魔盾安全分析报告

分析类型 开始时间 结束时间 持续时间 分析引擎版本
FILE 2018-03-23 19:54:21 2018-03-23 19:57:21 180 秒 1.4-Maldun
虚拟机机器名 标签 虚拟机管理 开机时间 关机时间
win7-sp1-x64-hpdapp01-1 win7-sp1-x64-hpdapp01-1 KVM 2018-03-23 19:54:53 2018-03-23 19:57:18
魔盾分数

4.2

可疑的

文件详细信息

文件名 10074_1上号器.exe
文件大小 15265104 字节
文件类型 PE32 executable (GUI) Intel 80386, for MS Windows
CRC32 4793342D
MD5 3961c3ece05b973db75a0210f027c809
SHA1 7a70fa5bcf62754dbea1a09589f76ec3a61891bd
SHA256 a319f23762fbfac179fbb8dc0c7f5d1d05ae680cd15abfa865ddf2d2fbdb1a7d
SHA512 f621c03e3cdc630b04ae5dc993d528a799b4b22a7ea50da8f47fd2a7702a0370e8e5673300cc4065a47cb6d870e86d0b33a59c2a598810d7a30e3748615e1fc5
Ssdeep 393216:+5LmGkx3pMTsqn89vTLvXv7s+/NfSgcFUbo8txD:CkxWn8lTD4SSP6boI
PEiD 无匹配
Yara 无Yara规则匹配
VirusTotal VirusTotal链接
VirusTotal扫描时间: 2018-02-06 02:20:56
扫描结果: 1/66

特征

创建RWX内存
从文件自身的二进制镜像中读取数据
self_read: process: 10074_1_________.exe, pid: 300, offset: 0x00066e00, length: 0x0001e020
self_read: process: 10074_1_________.exe, pid: 300, offset: 0x00e55da4, length: 0x0003855e
self_read: process: 10074_1_________.exe, pid: 300, offset: 0x00e8e304, length: 0x00000926
self_read: process: 10074_1_________.exe, pid: 300, offset: 0x00e8e950, length: 0x00000400
self_read: process: 10074_1_________.exe, pid: 300, offset: 0x00e8ec2a, length: 0x00000126
文件已被至少一个VirusTotal上的反病毒引擎检测为病毒
ESET-NOD32: a variant of Win32/Packed.Themida.AGK
异常的二进制特征
anomaly: Actual checksum does not match that reported in PE header
通过进程尝试长时间延迟分析任务
Process: msiexec.exe tried to sleep 120 seconds, actually delayed analysis time by 0 seconds

运行截图

网络分析

无信息

静态分析

PE 信息

初始地址 0x00400000
入口地址 0x0042f62e
声明校验值 0x0006301a
实际校验值 0x00e955a5
最低操作系统版本要求 5.0
编译时间 2012-12-20 23:26:49
载入哈希 64ac51d1685ad065533ce20c965f06ba

版本信息

LegalCopyright: Copyright (C) \u4e50\u6e38\u79df\u53f7\u4e0a\u53f7\u5668sh
InternalName: LYSHsetup
FileVersion: 1.0.0
CompanyName: shuyou
ProductName: \u4e50\u6e38\u79df\u53f7\u4e0a\u53f7\u5668sh
ProductVersion: 1.0.0
FileDescription: \u6b64 Installer \u6570\u636e\u5e93\u5305\u542b\u4e86\u5b89\u88c5 \u4e50\u6e38\u79df\u53f7\u4e0a\u53f7\u5668sh \u6240\u9700\u7684\u903b\u8f91\u548c\u6570\u636e\u3002
OriginalFileName: LYSHsetup.exe
Translation: 0x0804 0x04b0

PE数据组成

名称 虚拟地址 虚拟大小 原始数据大小 特征 熵(Entropy)
.text 0x00001000 0x0004315d 0x00043200 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6.57
.rdata 0x00045000 0x0000e282 0x0000e400 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4.57
.data 0x00054000 0x00003e3c 0x00002000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 3.88
.rsrc 0x00058000 0x000132e4 0x00013400 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6.78

