魔盾安全分析报告

分析类型 开始时间 结束时间 持续时间 分析引擎版本
URL 2018-05-21 23:13:15 2018-05-21 23:15:43 148 秒 1.4-Maldun
虚拟机机器名 标签 虚拟机管理 开机时间 关机时间
win7-sp1-x64-hpdapp03-1 win7-sp1-x64-hpdapp03-1 KVM 2018-05-21 23:13:15 2018-05-21 23:15:34
魔盾分数

1.95

正常的

URL信息

URL http://t.cn/Ruihs6R
VirusTotal VirusTotal无域名信息

特征

投放了一个或多个文件
file: c:\users\test\appdata\local\google\chrome\user data\default\extension state\manifest-000001
创建一个隐藏文件或系统文件
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF4de077.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF4e2303.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF4e2351.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Managed Mode Settings~RF4e2370.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF4e23ce.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF4e3fa2.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old~RF54e6fc.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\CURRENT~RF54e73b.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF54e779.TMP
file: C:\Users\test\AppData\Local\Temp\etilqs_lrIQrccocdifeBF
file: C:\Users\test\AppData\Local\Temp\etilqs_yBEkEHGn2VI9qDm
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF5b753e.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF5b755d.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF5b902a.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF5c6355.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF5c63f1.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF62a34a.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF693087.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF693114.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF6a4800.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF6a48ab.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF6d9de4.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF714f91.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF77dd0c.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF77dda8.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF7914f4.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF7915de.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF801c97.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF86aa01.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF86aaeb.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF87e030.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF87e0eb.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF88a839.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF8ee830.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF9574ef.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF95758b.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF96aac0.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF96ab7b.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF9772ba.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF9db291.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFa43fae.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFa4404a.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFa5f11e.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RFa5f1c9.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFa5f284.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFac3e1e.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFb2bf1b.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFb2bfd6.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFb3e5df.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFb3e6e8.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFb4ae46.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFbaedee.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFc17b1a.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc17bd5.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFc2af17.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc2b011.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc32a0b.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc9b775.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFd0452e.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd045e9.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFd17c47.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd17c85.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd3a408.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd8839c.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFdf1847.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFdf1875.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFe38535.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFe385b2.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFe3ff0f.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFea8c5a.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFea8c89.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFf11a13.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf11a52.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFf2513c.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RFf2518a.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf251d8.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf2caa9.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf95880.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFffe60a.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFffe658.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF1034294.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF10342e2.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF103bc01.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF10a49d8.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF110d762.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF110d7a1.TMP
file: C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF11288e2.TMP
file: C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF1128930.TMP
通过进程尝试长时间延迟分析任务
Process: chrome.exe tried to sleep 722 seconds, actually delayed analysis time by 0 seconds

运行截图

网络分析

访问主机记录

直接访问 IP地址 国家名
203.208.41.47 China

域名解析

域名 响应
www.gstatic.com A 203.208.41.55
A 203.208.41.63
A 203.208.41.56
A 203.208.41.47

TCP连接

IP地址 端口
203.208.41.47 443

UDP连接

IP地址 端口
192.168.122.1 53
192.168.122.1 53

投放文件

Top Sites-journal

文件名 Top Sites-journal
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Top Sites-journal
文件大小 16384 bytes
文件类型 data
MD5 cd8b61a3cc48913ac86cb0f7ea4854d4
SHA1 682619d0d261a4147cce771760069a61a7831062
SHA256 dd05603ba71560b3b0ae7ae6475d653cc92019954dae1c18a8777f6f4d6747eb
SHA512 b715fbc77e5d075203a98d548d8bca854ca2205206b9de5a153baebb0ab8c197579413a4a0b013565c5df9eb59b818ad8ef66f00c754cdf7ef86a91979b76d52
Ssdeep 24:vvcsqLySl709YPNE6UwTqLNl709YPNE6Uw3tnqLK:v5q77zPpUqq77zPpUEq
VirusTotal 搜索相关分析

data_2

文件名 data_2
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2
文件大小 1056768 bytes
文件类型 data
MD5 419fe9ac23f52b9f918d232572058a37
SHA1 dfa254ac2ab22d72bb9e91b7f5574507e8d2ac6b
SHA256 0efddaf0e3d65f9b74433582ac6fee1abb8da2b84cb3e4b5b53c82861bdeb4c0
SHA512 49f4ba38827351193927b222a67c6ca7e47002d8a0927c9a177ef7d32bfd852ff351db1c65cff0833bbb4aa5298b90f14f1c69db7b3023066014fd1bdc65f582
Ssdeep 3072:3J7EsN4DGJc/KDF88U9brpkwVy+Jl34CjjyK2Ozdje:57VQG6/KR4kX+JVJjjyK2O5j
VirusTotal 搜索相关分析

index

文件名 index
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\index
文件大小 262512 bytes
文件类型 data
MD5 0db52dc27c888afe076f49bdb3b7e6df
SHA1 9511b543d19bffce8dfed0a55c7858c240e22e14
SHA256 f25434767f1169eef25200d8e5231e5c64be582b82e4eb20260d81017e325575
SHA512 25d63061e6c12a565089194801feaf40e90ac9939a1e791b6d9f84d124a86e07d9cfb2a14cd710bd8a1449e3db858abbffb01ffd70a707e7b752e287cabd96bc
Ssdeep 24:s6z8ouJM4mX1lTuK36yIoenST6fM/4tmaQOCM/lVz:siwmZf61dJaOC
VirusTotal 搜索相关分析

989a.tmp

文件名 989a.tmp
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\989a.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\98ab.tmp
文件大小 150798 bytes
文件类型 MS Windows icon resource - 12 icons, 8x8
MD5 0146a4b8a4b12914fed212d9247855fe
SHA1 74a1a60b480510f2028aa8989526fb42b99a9f66
SHA256 0cae09b4abd00feaf104e0e381fb433012b4fceafe1a3df05b97057af257b22b
SHA512 feec81e8735c07781d32d3072dc5cc1b0d0c29062bfc01acf6d2af20be4eccad4d892fa33567ec192fc025791502dcae44ba7cfd1fb2734d3ea7b70c01909e7b
Ssdeep 1536:fcF6DcdHF28foSghSkEwunHxyLuAaUfR4x0M:fcQDcdHF28flg4kE7lW+T
VirusTotal 搜索相关分析

