
  • propsys.dll.PSGetNameFromPropertyKey
  • propsys.dll.PSStringFromPropertyKey
  • propsys.dll.InitVariantFromBuffer
  • comctl32.dll.#388
  • netutils.dll.NetApiBufferFree
  • advapi32.dll.UnregisterTraceGuids
  • comctl32.dll.#321
  • version.dll.GetFileVersionInfoA
  • shell32.dll.#680
  • ole32.dll.NdrOleInitializeExtension
  • ole32.dll.CoGetClassObject
  • ole32.dll.CoGetMarshalSizeMax
  • ole32.dll.CoMarshalInterface
  • ole32.dll.CoUnmarshalInterface
  • ole32.dll.StringFromIID
  • ole32.dll.CoGetPSClsid
  • ole32.dll.CoTaskMemAlloc
  • ole32.dll.CoCreateInstance
  • ole32.dll.CoReleaseMarshalData
  • ole32.dll.DcomChannelSetHResult
  • nsexec.dll.Exec
  • dpx.dll.DpxNewJob
  • wdscore.dll.WdsSetupLogInit
  • wdscore.dll.WdsSetupLogDestroy
  • wdscore.dll.WdsSetupLogMessageA
  • wdscore.dll.ConstructPartialMsgVA
  • wdscore.dll.CurrentIP
  • wdscore.dll.WdsGetSetupLog
  • kernel32.dll.AddVectoredExceptionHandler
  • cabinet.dll.#20
  • cabinet.dll.#21
  • cabinet.dll.#22
  • cabinet.dll.#23
  • advapi32.dll.CheckTokenMembership
  • ft_nd_sc.dll.DllRegisterServer
  • advapi32.dll.RegOpenKeyW
  • nsexec.dll.ExecToStack
  • oleaut32.dll.#200
  • comctl32.dll.#385
  • propsys.dll.PSLookupPropertyHandlerCLSID
  • propsys.dll.PSCreatePropertyStoreFromObject
  • oleaut32.dll.#6
  • propsys.dll.PropVariantToStringAlloc
  • propsys.dll.PropVariantToBuffer
  • propsys.dll.PropVariantToUInt64
  • propsys.dll.PropVariantToBoolean
  • propsys.dll.InitPropVariantFromBuffer
  • shell32.dll.#66
  • comctl32.dll.#336
  • nsexec.dll.ExecToLog
  • comctl32.dll.#387
  • comctl32.dll.#327
  • setupapi.dll.SetupGetThreadLogToken
  • setupapi.dll.SetupWriteTextLog
  • kernel32.dll.RegQueryValueExW
  • ntdll.dll.RtlGetVersion
  • wintrust.dll.WinVerifyTrust
  • spinf.dll.SpInfSetDirIdHandler
  • sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
  • spinf.dll.SpInfLoadInfFile
  • spinf.dll.SpInfGetVersionNode
  • spinf.dll.SpInfGetVersionDatum
  • spinf.dll.SpInfFreeInfFile
  • devrtl.dll.DevRtlSetThreadLogToken
  • netcfgx.dll.NetClassInstaller
  • nci.dll.NciDeviceInstall
  • wlaninst.dll.WlanDeviceClassCoInstaller
  • wwaninst.dll.WwanDeviceClassCoInstaller
  • devrtl.dll.DevRtlWriteTextLog
  • newdev.dll.UpdateDriverForPlugAndPlayDevicesW
  • kernel32.dll.RegCreateKeyExW
  • kernel32.dll.RegSetValueExW
  • drvstore.dll.DriverStoreFindW
  • kernel32.dll.GetSystemDefaultUILanguage
  • crypt32.dll.CryptQueryObject
  • crypt32.dll.CertGetCTLContextProperty
  • crypt32.dll.CertFreeCTLContext
  • advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
  • advapi32.dll.IsValidSecurityDescriptor
  • advapi32.dll.OpenThreadToken
  • advapi32.dll.OpenProcessToken
  • advapi32.dll.GetKernelObjectSecurity
  • advapi32.dll.DuplicateTokenEx
  • advapi32.dll.AdjustTokenPrivileges
  • advapi32.dll.SetThreadToken
  • advapi32.dll.SetFileSecurityW
  • drvstore.dll.DriverStoreSetLogContext
  • drvstore.dll.DriverStoreImportW
  • advapi32.dll.AllocateAndInitializeSid
  • advapi32.dll.FreeSid
  • user32.dll.GetProcessWindowStation
  • user32.dll.GetUserObjectInformationW
  • user32.dll.GetThreadDesktop
  • cfgmgr32.dll.CM_Add_Driver_PackageW
  • wintrust.dll.CryptCATAdminAddCatalog
  • sechost.dll.ConvertStringSidToSidW
  • sechost.dll.OpenSCManagerW
  • sechost.dll.OpenServiceW
  • sechost.dll.QueryServiceConfigA
  • sechost.dll.QueryServiceStatus
  • sechost.dll.CloseServiceHandle
  • advapi32.dll.LookupAccountSidW
  • sechost.dll.LookupAccountSidLocalW
  • sechost.dll.LookupAccountNameLocalW
  • wintrust.dll.CryptCATAdminReleaseCatalogContext
  • cryptnet.dll.CryptGetObjectUrl
  • setupapi.dll.SetupDiGetDeviceInstallParamsW
  • setupapi.dll.SetupDiOpenDevRegKey
  • ole32.dll.CoInitializeSecurity
  • wudfsvc.dll.ServiceMain
  • wudfsvc.dll.SvchostPushServiceGlobals