覆盖

偏移量: 0x0006b2e4
大小: 0x00e23a6c

导入

库 KERNEL32.dll:
0x445040 - EnterCriticalSection
0x445044 - LoadLibraryExW
0x445048 - GetModuleHandleW
0x44504c - GetModuleFileNameW
0x445050 - InitializeCriticalSection
0x445054 - DeleteCriticalSection
0x445058 - InterlockedDecrement
0x44505c - InterlockedIncrement
0x445060 - LoadLibraryW
0x445064 - GetCurrentThreadId
0x445068 - CloseHandle
0x44506c - GetShortPathNameW
0x445070 - LeaveCriticalSection
0x445074 - GetCommandLineW
0x445078 - SetCurrentDirectoryW
0x44507c - CreateThread
0x445080 - GetDriveTypeW
0x445084 - GetFileAttributesW
0x445088 - GetVersionExW
0x44508c - CopyFileW
0x445090 - GetExitCodeThread
0x445094 - GetCurrentProcess
0x445098 - FlushInstructionCache
0x44509c - SetLastError
0x4450a0 - lstrcmpiW
0x4450a4 - FreeLibrary
0x4450a8 - GetLastError
0x4450ac - WriteFile
0x4450b0 - CreateFileW
0x4450b4 - FindResourceExW
0x4450b8 - FindResourceW
0x4450bc - LoadResource
0x4450c0 - LockResource
0x4450c4 - SizeofResource
0x4450c8 - CreateMutexW
0x4450cc - RaiseException
0x4450d0 - WriteConsoleW
0x4450d4 - GetConsoleOutputCP
0x4450d8 - WriteConsoleA
0x4450dc - SetStdHandle
0x4450e0 - LCMapStringA
0x4450e4 - GetConsoleMode
0x4450e8 - GetConsoleCP
0x4450ec - InitializeCriticalSectionAndSpinCount
0x4450f0 - lstrlenW
0x4450f4 - MultiByteToWideChar
0x4450f8 - SetFileAttributesW
0x4450fc - WideCharToMultiByte
0x445100 - GetModuleHandleA
0x445104 - RtlUnwind
0x445108 - LCMapStringW
0x44510c - GetStringTypeW
0x445110 - LocalAlloc
0x445114 - GetProcAddress
0x445118 - InterlockedExchange
0x44511c - LoadLibraryA
0x445120 - GetTempPathW
0x445124 - GetTempFileNameW
0x445128 - DeleteFileW
0x44512c - FindFirstFileW
0x445130 - FindNextFileW
0x445134 - RemoveDirectoryW
0x445138 - FindClose
0x44513c - CreateDirectoryW
0x445140 - GetLogicalDriveStringsW
0x445144 - GetFileSize
0x445148 - ReadFile
0x44514c - GetDiskFreeSpaceExW
0x445150 - SetFilePointer
0x445154 - SetEndOfFile
0x445158 - EnumResourceLanguagesW
0x44515c - GetLocaleInfoW
0x445160 - GetSystemDefaultLangID
0x445164 - GetUserDefaultLangID
0x445168 - GlobalMemoryStatus
0x44516c - OutputDebugStringW
0x445170 - GetCurrentProcessId
0x445174 - GetLocalTime
0x445178 - FlushFileBuffers
0x44517c - lstrcpynW
0x445180 - GetSystemDirectoryW
0x445184 - GetWindowsDirectoryW
0x445188 - GetEnvironmentVariableW
0x44518c - GetSystemTime
0x445190 - WaitForSingleObject
0x445194 - MulDiv
0x445198 - TerminateThread
0x44519c - CreateEventW
0x4451a0 - SetEvent
0x4451a4 - MoveFileW
0x4451a8 - Sleep
0x4451ac - ResetEvent
0x4451b0 - CreateFileA
0x4451b4 - CreateNamedPipeW
0x4451b8 - ConnectNamedPipe
0x4451bc - FormatMessageW
0x4451c0 - GetTempPathA
0x4451c4 - GetTempFileNameA
0x4451c8 - DuplicateHandle
0x4451cc - GetStdHandle
0x4451d0 - CreateProcessW
0x4451d4 - CreateProcessA
0x4451d8 - DeleteFileA
0x4451dc - GetExitCodeProcess
0x4451e0 - LockFile
0x4451e4 - UnlockFile
0x4451e8 - GetVersion
0x4451ec - GetLocaleInfoA
0x4451f0 - SearchPathW
0x4451f4 - OpenProcess
0x4451f8 - TerminateProcess
0x4451fc - GlobalLock
0x445200 - GlobalUnlock
0x445204 - GlobalAlloc
0x445208 - GlobalFree
0x44520c - lstrcmpW
0x445210 - HeapDestroy
0x445214 - HeapAlloc
0x445218 - HeapFree
0x44521c - HeapReAlloc
0x445220 - HeapSize
0x445224 - GetProcessHeap
0x445228 - InterlockedCompareExchange
0x44522c - IsProcessorFeaturePresent
0x445230 - VirtualFree
0x445234 - VirtualAlloc
0x445238 - GetStartupInfoW
0x44523c - UnhandledExceptionFilter
0x445240 - SetUnhandledExceptionFilter
0x445244 - IsDebuggerPresent
0x445248 - TlsGetValue
0x44524c - TlsAlloc
0x445250 - TlsSetValue
0x445254 - TlsFree
0x445258 - ExitProcess
0x44525c - HeapCreate
0x445260 - GetModuleFileNameA
0x445264 - GetCPInfo
0x445268 - GetACP
0x44526c - GetOEMCP
0x445270 - IsValidCodePage
0x445274 - FreeEnvironmentStringsW
0x445278 - GetEnvironmentStringsW
0x44527c - SetHandleCount
0x445280 - GetFileType
0x445284 - GetStartupInfoA
0x445288 - QueryPerformanceCounter
0x44528c - GetTickCount
0x445290 - GetSystemTimeAsFileTime
0x445294 - GetUserDefaultLCID
0x445298 - EnumSystemLocalesA
0x44529c - IsValidLocale
0x4452a0 - GetStringTypeA
库 USER32.dll:
0x4452dc - SetWindowPos
0x4452e0 - MapWindowPoints
0x4452e4 - GetClientRect
0x4452e8 - GetParent
0x4452ec - GetWindowRect
0x4452f0 - SystemParametersInfoW
0x4452f4 - GetWindowLongW
0x4452f8 - GetWindow
0x4452fc - EndDialog
0x445300 - CreateDialogParamW
0x445304 - GetSystemMetrics
0x445308 - GetDC
0x44530c - PeekMessageW
0x445310 - TranslateMessage
0x445314 - DispatchMessageW
0x445318 - GetForegroundWindow
0x44531c - SendMessageW
0x445320 - CreateWindowExW
0x445324 - EnableWindow
0x445328 - ScreenToClient
0x44532c - PostQuitMessage
0x445330 - CallWindowProcW
0x445334 - ShowWindow
0x445338 - GetPropW
0x44533c - IsWindowVisible
0x445340 - RedrawWindow
0x445344 - InvalidateRect
0x445348 - IsWindow
0x44534c - GetWindowTextW
0x445350 - GetWindowTextLengthW
0x445354 - SetWindowTextW
0x445358 - SetForegroundWindow
0x44535c - LoadImageW
0x445360 - GetSystemMenu
0x445364 - EnableMenuItem
0x445368 - DestroyMenu
0x44536c - MsgWaitForMultipleObjects
0x445370 - ModifyMenuW
0x445374 - FindWindowW
0x445378 - MessageBeep
0x44537c - ExitWindowsEx
0x445380 - GetScrollRange
0x445384 - GetScrollPos
0x445388 - GetDlgCtrlID
0x44538c - SetPropW
0x445390 - RemovePropW
0x445394 - TrackPopupMenu
0x445398 - LoadMenuW
0x44539c - GetSubMenu
0x4453a0 - SetTimer
0x4453a4 - KillTimer
0x4453a8 - LoadIconW
0x4453ac - ReleaseDC
0x4453b0 - GetDesktopWindow
0x4453b4 - OpenClipboard
0x4453b8 - CloseClipboard
0x4453bc - EmptyClipboard
0x4453c0 - SetClipboardData
0x4453c4 - UnregisterClassA
0x4453c8 - PostMessageW
0x4453cc - LoadStringW
0x4453d0 - DialogBoxParamW
0x4453d4 - MessageBoxW
0x4453d8 - GetActiveWindow
0x4453dc - SetWindowLongW
0x4453e0 - DefWindowProcW
0x4453e4 - CharNextW
0x4453e8 - DestroyWindow
0x4453ec - GetDlgItem
0x4453f0 - SetFocus
库 GDI32.dll:
0x445010 - GetDeviceCaps
0x445014 - DeleteObject
0x445018 - GetObjectW
0x44501c - DeleteDC
0x445020 - SetBkMode
0x445024 - GetStockObject
0x445028 - CreateCompatibleBitmap
0x44502c - CreateCompatibleDC
0x445030 - SelectObject
0x445034 - BitBlt
0x445038 - CreateFontIndirectW
库 SHELL32.dll:
0x4452b4 - ShellExecuteW
0x4452b8 - SHGetFolderPathW
0x4452bc - SHBrowseForFolderW
0x4452c0 - SHGetMalloc
0x4452c4 - SHGetPathFromIDListW
0x4452c8 - ShellExecuteExW
0x4452cc - SHGetSpecialFolderLocation
库 ole32.dll:
0x445408 - CreateStreamOnHGlobal
0x44540c - CreateILockBytesOnHGlobal
0x445410 - CoTaskMemRealloc
0x445414 - CoTaskMemAlloc
0x445418 - CoCreateInstance
0x44541c - CoTaskMemFree
0x445420 - CoUninitialize
0x445424 - StgCreateDocfileOnILockBytes
0x445428 - CoInitialize
库 OLEAUT32.dll:
0x4452a8 - VarUI4FromStr
0x4452ac - OleLoadPicture
库 SHLWAPI.dll:
0x4452d4 - PathFileExistsW
库 COMCTL32.dll:
0x445000 - PropertySheetW
0x445004 - DestroyPropertySheetPage
0x445008 - CreatePropertySheetPageW
库 VERSION.dll:
0x4453f8 - GetFileVersionInfoW
0x4453fc - GetFileVersionInfoSizeW
0x445400 - VerQueryValueW