MANIFEST-000034

文件名 MANIFEST-000034
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\MANIFEST-000034
文件大小 1588 bytes
文件类型 data
MD5 b2ecb925ecb48383f2c748f3e23e216b
SHA1 99f6be8b8fb0efe99d1b894650ff5114e99fc540
SHA256 ba54bb82da22ed3f700429cecb9619bb0b84385eb8f291a36be48a2b58711452
SHA512 bfcce6fd6bdc9bac78c8bd000fc7169cb3dd03d793e31211df9b2304613ee3a3514c6f7685500058c3f73f0f399b34d7a6433f33f456196a1c784431572e9ee4
Ssdeep 24:zyCuHJuHqLDUALDUz+yz1Py3kch7Yukch7YMrwluBtjuBtxz5Pz5xz6Xz6TgTdgp:WXoeYUYV1aUBi61pHSXGdGqc7OXUoV
VirusTotal 搜索相关分析

History Provider Cache

文件名 History Provider Cache
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
文件大小 933 bytes
文件类型 data
MD5 9251842e6c6ab06f12754f03fa9dd71e
SHA1 60bc8432366f2ae226085de2bad1941badfc5485
SHA256 d7d6342694a25ba5350159f69c35471d309e8debfcc21326d7f02a627a54dbd8
SHA512 2b6271a4939f524c422d887e311f382cb9ed0064d83d04e2f864882c513c2496e66ece4e116b22466ac23f5155c54f9770368c941ab8d130bbfda4a5795479fb
Ssdeep 24:stlZmA+f7UPwBrdqv6p5r+IhM4hEnhEaNFRvx:S4A+Bx4v6HrbhDynyaNFRvx
VirusTotal 搜索相关分析

Archived History-journal

文件名 Archived History-journal
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Archived History-journal
文件大小 25136 bytes
文件类型 data
MD5 d4114b098a1697f6f3d4f9dbbe6dd853
SHA1 69ceff2b8c0b33c3ca2e77cb62a3fd98b70e606f
SHA256 2b8a0ca1ada98be7702826f3525504272702a4908e9a8ce4df0d8bed57de954a
SHA512 aa4e5f05c6a6b02b07f534388a59e5f851006574465de9c05af7158e1d9f4b00e622177e852413ddb260401ddc57fec0ddf943b2de200f4e47ec6b10f721b0eb
Ssdeep 3:Hn/rl9tFllI/fllnn/hollNllnn/ivllNllnn/tvtfllnn/svXFllnn/gotfllnd:H/rlI/h4f/sJ/tvh/uR/ttt
VirusTotal 搜索相关分析

History-journal

文件名 History-journal
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History-journal
文件大小 57968 bytes
文件类型 data
MD5 59f99feb8d84be2d3726971f93843ab6
SHA1 78fee5576caeabaeddd31f4adf9e21f7bee10a95
SHA256 f19c14b9b81cdae4de4f46c7642893d271536259a18a6f49a56ffceb52fb9d01
SHA512 f9eef6e553d1dd58bb4e979f28e5c4f789abcdd62e3fdb2554375e2bfd5bedaddc1553901ee747c57895ab2b500bf938a15e86207926036b4f434dc29afb5480
Ssdeep 48:VZHpwPf+WLq77i5euvSftHzNzr0rmudHYH+BAL:VZJwPf+WLE7icuqf7ZdH+By
VirusTotal 搜索相关分析

LOG

文件名 LOG
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG
文件大小 47 bytes
文件类型 ASCII text, with CRLF line terminators
MD5 e1127b53f1b2c28710d8156488b2365f
SHA1 1be787af30a8d9a60b7f81bdfb9f818eeac69c74
SHA256 e6ac950f2c12fe79b566c12506a3bbff707d57197230366799241874c63505a9
SHA512 cec21e6911dc5c3d3ae868a91562c68219af4b7560a8a5c2470bb4a4a4aad4a9946ccb274c63a5db9a08f1df29c1192657e49ec767040a4b34663d0ca2e5ff2b
Ssdeep 3:uoQKHocW+QLmtEl7WFy:uN+WvAM7v
VirusTotal 搜索相关分析

Favicons-journal

文件名 Favicons-journal
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
文件大小 14904 bytes
文件类型 data
MD5 dc40dd68a550e738720224e6ce4409cb
SHA1 0d39d107b3d267cdddb6c7b255068bf4493bf48a
SHA256 70bd210914ff972ee17230a371a3d0117bfed074a65ba071395893cf7fe721a8
SHA512 7bf630c9bedb92afbaff60baded7b166268cc41daa40f1113f25b4f9a4182937119d96aca270e87d28a32c420900d8933af697a9eaebdeb0eb3ef41fff28953f
Ssdeep 24:ZsYD4sY0EeruA+gLnsxQ1O6grA+gLnsxQ1O6gA:ZJfTEerP+0nU80U+0nU80A
VirusTotal 搜索相关分析

data_3

文件名 data_3
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3
文件大小 4202496 bytes
文件类型 data
MD5 f15c1e527f137582e8f05211e3c0bf22
SHA1 ecb7e2cfa6541c11c111377275d07587e3920f47
SHA256 45341e0d0e52ac39634f96aa4cba734468a8f18a6092f29c66200ecd088d0901
SHA512 0dfaf613dc71cd900bfa217885dce1511cb1d6607fa267ce4fc8a51e6eefd24f044082c9e795e0499d1314ac7fbdacb91d56d6d034c72fc3181bea2f60c8dc90
Ssdeep 6144:ispNJvA16kbtTS5cbdTn6GmiSytlnwc3IWJAmJSghw9q0KIjl:ispHvIxm5cbx6XWtlwcbAUm9qPKl
VirusTotal 搜索相关分析

000035.sst

文件名 000035.sst
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000035.sst
文件大小 159 bytes
文件类型 data
MD5 1aadd4067fa87f146e810ee74e8a8cd5
SHA1 78ddb56c1c52a308a8581eba714565b88741b39d
SHA256 5ace2e96cf0a00f193c0c33e0bc47a4b28c65edf37dc5ec80e6f5084b2fa10e6
SHA512 2b2d1f0367509800ec1c754ee16e4de96c5d0a60840646148865178b87cf282b7ef1208b98c249eba46006fb92a19488911f15a35cde90ff5aa776c7706ea9f3
Ssdeep 3:zI5EG7VfdAjG6k3f0QTnllCWi+lkcul/atS0Ovltr7:JOdAjGP3f0GnllQa+taA9d
VirusTotal 搜索相关分析

History Index 2017-09-journal

文件名 History Index 2017-09-journal
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History Index 2017-09-journal
文件大小 25136 bytes
文件类型 data
MD5 81ee42e0562cd8938a79a20cfdec3a82
SHA1 1d36597be9648faac824d5b23fe97024c5e8a372
SHA256 50a5b11e6519a945dd6562aa928bdb0ea849b94b6f0db5392aa69eade548c4d4
SHA512 443840bcb52343a92211bff59f7bb21ca638f0785ccee419b0bec08bc01a861c2af706527c7d5e07368b873bc81e66ff8e6eb0814d1ec020c70fd980d9b9b3f6
Ssdeep 48:YRYxqxhuWqncmxiDpZ2hxiDtcPFL/HZlm/MYPTQ:YWiEHSpZWSaLvnmkYPTQ
VirusTotal 搜索相关分析