投放文件

MSI3B2B.tmp

文件名 MSI3B2B.tmp
相关文件
  • C:\Users\test\AppData\Local\Temp\MSI3B2B.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3F41.tmp
  • C:\Users\test\AppData\Local\Temp\MSI405C.tmp
文件大小 70656 bytes
文件类型 PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 eaf178200165398c7aa371ef2b393f14
SHA1 97631dc2ac0c9d63a7eccc3f8ac27f8f34c3c2d0
SHA256 1d353986db1e09b7631896609fe935ff9c4a76a1b0c1822d66b1b5ed3bdd729e
SHA512 8592474f90735f163665f449985f79f8a40cac279c2fa684c9c22a7fea8b7bb63e5490db4c609b5cbd9e8e1908259bfbe9ee71097d570dc0dedf20555ba9a91d
Ssdeep 768:qSZqfk63/+Idc/b+VQTC3OfPxaQDIES1kZaP4WaPMtL1vmORkdxQ2DecxIiBSFdc:rqfk6WIssOfPxayZS2PeYsZ2z+D
VirusTotal 搜索相关分析

decoder.dll

文件名 decoder.dll
相关文件
  • C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install\decoder.dll
文件大小 122880 bytes
文件类型 PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 eb6a6d072f04ec1dc1f060c3f7b2936f
SHA1 131ab8a0f362d776c2fbda0d67ddf5fa83a5d3a1
SHA256 d3afa46a2d0f8a916b41e6660ac1dd40c8bffc149d7e8e765a367c2b5d3fad8e
SHA512 0ee534e3fd481ad9d8989df603270fe37e1e266c3477c2ec1c629f27be027e4394c0aed08c4e98ff9e9818aed5594c1f7624327588ebba6f90a0c942793b673f
Ssdeep 3072:NHLohTAI0NkxvLIe9R7Lw1Uz63MrWlhm+x:9o+5yxzIebLXq
VirusTotal 搜索相关分析

MSI3FEE.tmp

文件名 MSI3FEE.tmp
相关文件
  • C:\Users\test\AppData\Local\Temp\MSI3FEE.tmp
文件大小 275456 bytes
文件类型 PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 3a5745c8d2968d11e188be56b308cbe0
SHA1 bea328854744ae66844f8010a3a7ba9f86e3ab83
SHA256 08318908f3cc00bb24f679e982f7c0511ca4e87820e44c29281326f366da9201
SHA512 1a247146695dd8d76853cb531aeabb05d6d610f8712ffc8ffadc462f62ec0b8a294475ab6e80e74ee40242ce1699bc0fea60aecdac9b8f0bb87c858a071678da
Ssdeep 6144:OfnAqVqhElvjMec6zIsVNBH8Tq2n3Imiyq8a8MvYUmCUWDtF:O/AqVqhQQecOIsV/AWmiynaxYDs5F
VirusTotal 搜索相关分析

LYSHsetup.msi

文件名 LYSHsetup.msi
相关文件
  • C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install\3A9FAC3\LYSHsetup.msi
文件大小 561664 bytes
文件类型 Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Title: Installation Database, Keywords: Installer, MSI, Database, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Dec 11 11:47:44 2009, Number of Pages: 200, Security: 0, Code page: 936, Revision Number: {0FF4CD0F-D6B4-49AC-9E04-E45CD71CB5EF}, Number of Words: 0, Subject: sh, Author: shuyou, Name of Creating Application: Advanced Installer 9.8 build 48877, Template: ;2052, Comments: Installer sh
MD5 d038abd1dd3144227a72528f41590bbc
SHA1 3aedb2f6c6b11ecea1b0584b1b71dc2ba791a9f0
SHA256 07ee04d3f3367762814d37aa1d6d9dc2c471fb1f0231fa08e6d6eb5111500cc6
SHA512 7d43b2b90b514db114bd1ce6b9e848126027f8a056715fb311db5c11c790d540730adb824ca5fe2be5d1ee7b088b6ca77ca64f8c02bfa19b8ba03e1afc819327
Ssdeep 12288:Dfwh/AqVqhQQecOIsV/AWmiynaxYDs5FJeY5AKxf5H0V:DfmF6CP/fkax7JeY5AKz
VirusTotal 搜索相关分析

行为分析

互斥量(Mutexes)
  • Advinst_3ACB3D16E1D642ACB0D273687CFDDC28
  • Local\MSCTF.Asm.MutexDefault1
执行的命令
  • C:\Windows\system32\msiexec.exe /i "C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install\3A9FAC3\LYSHsetup.msi" AI_SETUPEXEPATH="C:\Users\test\AppData\Local\Temp\10074_1_________.exe" SETUPEXEDIR="C:\Users\test\AppData\Local\Temp\" EXE_CMD_LINE="/exenoupdates /exelang 0 /noprereqs "
创建的服务 无信息
启动的服务 无信息

进程

10074_1_________.exe PID: 300, 上一级进程 PID: 1960

msiexec.exe PID: 2068, 上一级进程 PID: 300

访问的文件
  • \Device\KsecDD
  • C:\Users\test\AppData\Local\Temp\10074_1_________.exe
  • C:\Users\test\AppData\Roaming
  • C:\Windows\SysWOW64\shell32.dll
  • C:\
  • C:\Users
  • \??\MountPointManager
  • C:\Users\test\AppData\Local\Microsoft\Windows\Caches
  • C:\Users\test\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
  • C:\Users\test\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000036.db
  • C:\Users\desktop.ini
  • C:\Users\test
  • C:\Users\test\AppData
  • C:\Users\test\Desktop\desktop.ini
  • C:\Windows\Fonts\staticcache.dat
  • C:\Windows\System32\msi.dll
  • \\?\C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install\
  • \\?\C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\
  • \\?\C:\Users\test\AppData\Roaming\shuyou\
  • \\?\C:\Users\test\AppData\Roaming\
  • C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install\decoder.dll
  • C:\Users\test\AppData\Roaming\shuyou
  • C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0
  • C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install
  • C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install\holder0.aiph
  • C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install\3A9FAC3
  • C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install\3A9FAC3\
  • \\?\C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install\3A9FAC3\
  • C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install\3A9FAC3\LYSHsetup.msi
  • C:\Windows\sysnative\msiexec.exe.Local\
  • C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac
  • C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll
  • C:\Windows\WindowsShell.Manifest
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Windows\sysnative\msimsg.dll
  • A:
  • B:
  • D:
  • E:
  • F:
  • G:
  • H:
  • I:
  • J:
  • K:
  • L:
  • M:
  • N:
  • O:
  • P:
  • Q:
  • R:
  • S:
  • T:
  • U:
  • V:
  • W:
  • X:
  • Y:
  • Z:
  • C:\Windows\AppPatch\AppPatch64\sysmain.sdb
  • C:\Windows\AppPatch\msimain.sdb
  • C:\Windows\sysnative\sxs.dll
  • C:\Windows\sysnative\*
  • C:\Windows\sysnative\ar-SA\sxs.DLL.mui
  • C:\Windows\sysnative\bg-BG\sxs.DLL.mui
  • C:\Windows\sysnative\cs-CZ\sxs.DLL.mui
  • C:\Windows\sysnative\da-DK\sxs.DLL.mui
  • C:\Windows\sysnative\de-DE\sxs.DLL.mui
  • C:\Windows\sysnative\el-GR\sxs.DLL.mui
  • C:\Windows\sysnative\en\sxs.DLL.mui
  • C:\Windows\sysnative\en-US\sxs.DLL.mui
  • C:\Windows\sysnative\es-ES\sxs.DLL.mui
  • C:\Windows\sysnative\et-EE\sxs.DLL.mui
  • C:\Windows\sysnative\fi-FI\sxs.DLL.mui
  • C:\Windows\sysnative\fr-FR\sxs.DLL.mui
  • C:\Windows\sysnative\he-IL\sxs.DLL.mui
  • C:\Windows\sysnative\hr-HR\sxs.DLL.mui
  • C:\Windows\sysnative\hu-HU\sxs.DLL.mui
  • C:\Windows\sysnative\it-IT\sxs.DLL.mui
  • C:\Windows\sysnative\ja-JP\sxs.DLL.mui
  • C:\Windows\sysnative\ko-KR\sxs.DLL.mui
  • C:\Windows\sysnative\lt-LT\sxs.DLL.mui
  • C:\Windows\sysnative\lv-LV\sxs.DLL.mui
  • C:\Windows\sysnative\nb-NO\sxs.DLL.mui
  • C:\Windows\sysnative\nl-NL\sxs.DLL.mui
  • C:\Windows\sysnative\pl-PL\sxs.DLL.mui
  • C:\Windows\sysnative\pt-BR\sxs.DLL.mui
  • C:\Windows\sysnative\pt-PT\sxs.DLL.mui
  • C:\Windows\sysnative\ro-RO\sxs.DLL.mui
  • C:\Windows\sysnative\ru-RU\sxs.DLL.mui
  • C:\Windows\sysnative\sk-SK\sxs.DLL.mui
  • C:\Windows\sysnative\sl-SI\sxs.DLL.mui
  • C:\Windows\sysnative\sr-Latn-CS\sxs.DLL.mui
  • C:\Windows\sysnative\sv-SE\sxs.DLL.mui
  • C:\Windows\sysnative\th-TH\sxs.DLL.mui
  • C:\Windows\sysnative\tr-TR\sxs.DLL.mui
  • C:\Windows\sysnative\uk-UA\sxs.DLL.mui
  • C:\Windows\sysnative\zh-HK\sxs.DLL.mui
  • C:\Windows\sysnative\zh-TW\sxs.DLL.mui
  • C:\Windows\sysnative\MSCOREE.DLL.local
  • C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
  • C:\Windows\Microsoft.NET\Framework64\v4.0.30319
  • C:\Windows\Microsoft.NET\Framework64\*
  • C:\Windows\Microsoft.NET\Framework64\v2.0.50727\clr.dll
  • C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
  • C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
  • C:\Windows\sysnative\msiexec.exe.config
  • C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll
  • C:\Users\test\AppData\Local\Temp\
  • C:\Users\test\AppData\Local\Temp
  • C:\Users\test\AppData\Local\Temp\MSI3B2B.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3F41.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3FEE.tmp
  • C:\Users\test\AppData\Local\Temp\MSI405C.tmp
  • C:\Windows\Installer\$PatchCache$\Managed\646F1E11E452022429768BE7349AAF3C
  • C:\MSId96.tmp
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\ClientFile\zhw.dll
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\ClientFile\x64\ProtectS.sys
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\Newtonsoft.Json.dll
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\UpdateFile\file.zip
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\ClientFile\WebGame.exe
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\ClientFile\ProtectS.sys
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\ClientFile\jsq.dll
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\ClientFile\unins000.exe
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\ClientFile\msvcp110.dll
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\icsharpcode.sharpziplib.dll
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\ClientFile\frame.dll
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\ClientFile\msvcr110.dll
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\ClientFile\client.exe
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\ClientFile\Sound\CFLoginHelp.wav
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\Newtonsoft.Json.xml
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\shuyouApplication.exe
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\shuyouApplication.exe.config
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\ClientFile\Sound\TimeOut.wav
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\ClientFile\uninst.dat
  • C:\Program Files (x86)\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\UpdateFile\update.txt
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh.lnk
  • C:\Users\Public\Desktop\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh.lnk
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh\\xe5\x8d\xb8\xe8\xbd\xbd.lnk
读取的文件
  • \Device\KsecDD
  • C:\Users\test\AppData\Local\Temp\10074_1_________.exe
  • C:\Windows\SysWOW64\shell32.dll
  • C:\
  • C:\Users\test\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
  • C:\Users\test\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000036.db
  • C:\Users\desktop.ini
  • C:\Users
  • C:\Users\test
  • C:\Users\test\AppData
  • C:\Users\test\Desktop\desktop.ini
  • C:\Windows\Fonts\staticcache.dat
  • C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install\decoder.dll
  • C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll
  • C:\Windows\WindowsShell.Manifest
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install\3A9FAC3\LYSHsetup.msi
  • C:\Windows\sysnative\msimsg.dll
  • C:\Windows\AppPatch\AppPatch64\sysmain.sdb
  • C:\Windows\AppPatch\msimain.sdb
  • C:\Windows\sysnative\sxs.dll
  • C:\Windows\sysnative\ar-SA\sxs.DLL.mui
  • C:\Windows\sysnative\bg-BG\sxs.DLL.mui
  • C:\Windows\sysnative\cs-CZ\sxs.DLL.mui
  • C:\Windows\sysnative\da-DK\sxs.DLL.mui
  • C:\Windows\sysnative\de-DE\sxs.DLL.mui
  • C:\Windows\sysnative\el-GR\sxs.DLL.mui
  • C:\Windows\sysnative\en\sxs.DLL.mui
  • C:\Windows\sysnative\en-US\sxs.DLL.mui
  • C:\Windows\sysnative\es-ES\sxs.DLL.mui
  • C:\Windows\sysnative\et-EE\sxs.DLL.mui
  • C:\Windows\sysnative\fi-FI\sxs.DLL.mui
  • C:\Windows\sysnative\fr-FR\sxs.DLL.mui
  • C:\Windows\sysnative\he-IL\sxs.DLL.mui
  • C:\Windows\sysnative\hr-HR\sxs.DLL.mui
  • C:\Windows\sysnative\hu-HU\sxs.DLL.mui
  • C:\Windows\sysnative\it-IT\sxs.DLL.mui
  • C:\Windows\sysnative\ja-JP\sxs.DLL.mui
  • C:\Windows\sysnative\ko-KR\sxs.DLL.mui
  • C:\Windows\sysnative\lt-LT\sxs.DLL.mui
  • C:\Windows\sysnative\lv-LV\sxs.DLL.mui
  • C:\Windows\sysnative\nb-NO\sxs.DLL.mui
  • C:\Windows\sysnative\nl-NL\sxs.DLL.mui
  • C:\Windows\sysnative\pl-PL\sxs.DLL.mui
  • C:\Windows\sysnative\pt-BR\sxs.DLL.mui