Top Sites

文件名 Top Sites
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Top Sites
文件大小 40960 bytes
文件类型 SQLite 3.x database
MD5 baa521db090de087cb59ec59f8fece5e
SHA1 766ea2e6b31ffa8766ab33139613dc89bb31a7f5
SHA256 0302a36693099e39db6d54b9565aaf0dbe0fa461b6b355d2ed5d97128c5eec84
SHA512 195a008886b9a9db8c1d49ec57cdef3378ef0c833f1c0d0e2884062d0dcd63a9464a0389ce8341872c6cadf7f46edf19d1a1b55c807d298461e7a9508fc9fb45
Ssdeep 12:TL90KLBO4rOrLSOmZNPNEFxOUwa8tXLfuogMpJPXoDvXc/Ao4vXciNIccodccoT6:TL9l709YPNE6UwPLGogMpNYk2l
VirusTotal 搜索相关分析

Web Data-journal

文件名 Web Data-journal
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal
文件大小 16384 bytes
文件类型 data
MD5 79a927bd9d86f8952cb74d4fc3a93f52
SHA1 907a6e2f12b9b3aa5a9076219aee7e656eecaa82
SHA256 2d6c2e7b04121a9f38d9c38be0dd4c05744f2e54ca02954c23291b87be6d3a66
SHA512 5b3aa267ccda02210acb9f8afc0f6a9c3d18a856a53f98a46c78d80aed193a66c47143eba0e6bdb445c8c2be3ff45138e24f9a517e9c4bb2a78d9f41741f67b5
Ssdeep 96:Xu1Q47LsTlWNwybO2kW3tX4g5xkd4dcd76dgdo:XiQ4s5MtX4geM
VirusTotal 搜索相关分析

95B9.tmp

文件名 95B9.tmp
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\95B9.tmp
文件大小 1 bytes
文件类型 very short file (no magic)
MD5 5058f1af8388633f609cadb75a75dc9d
SHA1 3a52ce780950d4d969792a2559cd519d7ee8c727
SHA256 cdb4ee2aea69cc6a83331bbe96dc2caa9a299d21329efb0336fc02a82e1839a8
SHA512 0b61241d7c17bcbb1baee7094d14b7c451efecc7ffcbd92598a0f13d313cc9ebc2a07e61f007baf58fbf94ff9a8695bdd5cae7ce03bbf1e94e93613a00f25f21
Ssdeep 3:L:L
VirusTotal 搜索相关分析

MANIFEST-000001

文件名 MANIFEST-000001
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Extension State\MANIFEST-000001
文件大小 41 bytes
文件类型 PGP\011Secret Key -
MD5 5af87dfd673ba2115e2fcf5cfdb727ab
SHA1 d5b5bbf396dc291274584ef71f444f420b6056f1
SHA256 f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
SHA512 de34583a7dbafe4dd0dc0601e8f6906b9bc6a00c56c9323561204f77abbc0dc9007c480ffe4092ff2f194d54616caf50aecbd4a1e9583cae0c76ad6dd7c2375b
Ssdeep 3:scoBAIxQRDKIVjn:scoBY7jn
VirusTotal 搜索相关分析

data_0

文件名 data_0
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0
文件大小 45056 bytes
文件类型 data
MD5 190a129b7b0664c2f018103f2806fac4
SHA1 391f90015a299e1f32f0727b8ec0628451d6b3b1
SHA256 5d6c17587d091d543c85e75dd21603785c900c1d24ff953ec60ad91dab0fcac5
SHA512 38969e86bcf821deec15c1f2f57e7c591a640f8c01501f6b089246300ef84d8d69b27c51f4cfa9025dad5c8ffea2cf7e8159e076b9506e51e2c1b475c3f5c77d
Ssdeep 192:n1yEc27TEdc0j9/45EPrsNifLD1W5eu43t56kU:Hf4pAoMifv1s743H6
VirusTotal 搜索相关分析

Current Session

文件名 Current Session
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Current Session
文件大小 265 bytes
文件类型 data
MD5 9e06926086915b46fda69dd9a005c51d
SHA1 2507d3c0ea73e69422107bc1d2bcb8fa67c715df
SHA256 0885692f7b9e8e4892668417452f01d4a695b8be933dffab9ac96124ef2f9eb8
SHA512 f5539b1f83dd1cb52c6031c77a6c4cbdb665f05b067bf0cf6bad2f36c5c764d31fb90598b5543064e28920e9f310cdc08fda5f419c81b35f60106d0b439e3e34
Ssdeep 6:3olydBljQuThk2/dl9Cra0yl9Craosl9Craosl9CraoQ:3olydBhQSNliaHliaPliaPliaH
VirusTotal 搜索相关分析

CURRENT

文件名 CURRENT
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Extension State\CURRENT
文件大小 16 bytes
文件类型 ASCII text
MD5 206702161f94c5cd39fadd03f4014d98
SHA1 bd8bfc144fb5326d21bd1531523d9fb50e1b600a
SHA256 1005a525006f148c86efcbfb36c6eac091b311532448010f70f7de9a68007167
SHA512 0af09f26941b11991c750d1a2b525c39a8970900e98cba96fd1b55dbf93fee79e18b8aab258f48b4f7bda40d059629bc7770d84371235cdb1352a4f17f80e145
Ssdeep 3:1sjgWIV//Xv:1qIF/
VirusTotal 搜索相关分析

data_1

文件名 data_1
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1
文件大小 270336 bytes
文件类型 data
MD5 f96e296df8244985b3152ebde6b835cc
SHA1 2c3167f981dbfb0e953385dc490daf9b90cdfd8b
SHA256 b2759de358b0d87effefc8578900fe5af64a11da457c6260e73460ba7ea45528
SHA512 3bf01d665e3c4fb8c2144d30dfc0db54b46af22fb03d4020dfd3013f03db48c224d6b5df2fe3e3689ab07505180c23d692b18815864d505e5a7380ebb735ea72
Ssdeep 3072:pvEZQppxnkWMl5KxZaxF/c+XfZ5AlFzjCD:jgF/c+XfXAlFyD
VirusTotal 搜索相关分析