  • C:\Windows\sysnative\pt-PT\sxs.DLL.mui
  • C:\Windows\sysnative\ro-RO\sxs.DLL.mui
  • C:\Windows\sysnative\ru-RU\sxs.DLL.mui
  • C:\Windows\sysnative\sk-SK\sxs.DLL.mui
  • C:\Windows\sysnative\sl-SI\sxs.DLL.mui
  • C:\Windows\sysnative\sr-Latn-CS\sxs.DLL.mui
  • C:\Windows\sysnative\sv-SE\sxs.DLL.mui
  • C:\Windows\sysnative\th-TH\sxs.DLL.mui
  • C:\Windows\sysnative\tr-TR\sxs.DLL.mui
  • C:\Windows\sysnative\uk-UA\sxs.DLL.mui
  • C:\Windows\sysnative\zh-HK\sxs.DLL.mui
  • C:\Windows\sysnative\zh-TW\sxs.DLL.mui
  • C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
  • C:\Windows\sysnative\msiexec.exe.config
  • C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll
  • C:\Users\test\AppData\Local\Temp\MSI3B2B.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3F41.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3FEE.tmp
  • C:\Users\test\AppData\Local\Temp\MSI405C.tmp
修改的文件
  • C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install\decoder.dll
  • C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install\holder0.aiph
  • C:\Users\test\AppData\Roaming\shuyou\\xe4\xb9\x90\xe6\xb8\xb8\xe7\xa7\x9f\xe5\x8f\xb7\xe4\xb8\x8a\xe5\x8f\xb7\xe5\x99\xa8sh 1.0.0\install\3A9FAC3\LYSHsetup.msi
  • C:\Users\test\AppData\Local\Temp\MSI3B2B.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3F41.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3FEE.tmp
  • C:\Users\test\AppData\Local\Temp\MSI405C.tmp
删除的文件
  • C:\Users\test\AppData\Local\Temp\MSI3B2B.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3F41.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3FEE.tmp
  • C:\Users\test\AppData\Local\Temp\MSI405C.tmp
注册表键
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders
  • HKEY_CURRENT_USER
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\10074_1_________.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
  • HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Explorer
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Directory\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory
  • HKEY_CLASSES_ROOT\Directory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ShellEx\IconHandler
  • HKEY_CLASSES_ROOT\Folder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\IconHandler
  • HKEY_CLASSES_ROOT\AllFilesystemObjects
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\IconHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\10074_1_________.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3FC47A08-E5C9-4BCA-A2C7-BC9A282AED14}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
  • HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\MS Shell Dlg 2
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\UpgradeCodes\DD6E152F69304754CB9A0042815F1FA5
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\UpgradeCodes\DD6E152F69304754CB9A0042815F1FA5
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\UpgradeCodes\DD6E152F69304754CB9A0042815F1FA5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Version
  • HKEY_CURRENT_USER\InterbootContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\UseFilter
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\decoder.dll
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\\xe5\xae\x8b\xe4\xbd\x93
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\646F1E11E452022429768BE7349AAF3C
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\646F1E11E452022429768BE7349AAF3C
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\646F1E11E452022429768BE7349AAF3C
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\msiexec.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109110000000000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109110000000000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109110000000000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109110000000000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109110000000000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\000041091A0040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\000041091A0040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\000041091A0040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\000041091A0040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\000041091A0040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109440040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109440040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109440040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109440040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109440040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109510040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109510040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109510040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109510040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109510040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109610040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109610040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109610040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109610040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109610040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109810040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109810040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109810040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109810040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109810040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109820040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109820040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109820040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109820040800100000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109820040800100000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109820040800100000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800100000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800100000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109910040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109910040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109910040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109910040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109910040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109A10040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109A10040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109A10040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A10040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A10040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109A20000000100000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109A20000000100000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109A20000000100000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20000000100000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20000000100000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109A20040800100000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109A20040800100000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109A20040800100000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20040800100000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20040800100000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109AB0040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109AB0040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109AB0040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109AB0040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109AB0040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109B10040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109B10040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109B10040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109B10040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109B10040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109C20040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109C20040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109C20040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109C20040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109C20040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109E60040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109E60040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109E60040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109E60040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109E60040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109F10040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109F10040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109F10040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109F10090400000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109F10090400000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109F10090400000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10090400000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10090400000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\0547300BD62584433A07ACBC8D77960A