LOG

文件名 LOG
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
文件大小 352 bytes
文件类型 ASCII text, with CRLF line terminators
MD5 d01d80bf53d1722ff056b162f9d812fc
SHA1 2ffd72bd5733acd9cc482b3481706276ee1f0279
SHA256 c311f00040d5c0cf7bcdfc0650d83d32bfda091597827cf931c9bebb75857dd4
SHA512 4b4f3b53907fe28afe81053758d1e80a77d964320448e189b33823bed9653a08e784975cdfe6415851a56f8bbbf307297216d5557fc6ed5d9a3ec288b2dd9b26
Ssdeep 6:uNbpZmwp6b+MQKFKK6b+MQKFJw6xO7V2K6xO7I64NcJcU0nPV:kt/Uw/x47Y/47N5T0nd
VirusTotal 搜索相关分析

Web Data

文件名 Web Data
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Web Data
文件大小 75776 bytes
文件类型 SQLite 3.x database
MD5 61798ad3837e168ef0e0b08e5f0666b7
SHA1 1b931361d73e0c6ca09c40755aaf211ea1c1be7b
SHA256 d87a866f13c5c5ed296e3ce7b3362bb98539978d3ad6821190b254f800ab3ad6
SHA512 aab820f846a3448c3e336f0ac78e65857a7529ac457e092d020129098138eaa0e8e1ac0e365dfaa92660cf9ec684c042bef937322222bb70fc1ec570e72419a2
Ssdeep 96:M1jLI7NDffAyb3fkW3tXDybO2kW3tXjYLUg7ftaE4Vaw6uKqIdEQ/N8JHsPD737A:YjLIBDff3HtX/MtXUoV6FN
VirusTotal 搜索相关分析

MANIFEST-000002

文件名 MANIFEST-000002
相关文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Extension State\MANIFEST-000002
文件大小 50 bytes
文件类型 MPEG-4 LOAS
MD5 22bf0e81636b1b45051b138f48b3d148
SHA1 56755d203579ab356e5620ce7e85519ad69d614a
SHA256 e292f241daafc3df90f3e2d339c61c6e2787a0d0739aac764e1ea9bb8544ee97
SHA512 a4cf1f5c74e0df85dda8750be9070e24e19b8be15c6f22f0c234ef8423ef9ca3db22ba9ef777d64c33e8fd49fada6fcca26c1a14ba18e8472370533a1c65d8d0
Ssdeep 3:Ukk/vxQRDKIVqU0blS:oO7iblS
VirusTotal 搜索相关分析