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\0547300BD62584433A07ACBC8D77960A
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\0547300BD62584433A07ACBC8D77960A
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0547300BD62584433A07ACBC8D77960A\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0547300BD62584433A07ACBC8D77960A\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\11E3B31B5551F3536AA39833EE01F4DB
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\11E3B31B5551F3536AA39833EE01F4DB
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\11E3B31B5551F3536AA39833EE01F4DB
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\11E3B31B5551F3536AA39833EE01F4DB\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\11E3B31B5551F3536AA39833EE01F4DB\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\40244AC97CCCA7330B93A3FB99A88B9A
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\40244AC97CCCA7330B93A3FB99A88B9A
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\40244AC97CCCA7330B93A3FB99A88B9A
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\40244AC97CCCA7330B93A3FB99A88B9A\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\40244AC97CCCA7330B93A3FB99A88B9A\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\4EA42A62D9304AC4784BF2238110120F
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\4EA42A62D9304AC4784BF2238110120F
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\4EA42A62D9304AC4784BF2238110120F
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\4EA42A62D9304AC4784BF2238110120F\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\4EA42A62D9304AC4784BF2238110120F\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\62DBF9290209B993A9A757D1160F9B24
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\62DBF9290209B993A9A757D1160F9B24
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\62DBF9290209B993A9A757D1160F9B24
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\62DBF9290209B993A9A757D1160F9B24\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\62DBF9290209B993A9A757D1160F9B24\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\68AB67CA7DA72502B744BA0000000010
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\68AB67CA7DA72502B744BA0000000010
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\68AB67CA7DA72502B744BA0000000010
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\68AB67CA7DA72502B744BA0000000010\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\68AB67CA7DA72502B744BA0000000010\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\7C9F8B73BF303523781852719CD9C700
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\7C9F8B73BF303523781852719CD9C700
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\7C9F8B73BF303523781852719CD9C700
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\7C9F8B73BF303523781852719CD9C700\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\7C9F8B73BF303523781852719CD9C700\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\91915B2EA702BE34EA8737F3C976792C
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\91915B2EA702BE34EA8737F3C976792C
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\91915B2EA702BE34EA8737F3C976792C
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\91915B2EA702BE34EA8737F3C976792C\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\91915B2EA702BE34EA8737F3C976792C\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\B4C5FD36FB3E64330A335CB7224FC4E9
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\B4C5FD36FB3E64330A335CB7224FC4E9
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\B4C5FD36FB3E64330A335CB7224FC4E9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\B4C5FD36FB3E64330A335CB7224FC4E9\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\B4C5FD36FB3E64330A335CB7224FC4E9\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\F60730A4A66673047777F5728467D401
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\F60730A4A66673047777F5728467D401
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\F60730A4A66673047777F5728467D401
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401\InstanceType
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
  • HKEY_CURRENT_USER\Software\Classes
  • HKEY_CURRENT_USER\Software\Classes\Interface\{000C101C-0000-0000-C000-000000000046}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000C101C-0000-0000-C000-000000000046}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000C101C-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}
  • HKEY_CURRENT_USER\Software\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\TreatAs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\TreatAs
  • HKEY_CURRENT_USER\Software\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\Progid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\Progid
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\Progid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\Progid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\InProcServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\InProcServer32\ThreadingModel
  • HKEY_CURRENT_USER\Software\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\InprocHandler32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\InprocHandler32
  • HKEY_CURRENT_USER\Software\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\InprocHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\InprocHandler
  • HKEY_CLASSES_ROOT\CLSID\{000C101D-0000-0000-C000-000000000046}\DllVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C101D-0000-0000-C000-000000000046}\DllVersion\(Default)
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\646F1E11E452022429768BE7349AAF3C\InstallProperties
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\AppCompat
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\{11e1f646-254e-4220-9267-b87e43a9fac3}
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\CustomLocale
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\.
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\..
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\0409
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\AdvancedInstallers
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Boot
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\catroot
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\catroot2
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\CodeIntegrity
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\com
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\config
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Dism
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\drivers
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\DriverStore
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\FxsTmp
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\GroupPolicy
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\GroupPolicyUsers
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ias
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\icsxml
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\IME
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\inetsrv
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\LogFiles
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Macromed
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\manifeststore
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Microsoft
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\migration
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\migwiz
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Msdtc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\MUI
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\NDF
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\NetworkList
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\oobe
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Printing_Admin_Scripts
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ras
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Recovery
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\restore
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Setup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\slmgr
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SMI
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Speech
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\spool
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\spp
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sppui
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sysprep
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Tasks
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wbem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\WCN
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wdi
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wfp
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\WinBioDatabase
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\WinBioPlugIns
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\WindowsPowerShell
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\winevt
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\winrm
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-CHS
  • HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\v4.0
  • HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\InstallRoot
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CLRLoadLogDir
  • HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\msi.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\msi.dll\{462EF42B-ABA4-4eac-9843-9EED260F54D0}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\msi.dll\{462EF42B-ABA4-4eac-9843-9EED260F54D0}\Registry Keys
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\msi.dll\{462EF42B-ABA4-4eac-9843-9EED260F54D0}\Relative Files
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\msi.dll\{462EF42B-ABA4-4eac-9843-9EED260F54D0}\Target Version
  • HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\OnlyUseLatestCLR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full\Release
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Policies\Microsoft\Windows\Installer
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\PendingFileRenameOperations
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
  • HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOwner
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOrganization
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\InProgress
  • HKEY_CURRENT_USER\Control Panel\International
  • HKEY_CURRENT_USER\Control Panel\International\LocaleName
  • HKEY_CURRENT_USER\Software\Classes\Interface\{000C1033-0000-0000-C000-000000000046}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000C1033-0000-0000-C000-000000000046}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000C1033-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{000C1025-0000-0000-C000-000000000046}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000C1025-0000-0000-C000-000000000046}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000C1025-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Tahoma
  • HKEY_LOCAL_MACHINE\Software\Caphyon\Advanced Installer\LZMA\{11E1F646-254E-4220-9267-B87E43A9FAC3}\1.0.0
  • HKEY_CURRENT_USER\Software\Caphyon\Advanced Installer\LZMA\{11E1F646-254E-4220-9267-B87E43A9FAC3}\1.0.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Install
  • HKEY_CURRENT_USER\Software\Microsoft\CTF\LayoutIcon\0804\00000804
读取的注册表键
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InitFolderHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InitFolderHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\UseFilter
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\decoder.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\\xe5\xae\x8b\xe4\xbd\x93
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109110000000000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109110000000000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\000041091A0040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\000041091A0040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109440040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109440040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109510040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109510040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109610040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109610040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109810040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109810040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800100000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800100000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109910040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109910040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A10040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A10040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20000000100000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20000000100000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20040800100000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20040800100000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109AB0040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109AB0040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109B10040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109B10040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109C20040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109C20040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109E60040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109E60040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10090400000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10090400000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0547300BD62584433A07ACBC8D77960A\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0547300BD62584433A07ACBC8D77960A\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\11E3B31B5551F3536AA39833EE01F4DB\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\11E3B31B5551F3536AA39833EE01F4DB\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\40244AC97CCCA7330B93A3FB99A88B9A\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\40244AC97CCCA7330B93A3FB99A88B9A\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\4EA42A62D9304AC4784BF2238110120F\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\4EA42A62D9304AC4784BF2238110120F\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\62DBF9290209B993A9A757D1160F9B24\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\62DBF9290209B993A9A757D1160F9B24\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\68AB67CA7DA72502B744BA0000000010\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\68AB67CA7DA72502B744BA0000000010\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\7C9F8B73BF303523781852719CD9C700\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\7C9F8B73BF303523781852719CD9C700\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\91915B2EA702BE34EA8737F3C976792C\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\91915B2EA702BE34EA8737F3C976792C\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\B4C5FD36FB3E64330A335CB7224FC4E9\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\B4C5FD36FB3E64330A335CB7224FC4E9\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401\InstanceType
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000C101C-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\InProcServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\InProcServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C101D-0000-0000-C000-000000000046}\DllVersion\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\.
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\..
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\0409
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\AdvancedInstallers
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Boot
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\catroot
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\catroot2
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\CodeIntegrity
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\com
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\config
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Dism
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\drivers
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\DriverStore
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\FxsTmp
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\GroupPolicy
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\GroupPolicyUsers