行为分析

互斥量(Mutexes) 无信息
执行的命令 无信息
创建的服务 无信息
启动的服务 无信息

进程

chrome.exe PID: 1784, 上一级进程 PID: 1896

chrome.exe PID: 2436, 上一级进程 PID: 1784

访问的文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\9790.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF4de077.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld
  • C:\
  • C:\Users
  • C:\Users\test
  • C:\Users\test\AppData
  • C:\Users\test\AppData\Local
  • C:\Users\test\AppData\Local\Google
  • C:\Users\test\AppData\Local\Google\Chrome
  • C:\Users\test\AppData\Local\Google\Chrome\User Data
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default
  • C:\Windows\System32\ntshrui.dll
  • C:\Windows\AppPatch\sysmain.sdb
  • C:\Windows\System32\
  • C:\Windows\SysWOW64\ntshrui.dll
  • C:\Windows
  • C:\Windows\System32
  • C:\Windows\System32\*.*
  • C:\Users\test\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\*
  • C:\Users\test\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\*
  • C:\Users\test\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\*
  • C:\Windows\System32\p2pcollab.dll
  • C:\Windows\System32\qagentrt.dll
  • C:\Windows\System32\dnsapi.dll
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B599.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B5AA.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B5AB.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B5AC.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Top Sites-journal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B5AD.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Top Sites-wal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\989A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\98AB.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\98AC.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\98AD.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\98BD.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms
  • C:\Program Files (x86)
  • C:\Program Files (x86)\Google
  • C:\Program Files (x86)\Google\Chrome
  • C:\Program Files (x86)\Google\Chrome\Application
  • C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  • C:\Program Files (x86)\Google\Chrome\Application\
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\FU1GMON8N9RN46AJNNDQ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF4e2303.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\994B.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF4e2351.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\998A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Managed Mode Settings
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Managed Mode Settings~RF4e2370.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\99BA.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF4e23ce.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6E6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6E7.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6F7.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6F8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6F9.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6FA.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\9F56.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\A070.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\33SDD9A83207WYDRZP1T.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF4e3fa2.TMP
  • C:\Windows\System32\spool\drivers\color\D65.camp
  • C:\Windows\System32\spool\drivers\color\Photo.gmmp
  • C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Application Cache\Index
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old~RF54e6fc.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOCK
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\CURRENT
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\MANIFEST-000031
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\*
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000033.log
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000035.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000036.log
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\MANIFEST-000034
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000034.dbtmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\CURRENT~RF54e73b.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\A9C4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\index
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Archived History-journal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History-journal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000029.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000026.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000032.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000023.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000011.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000014.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000005.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF54e779.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000008.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000020.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000017.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History Index 2017-09
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History Index 2017-09-journal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History Index 2017-09-wal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3
  • C:\Users\test\AppData\Local\Temp\etilqs_lrIQrccocdifeBF
  • C:\Users\test\AppData\Local\Temp\etilqs_yBEkEHGn2VI9qDm
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\AA61.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History Index *
  • C:\Users\desktop.ini
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF5b753e.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\AAB0.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF5b755d.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\989A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\98AB.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\98AC.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\98AD.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\98BD.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B339.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B33A.tmp
  • C:\Program Files (x86)\desktop.ini
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\X1FUCM7T5IF1PHLXTPE7.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF5b902a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\B5AB.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF5c6355.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\9F56.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\A070.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B638.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B639.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RCGBK23D5TRM7HOBIPU4.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF5c63f1.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B339.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B33A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B6F5.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B6F6.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\PMGOFCSRF083PQMLVPWH.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF62a34a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\B755.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF693087.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B638.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B639.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B7B4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B7B5.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\K5UKZ1NKV4N4KBL587H5.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF693114.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\BD51.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF6a4800.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6F5.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6F6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BDCF.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BDD0.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\93AHIBNKPEDHQ70E06PX.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF6a48ab.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B7B4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B7B5.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BEE9.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BEEA.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BYEORFM62LP3Q0IKF457.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF6d9de4.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\BDCF.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\BDD0.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BFA7.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BFA8.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\990EU5E7B72JE75H6R5O.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF714f91.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\C064.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF77dd0c.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\BEE9.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\BEEA.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\C0C2.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\C0C3.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HY4SJGVT01JOACP38M2S.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF77dda8.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\E48A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF7914f4.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\BFA7.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\BFA8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\E536.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\E537.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\K0G6PHAW4DK44942ZDN2.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF7915de.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\C0C2.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\C0C3.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\E622.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\E623.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NTHVLYTV0IJDA3JG55DP.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF801c97.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\E6B1.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF86aa01.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\E536.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\E537.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\E75D.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\E76E.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\QO75O42CI9DQVE1OVC9U.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF86aaeb.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\B82.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF87e030.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\E622.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\E623.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\C1F.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\C20.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KJ8C3HXPMMI88EBKZZT2.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF87e0eb.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\E75D.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\E76E.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\CDC.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\CDD.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\GN1HLUQHEH8FW184DXCK.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF88a839.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\C1F.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\C20.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\DF7.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\DF8.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NHHDL4L0978QJPGF3FBT.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF8ee830.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\E57.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF9574ef.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\CDC.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\CDD.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\EC5.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\ED6.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MDCCPKMPF1XU44DMN6TJ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF95758b.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\329C.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF96aac0.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\DF7.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\DF8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\3339.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\333A.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\D2MK95L7VINUSF9WOLAG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF96ab7b.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\EC5.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\ED6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\33F6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\33F7.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9C37W79BKL2HU6NK27RS.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF9772ba.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\3339.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\333A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\3501.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\3502.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Z4YU1JAOBMD3G8ZN1P7O.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF9db291.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\359F.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFa43fae.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\33F6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\33F7.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\35FE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\35FF.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HM0AA2AY4H35HYE4O8QA.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFa4404a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\5C83.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFa5f11e.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\5C94.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RFa5f1c9.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\3501.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\3502.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5D9E.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5D9F.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TLXOVZT4E37BJ3JI08VV.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFa5f284.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\35FE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\35FF.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6B27.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6B28.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\F1K8BAKBNM4FK0UG2HOA.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFac3e1e.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\6BE4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFb2bf1b.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\5D9E.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\5D9F.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6CA0.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6CA1.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\IKBVWIPNZVHMAGXLE2R8.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFb2bfd6.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\8189.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFb3e5df.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\6B27.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\6B28.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\81F8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\81F9.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\G8IVK6T6ETSD7OCYGDWR.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFb3e6e8.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\6CA0.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\6CA1.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\8370.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\8381.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BY0R5PT3MPFLLW12LLT9.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFb4ae46.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\81F8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\81F9.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\84E8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\84E9.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BE1O7L3ABEJZWT2N7EU3.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFbaedee.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\85A6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFc17b1a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\8370.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\8381.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\8662.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\8663.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\8IDTFMTJZNQKKCMX8Y34.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc17bd5.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\A884.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFc2af17.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\84E8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\84E9.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\A930.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\A941.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\O4JUJGPK05HCLDPP4IPT.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc2b011.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\8662.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\8663.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\AA7A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\AA7B.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BKGG4QDPCKVRST32AQBY.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc32a0b.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\A930.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\A941.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\ABB4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\ABB5.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BJ9LDKONIFGY11IUX9LP.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc9b775.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\ACDE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFd0452e.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\AA7A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\AA7B.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\ADE9.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\ADEA.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\51U29618353884JU2IIM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd045e9.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\D336.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFd17c47.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\ABB4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\ABB5.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\D356.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\D357.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3JJRR2IATGTLLK3KNPQM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd17c85.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\ADE9.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\ADEA.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\D3B6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\D3B7.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\C5EARNEAVRQIT03XSQ33.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd3a408.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\D356.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\D357.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\D425.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\D426.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\28SWH8EVUJY6VHX38JQM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd8839c.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\DB96.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFdf1847.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\D3B6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\D3B7.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\DBB6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\DBC7.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\WO1HW7ZFNPBN6EPQ6GI4.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFdf1875.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\F6A8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFe38535.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\D425.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\D426.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F716.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F717.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9KLUSP0WO9VK1U8U70CK.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFe385b2.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\DBB6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\DBC7.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F7C3.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F7C4.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CQO3DU5WLZ2472OLVB7N.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFe3ff0f.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\F7F4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFea8c5a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F716.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F717.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F814.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F825.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HV6NO2WPJWX44FKYRCY9.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFea8c89.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\F864.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFf11a13.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F7C3.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F7C4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F885.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F886.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LI3675XBYQULNV2VVFM1.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf11a52.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\1DF1.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFf2513c.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\1E21.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RFf2518a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F814.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F825.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1E8F.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1E90.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\A6TEXXR3E7DM9HQEV4GC.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf251d8.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F885.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F886.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1EDF.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1EF0.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7I6JLIQSPX7U7OCO15AW.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf2caa9.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1E8F.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1E90.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1F4E.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1F5F.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\QCP5KWV7G5J22JGYTNRL.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf95880.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\1FAE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFffe60a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1EDF.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1EF0.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1FDE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1FDF.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3HCQA1HH00C2LAV33VH8.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFffe658.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\454A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF1034294.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1F4E.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1F5F.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\457A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\457B.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\JFV5Y5TLXAG48U6H41HM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF10342e2.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1FDE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1FDF.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\45CA.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\45DA.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Z4S8DVF85YWA696R2RDM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF103bc01.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\457A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\457B.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\4639.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\464A.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\60BR433CDU2XLFUAGBQS.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF10a49d8.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\4699.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF110d762.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\45CA.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\45DA.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\46C8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\46C9.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Z8KD0285Z33WJ418BUL4.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF110d7a1.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\6D8C.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF11288e2.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\4639.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\464A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6DBC.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6DBD.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\17EH14QRZ7Y3YWFF5S2C.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF1128930.TMP
  • C:\Program Files (x86)\Google\Chrome\Application\chrome.dll
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\chrome.dll
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\OLEACC.dll
  • C:\Windows\System32\oleacc.dll
  • C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.Local\
  • C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2
  • C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\Secur32.dll
  • C:\Windows\System32\secur32.dll
  • C:\Program Files (x86)\Google\Chrome\Application\OLEACCRC.DLL
  • C:\Windows\System32\oleaccrc.dll
  • C:\Windows\WindowsShell.Manifest
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\icudt.dll
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\chrome_100_percent.pak
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\Locales
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\Locales\zh-CN.pak
  • C:\Windows\System32\tzres.dll
  • \Device\KsecDD
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\pdf.dll
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
  • \??\pipe\chrome.1784.0.39590524
读取的文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\9790.tmp
  • C:\
  • C:\Users
  • C:\Users\test
  • C:\Users\test\AppData
  • C:\Users\test\AppData\Local
  • C:\Users\test\AppData\Local\Google
  • C:\Users\test\AppData\Local\Google\Chrome
  • C:\Users\test\AppData\Local\Google\Chrome\User Data
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld
  • C:\Windows\System32\ntshrui.dll
  • C:\Windows\AppPatch\sysmain.sdb
  • C:\Windows\System32\
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Top Sites-journal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\989A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\98AB.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\98AC.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\98AD.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\98BD.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms
  • C:\Program Files (x86)
  • C:\Program Files (x86)\Google
  • C:\Program Files (x86)\Google\Chrome
  • C:\Program Files (x86)\Google\Chrome\Application
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\FU1GMON8N9RN46AJNNDQ.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\994B.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\998A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Managed Mode Settings
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\99BA.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\9F56.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\A070.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\33SDD9A83207WYDRZP1T.temp
  • C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOCK
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\CURRENT
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\MANIFEST-000031
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000033.log
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000035.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000034.dbtmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\A9C4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\index
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Archived History-journal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History-journal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000029.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000026.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000032.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000023.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000011.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000014.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000005.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000008.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000020.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000017.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History Index 2017-09
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History Index 2017-09-journal
  • C:\Users\test\AppData\Local\Temp\etilqs_lrIQrccocdifeBF
  • C:\Users\test\AppData\Local\Temp\etilqs_yBEkEHGn2VI9qDm
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\AA61.tmp
  • C:\Users\desktop.ini
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\AAB0.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B339.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B33A.tmp
  • C:\Program Files (x86)\desktop.ini
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\X1FUCM7T5IF1PHLXTPE7.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\B5AB.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B638.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B639.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RCGBK23D5TRM7HOBIPU4.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B6F5.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B6F6.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\PMGOFCSRF083PQMLVPWH.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\B755.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B7B4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\B7B5.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\K5UKZ1NKV4N4KBL587H5.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\BD51.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BDCF.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BDD0.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\93AHIBNKPEDHQ70E06PX.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BEE9.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BEEA.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BYEORFM62LP3Q0IKF457.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BFA7.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BFA8.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\990EU5E7B72JE75H6R5O.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\C064.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\C0C2.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\C0C3.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HY4SJGVT01JOACP38M2S.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\E48A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\E536.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\E537.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\K0G6PHAW4DK44942ZDN2.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\E622.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\E623.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NTHVLYTV0IJDA3JG55DP.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\E6B1.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\E75D.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\E76E.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\QO75O42CI9DQVE1OVC9U.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\B82.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\C1F.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\C20.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KJ8C3HXPMMI88EBKZZT2.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\CDC.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\CDD.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\GN1HLUQHEH8FW184DXCK.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\DF7.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\DF8.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NHHDL4L0978QJPGF3FBT.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\E57.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\EC5.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\ED6.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MDCCPKMPF1XU44DMN6TJ.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\329C.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\3339.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\333A.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\D2MK95L7VINUSF9WOLAG.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\33F6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\33F7.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9C37W79BKL2HU6NK27RS.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\3501.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\3502.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Z4YU1JAOBMD3G8ZN1P7O.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\359F.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\35FE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\35FF.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HM0AA2AY4H35HYE4O8QA.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\5C83.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\5C94.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5D9E.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5D9F.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TLXOVZT4E37BJ3JI08VV.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6B27.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6B28.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\F1K8BAKBNM4FK0UG2HOA.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\6BE4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6CA0.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6CA1.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\IKBVWIPNZVHMAGXLE2R8.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\8189.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\81F8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\81F9.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\G8IVK6T6ETSD7OCYGDWR.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\8370.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\8381.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BY0R5PT3MPFLLW12LLT9.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\84E8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\84E9.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BE1O7L3ABEJZWT2N7EU3.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\85A6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\8662.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\8663.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\8IDTFMTJZNQKKCMX8Y34.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\A884.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\A930.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\A941.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\O4JUJGPK05HCLDPP4IPT.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\AA7A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\AA7B.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BKGG4QDPCKVRST32AQBY.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\ABB4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\ABB5.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BJ9LDKONIFGY11IUX9LP.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\ACDE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\ADE9.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\ADEA.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\51U29618353884JU2IIM.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\D336.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\D356.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\D357.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3JJRR2IATGTLLK3KNPQM.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\D3B6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\D3B7.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\C5EARNEAVRQIT03XSQ33.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\D425.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\D426.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\28SWH8EVUJY6VHX38JQM.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\DB96.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\DBB6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\DBC7.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\WO1HW7ZFNPBN6EPQ6GI4.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\F6A8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F716.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F717.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9KLUSP0WO9VK1U8U70CK.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F7C3.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F7C4.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CQO3DU5WLZ2472OLVB7N.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\F7F4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F814.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F825.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HV6NO2WPJWX44FKYRCY9.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\F864.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F885.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\F886.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LI3675XBYQULNV2VVFM1.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\1DF1.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\1E21.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1E8F.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1E90.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\A6TEXXR3E7DM9HQEV4GC.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1EDF.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1EF0.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7I6JLIQSPX7U7OCO15AW.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1F4E.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1F5F.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\QCP5KWV7G5J22JGYTNRL.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\1FAE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1FDE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\1FDF.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3HCQA1HH00C2LAV33VH8.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\454A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\457A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\457B.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\JFV5Y5TLXAG48U6H41HM.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\45CA.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\45DA.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Z4S8DVF85YWA696R2RDM.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\4639.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\464A.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\60BR433CDU2XLFUAGBQS.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\4699.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\46C8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\46C9.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Z8KD0285Z33WJ418BUL4.temp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\6D8C.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6DBC.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6DBD.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\17EH14QRZ7Y3YWFF5S2C.temp