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ias
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\icsxml
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\IME
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\inetsrv
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\LogFiles
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Macromed
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\manifeststore
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Microsoft
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\migration
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\migwiz
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Msdtc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\MUI
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\NDF
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\NetworkList
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\oobe
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Printing_Admin_Scripts
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ras
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Recovery
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\restore
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Setup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\slmgr
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SMI
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Speech
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\spool
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\spp
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sppui
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sysprep
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Tasks
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wbem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\WCN
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wdi
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wfp
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\WinBioDatabase
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\WinBioPlugIns
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\WindowsPowerShell
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\winevt
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\winrm
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-CHS
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\InstallRoot
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CLRLoadLogDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\msi.dll\{462EF42B-ABA4-4eac-9843-9EED260F54D0}\Target Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\OnlyUseLatestCLR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full\Release
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\PendingFileRenameOperations
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOwner
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOrganization
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization
  • HKEY_CURRENT_USER\Control Panel\International\LocaleName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000C1033-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000C1025-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Install
修改的注册表键 无信息
删除的注册表键 无信息
API解析
  • kernel32.dll.FlsAlloc
  • kernel32.dll.FlsGetValue
  • kernel32.dll.FlsSetValue
  • kernel32.dll.FlsFree
  • kernel32.dll.IsProcessorFeaturePresent
  • cryptbase.dll.SystemFunction036
  • ole32.dll.StringFromGUID2
  • advapi32.dll.OpenThreadToken
  • ole32.dll.CoInitializeEx
  • ole32.dll.CreateBindCtx
  • ole32.dll.CoTaskMemAlloc
  • ole32.dll.CoGetApartmentType
  • ole32.dll.CoRegisterInitializeSpy
  • ole32.dll.CoTaskMemFree
  • comctl32.dll.#236
  • oleaut32.dll.#6
  • ole32.dll.CoGetMalloc
  • comctl32.dll.#320
  • comctl32.dll.#324
  • comctl32.dll.#323
  • comctl32.dll.#328
  • comctl32.dll.#334
  • advapi32.dll.RegEnumKeyW
  • setupapi.dll.CM_Get_Device_Interface_List_Size_ExW
  • oleaut32.dll.#2
  • setupapi.dll.CM_Get_Device_Interface_List_ExW
  • ole32.dll.CoCreateInstance
  • comctl32.dll.#332
  • comctl32.dll.#386
  • advapi32.dll.InitializeSecurityDescriptor
  • advapi32.dll.SetEntriesInAclW
  • ntmarta.dll.GetMartaExtensionInterface
  • advapi32.dll.SetSecurityDescriptorDacl
  • advapi32.dll.IsTextUnicode
  • comctl32.dll.#338
  • comctl32.dll.#339
  • shell32.dll.#102
  • ole32.dll.CoUninitialize
  • kernel32.dll.InterlockedPushEntrySList
  • kernel32.dll.InterlockedPopEntrySList
  • comctl32.dll.RegisterClassNameW
  • uxtheme.dll.EnableThemeDialogTexture
  • ole32.dll.CoRevokeInitializeSpy
  • gdi32.dll.GetLayout
  • gdi32.dll.GdiRealizationInfo
  • gdi32.dll.FontIsLinked
  • advapi32.dll.RegOpenKeyExW
  • advapi32.dll.RegQueryInfoKeyW
  • gdi32.dll.GetTextFaceAliasW
  • advapi32.dll.RegEnumValueW
  • advapi32.dll.RegCloseKey
  • advapi32.dll.RegQueryValueExW
  • advapi32.dll.RegQueryValueExA
  • advapi32.dll.RegEnumKeyExW
  • gdi32.dll.GetTextExtentExPointWPri
  • gdi32.dll.GetFontAssocStatus
  • msi.dll.#205
  • kernel32.dll.GetNativeSystemInfo
  • kernel32.dll.IsWow64Process
  • advapi32.dll.RegOpenKeyExA
  • advapi32.dll.RegDeleteKeyA
  • decoder.dll.InitExtraction
  • decoder.dll.GetTotalFilesSize
  • decoder.dll.ExtractAllFiles
  • decoder.dll.EndExtraction
  • uxtheme.dll.OpenThemeData
  • kernel32.dll.GetSystemDefaultUILanguage
  • kernel32.dll.GetUserDefaultUILanguage
  • kernel32.dll.Wow64DisableWow64FsRedirection
  • kernel32.dll.Wow64RevertWow64FsRedirection
  • lpk.dll.LpkEditControl
  • comctl32.dll.InitCommonControlsEx
  • kernel32.dll.SortGetHandle
  • kernel32.dll.SortCloseHandle
  • kernel32.dll.HeapSetInformation
  • ntdll.dll.WinSqmIsOptedIn
  • shlwapi.dll.UrlIsW
  • ole32.dll.StgOpenStorage
  • cryptsp.dll.CryptAcquireContextW
  • cryptsp.dll.CryptGenRandom
  • kernel32.dll.GetThreadPreferredUILanguages
  • shell32.dll.SHGetPropertyStoreForWindow
  • propsys.dll.PSStringFromPropertyKey
  • propsys.dll.PropVariantToString
  • ole32.dll.CoInitialize
  • netapi32.dll.NetGetJoinInformation
  • netapi32.dll.NetApiBufferFree
  • kernel32.dll.GetFileAttributesExW
  • advapi32.dll.CreateWellKnownSid
  • advapi32.dll.CheckTokenMembership
  • advapi32.dll.SaferiChangeRegistryScope
  • advapi32.dll.SaferIdentifyLevel
  • advapi32.dll.SaferGetLevelInformation
  • advapi32.dll.SaferCloseLevel
  • ole32.dll.CoQueryProxyBlanket
  • msi.dll.DllGetClassObject
  • msi.dll.DllCanUnloadNow
  • ole32.dll.CoSetProxyBlanket
  • apphelp.dll.ApphelpGetMsiProperties
  • apphelp.dll.SdbInitDatabase
  • apphelp.dll.SdbFindFirstMsiPackage_Str
  • apphelp.dll.SdbReleaseDatabase
  • version.dll.GetFileVersionInfoSizeW
  • version.dll.GetFileVersionInfoW
  • version.dll.VerQueryValueW
  • mscoree.dll.GetCORSystemDirectory
  • kernel32.dll.InitializeCriticalSectionEx
  • kernel32.dll.CreateEventExW
  • kernel32.dll.CreateSemaphoreExW
  • kernel32.dll.SetThreadStackGuarantee
  • kernel32.dll.CreateThreadpoolTimer
  • kernel32.dll.SetThreadpoolTimer
  • kernel32.dll.WaitForThreadpoolTimerCallbacks
  • kernel32.dll.CloseThreadpoolTimer
  • kernel32.dll.CreateThreadpoolWait
  • kernel32.dll.SetThreadpoolWait
  • kernel32.dll.CloseThreadpoolWait
  • kernel32.dll.FlushProcessWriteBuffers
  • kernel32.dll.FreeLibraryWhenCallbackReturns
  • kernel32.dll.GetCurrentProcessorNumber
  • kernel32.dll.GetLogicalProcessorInformation
  • kernel32.dll.CreateSymbolicLinkW
  • kernel32.dll.EnumSystemLocalesEx
  • kernel32.dll.CompareStringEx
  • kernel32.dll.GetDateFormatEx
  • kernel32.dll.GetLocaleInfoEx
  • kernel32.dll.GetTimeFormatEx
  • kernel32.dll.GetUserDefaultLocaleName
  • kernel32.dll.IsValidLocaleName
  • kernel32.dll.LCMapStringEx
  • kernel32.dll.GetTickCount64
  • kernel32.dll.AcquireSRWLockExclusive
  • kernel32.dll.ReleaseSRWLockExclusive
  • advapi32.dll.EventRegister
  • mscoree.dll.#142
  • mscoreei.dll.RegisterShimImplCallback
  • mscoreei.dll.OnShimDllMainCalled
  • mscoreei.dll.GetCORSystemDirectory_RetAddr
  • kernel32.dll.GetSystemWindowsDirectoryW
  • shell32.dll.SHGetFolderPathW
  • shell32.dll.DllGetVersion
  • ntdll.dll.NtQuerySystemInformation
  • kernel32.dll.GlobalMemoryStatusEx
  • kernel32.dll.CheckElevationEnabled
  • msihnd.dll.DllGetClassObject
  • ntdll.dll.NtMapViewOfSection
  • ntdll.dll.RtlImageNtHeaderEx
  • kernel32.dll.GetEnvironmentStringsW
  • ole32.dll.CoIsHandlerConnected
  • kernel32.dll.FreeEnvironmentStringsW
  • user32.dll.AllowSetForegroundWindow
  • rpcrt4.dll.I_RpcBindingInqLocalClientPID
  • oleaut32.dll.#500
  • user32.dll.ChangeWindowMessageFilterEx
  • gdi32.dll.GdiIsMetaPrintDC
  • oleaut32.dll.SysAllocString
  • oleaut32.dll.SysStringLen
  • oleaut32.dll.SysFreeString