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\chrome.dll
  • C:\Windows\System32\oleacc.dll
  • C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
  • C:\Windows\System32\secur32.dll
  • C:\Windows\System32\oleaccrc.dll
  • C:\Windows\WindowsShell.Manifest
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\icudt.dll
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\chrome_100_percent.pak
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\Locales\zh-CN.pak
  • C:\Windows\System32\tzres.dll
  • \Device\KsecDD
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\pdf.dll
  • C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
  • \??\pipe\chrome.1784.0.39590524
修改的文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\9790.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF4de077.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Top Sites-journal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\989A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\98AB.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\FU1GMON8N9RN46AJNNDQ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF4e2303.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\994B.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF4e2351.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\998A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Managed Mode Settings
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Managed Mode Settings~RF4e2370.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\99BA.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF4e23ce.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\33SDD9A83207WYDRZP1T.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF4e3fa2.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old~RF54e6fc.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOCK
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000035.sst
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000036.log
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\MANIFEST-000034
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000034.dbtmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\CURRENT
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\CURRENT~RF54e73b.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\index
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\A9C4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Archived History-journal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History-journal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF54e779.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History Index 2017-09
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History Index 2017-09-journal
  • C:\Users\test\AppData\Local\Temp\etilqs_lrIQrccocdifeBF
  • C:\Users\test\AppData\Local\Temp\etilqs_yBEkEHGn2VI9qDm
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\AA61.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF5b753e.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\AAB0.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF5b755d.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\X1FUCM7T5IF1PHLXTPE7.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF5b902a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\B5AB.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF5c6355.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RCGBK23D5TRM7HOBIPU4.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF5c63f1.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\PMGOFCSRF083PQMLVPWH.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF62a34a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\B755.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF693087.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\K5UKZ1NKV4N4KBL587H5.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF693114.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\BD51.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF6a4800.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\93AHIBNKPEDHQ70E06PX.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF6a48ab.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BYEORFM62LP3Q0IKF457.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF6d9de4.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\990EU5E7B72JE75H6R5O.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF714f91.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\C064.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF77dd0c.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HY4SJGVT01JOACP38M2S.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF77dda8.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\E48A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF7914f4.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\K0G6PHAW4DK44942ZDN2.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF7915de.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NTHVLYTV0IJDA3JG55DP.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF801c97.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\E6B1.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF86aa01.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\QO75O42CI9DQVE1OVC9U.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF86aaeb.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\B82.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF87e030.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KJ8C3HXPMMI88EBKZZT2.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF87e0eb.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\GN1HLUQHEH8FW184DXCK.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF88a839.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NHHDL4L0978QJPGF3FBT.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF8ee830.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\E57.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF9574ef.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MDCCPKMPF1XU44DMN6TJ.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF95758b.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\329C.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF96aac0.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\D2MK95L7VINUSF9WOLAG.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF96ab7b.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9C37W79BKL2HU6NK27RS.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF9772ba.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Z4YU1JAOBMD3G8ZN1P7O.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF9db291.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\359F.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFa43fae.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HM0AA2AY4H35HYE4O8QA.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFa4404a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\5C83.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFa5f11e.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\5C94.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RFa5f1c9.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TLXOVZT4E37BJ3JI08VV.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFa5f284.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\F1K8BAKBNM4FK0UG2HOA.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFac3e1e.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\6BE4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFb2bf1b.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\IKBVWIPNZVHMAGXLE2R8.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFb2bfd6.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\8189.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFb3e5df.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\G8IVK6T6ETSD7OCYGDWR.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFb3e6e8.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BY0R5PT3MPFLLW12LLT9.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFb4ae46.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BE1O7L3ABEJZWT2N7EU3.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFbaedee.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\85A6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFc17b1a.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\8IDTFMTJZNQKKCMX8Y34.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc17bd5.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\A884.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFc2af17.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\O4JUJGPK05HCLDPP4IPT.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc2b011.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BKGG4QDPCKVRST32AQBY.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc32a0b.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\BJ9LDKONIFGY11IUX9LP.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc9b775.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\ACDE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFd0452e.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\51U29618353884JU2IIM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd045e9.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\D336.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFd17c47.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3JJRR2IATGTLLK3KNPQM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd17c85.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\C5EARNEAVRQIT03XSQ33.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd3a408.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\28SWH8EVUJY6VHX38JQM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd8839c.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\DB96.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFdf1847.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\WO1HW7ZFNPBN6EPQ6GI4.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFdf1875.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\F6A8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFe38535.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9KLUSP0WO9VK1U8U70CK.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFe385b2.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CQO3DU5WLZ2472OLVB7N.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFe3ff0f.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\F7F4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFea8c5a.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HV6NO2WPJWX44FKYRCY9.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFea8c89.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\F864.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFf11a13.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LI3675XBYQULNV2VVFM1.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf11a52.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\1DF1.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFf2513c.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\1E21.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RFf2518a.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\A6TEXXR3E7DM9HQEV4GC.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf251d8.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7I6JLIQSPX7U7OCO15AW.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf2caa9.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\QCP5KWV7G5J22JGYTNRL.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf95880.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\1FAE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFffe60a.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3HCQA1HH00C2LAV33VH8.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFffe658.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\454A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF1034294.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\JFV5Y5TLXAG48U6H41HM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF10342e2.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Z4S8DVF85YWA696R2RDM.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF103bc01.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\60BR433CDU2XLFUAGBQS.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF10a49d8.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\4699.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF110d762.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Z8KD0285Z33WJ418BUL4.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF110d7a1.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\6D8C.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF11288e2.TMP
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\17EH14QRZ7Y3YWFF5S2C.temp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF1128930.TMP
  • \??\pipe\chrome.1784.0.39590524
删除的文件
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\9790.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF4de077.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B599.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B5AA.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B5AB.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B5AC.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B5AD.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF4e2303.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\994B.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF4e2351.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\998A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Managed Mode Settings~RF4e2370.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\99BA.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF4e23ce.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6E6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6E7.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6F7.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6F8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6F9.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6FA.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF4e3fa2.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old~RF54e6fc.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000034.dbtmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\CURRENT~RF54e73b.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000033.log
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Session Storage\MANIFEST-000031
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\A9C4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF54e779.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History Index 2017-09
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\AA61.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF5b753e.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\AAB0.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF5b755d.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\History Index 2017-09-journal
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\989A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\98AB.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\98AC.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\98AD.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\98BD.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF5b902a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\B5AB.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF5c6355.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\9F56.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\A070.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF5c63f1.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B339.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B33A.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF62a34a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\B755.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF693087.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B638.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B639.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF693114.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\BD51.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF6a4800.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6F5.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B6F6.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF6a48ab.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B7B4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\B7B5.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF6d9de4.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\BDCF.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\BDD0.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF714f91.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\C064.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF77dd0c.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\BEE9.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\BEEA.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF77dda8.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\E48A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF7914f4.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\BFA7.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\BFA8.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF7915de.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\C0C2.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\C0C3.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF801c97.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\E6B1.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF86aa01.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\E536.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\E537.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF86aaeb.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\B82.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF87e030.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\E622.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\E623.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF87e0eb.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\E75D.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\E76E.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF88a839.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\C1F.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\C20.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF8ee830.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\E57.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF9574ef.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\CDC.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\CDD.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF95758b.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\329C.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF96aac0.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\DF7.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\DF8.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF96ab7b.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\EC5.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\ED6.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF9772ba.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\3339.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\333A.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF9db291.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\359F.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFa43fae.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\33F6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\33F7.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFa4404a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\5C83.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFa5f11e.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\5C94.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RFa5f1c9.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\3501.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\3502.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFa5f284.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\35FE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\35FF.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFac3e1e.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\6BE4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFb2bf1b.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\5D9E.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\5D9F.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFb2bfd6.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\8189.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFb3e5df.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\6B27.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\6B28.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFb3e6e8.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\6CA0.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\6CA1.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFb4ae46.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\81F8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\81F9.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFbaedee.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\85A6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFc17b1a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\8370.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\8381.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc17bd5.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\A884.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFc2af17.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\84E8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\84E9.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc2b011.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\8662.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\8663.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc32a0b.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\A930.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\A941.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFc9b775.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\ACDE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFd0452e.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\AA7A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\AA7B.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd045e9.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\D336.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFd17c47.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\ABB4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\ABB5.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd17c85.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\ADE9.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\ADEA.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd3a408.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\D356.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\D357.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFd8839c.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\DB96.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFdf1847.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\D3B6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\D3B7.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFdf1875.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\F6A8.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFe38535.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\D425.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\D426.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFe385b2.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\DBB6.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\DBC7.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFe3ff0f.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\F7F4.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFea8c5a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F716.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F717.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFea8c89.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\F864.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFf11a13.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F7C3.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F7C4.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf11a52.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\1DF1.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFf2513c.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\1E21.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences~RFf2518a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F814.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F825.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf251d8.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F885.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\F886.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf2caa9.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1E8F.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1E90.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFf95880.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\1FAE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RFffe60a.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1EDF.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1EF0.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RFffe658.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\454A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF1034294.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1F4E.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1F5F.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF10342e2.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1FDE.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\1FDF.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF103bc01.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\457A.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\457B.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF10a49d8.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\4699.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF110d762.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\45CA.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\45DA.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF110d7a1.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\6D8C.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Local State~RF11288e2.TMP
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\4639.tmp
  • C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\JumpListIconsOld\464A.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms~RF1128930.TMP
注册表键
  • HKEY_LOCAL_MACHINE\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
  • ap
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ConfirmFileDelete
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ConfirmFileDelete
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\NoFileFolderConnection
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Directory\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory
  • HKEY_CLASSES_ROOT\Directory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ShellEx\PropertyHandler
  • HKEY_CLASSES_ROOT\Folder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\PropertyHandler
  • HKEY_CLASSES_ROOT\AllFilesystemObjects
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\PropertyHandler
  • HKEY_CLASSES_ROOT\.tmp
  • HKEY_CLASSES_ROOT\.tmp\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tmp\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tmp
  • HKEY_CLASSES_ROOT\Unknown
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\ShellEx\IconHandler
  • HKEY_CLASSES_ROOT\SystemFileAssociations\.tmp
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\NeverShowExt
  • HKEY_CURRENT_USER
  • HKEY_CURRENT_USER\Software\Microsoft\CTF\LayoutIcon\0804\00000804
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MaxUndoItems
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Advanced\MaxUndoItems
  • HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\FileSystem
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\FileSystem\(Default)
  • HKEY_CLASSES_ROOT\CLSID\{217FC9C0-3AEA-1069-A2DB-08002B30309D}\InProcServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{217FC9C0-3AEA-1069-A2DB-08002B30309D}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\Sharing
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\Sharing\(Default)
  • HKEY_CLASSES_ROOT\CLSID\{40DD6E20-7C17-11CE-A804-00AA003CA9F6}\InProcServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{40DD6E20-7C17-11CE-A804-00AA003CA9F6}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{40DD6E20-7C17-11CE-A804-00AA003CA9F6}\InProcServer32\LoadWithoutCOM
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
  • HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{40dd6e20-7c17-11ce-a804-00aa003ca9f6}\InProcServer32
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ntshrui.dll
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{40DD6E20-7C17-11CE-A804-00AA003CA9F6} {000214FC-0000-0000-C000-000000000046} 0xFFFF
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{40DD6E20-7C17-11CE-A804-00AA003CA9F6}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\WinSCPCopyHook
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\WinSCPCopyHook\(Default)
  • HKEY_CLASSES_ROOT\CLSID\{E15E1D68-0D1C-49F7-BEB8-812B1E00FA60}\InProcServer32
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\PhysicalStores
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000\ProfileImagePath
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\Certificates
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\CRLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\CTLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\Keys
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\PhysicalStores
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\CRLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\CTLs
  • HKEY_CURRENT_USER\
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\Certificates
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\CRLs
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\CTLs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA\PhysicalStores
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\475BA6DA2AFD5AE3ADAE78A261CA0E3E548B9532
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\475BA6DA2AFD5AE3ADAE78A261CA0E3E548B9532\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\CA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA\PhysicalStores
  • HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPublisher\Safer
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\Certificates
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CRLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CTLs
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Disallowed
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores
  • HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\PhysicalStores
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\Certificates
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\CRLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\CTLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root\PhysicalStores
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A7217F919843199C958C128449DD52D2723B0A8A
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A7217F919843199C958C128449DD52D2723B0A8A\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D85213E038F309D02A40917B59E142368AE6B1C0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D85213E038F309D02A40917B59E142368AE6B1C0\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\DBB84423C928ABE889D0E368FC3191D151DDB1AB
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\DBB84423C928ABE889D0E368FC3191D151DDB1AB\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\PROFILELIST
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1001
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1001\ProfileImagePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root\PhysicalStores
  • HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\SmartCardRoot
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPeople
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople\PhysicalStores
  • HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\PhysicalStores
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\Certificates
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\CRLs
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\CTLs
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\Certificates
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\CRLs
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\CTLs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust\PhysicalStores
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\trust
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust\PhysicalStores
  • HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Sharing
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe\DontUseDesktopChangeRouter
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
  • HKEY_LOCAL_MACHINE\System\Setup
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\PropertySystem\PropertyHandlers\.tmp
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\ShellEx\PropertyHandler
  • HKEY_CLASSES_ROOT\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\ShellEx\PropertyHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4a\AAF68885
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4A\AAF68885\LanguageList
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4A\AAF68885\@%SystemRoot%\system32\p2pcollab.dll,-8042
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4A\AAF68885\@%SystemRoot%\system32\dnsapi.dll,-103
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\UrlDllGetObjectUrl
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\UrlDllGetObjectUrl
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\AuthRoot
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot\DisableRootAutoUpdate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllVerifyEncodedSignature
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllVerifyEncodedSignature
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllVerifyCertificateChainPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyCertificateChainPolicy
  • HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.NamespaceCLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 6
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_JumpListItems
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Advanced\Start_JumpListItems
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRecentDocsHistory
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRecentDocsHistory
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_TrackDocs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Advanced\Start_TrackDocs
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\Location Awareness
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\\xe5\xae\x8b\xe4\xbd\x93
  • HKEY_CURRENT_USER\Control Panel\Desktop
  • HKEY_CURRENT_USER\Control Panel\Desktop\SmoothScroll
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewAlphaSelect
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewShadow
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AccListViewV6
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\UseDoubleClickTimer
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\Win
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\camp
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\rip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
  • HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
  • HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}\brand
  • HKEY_CLASSES_ROOT\.
  • HKEY_CLASSES_ROOT\.\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.\UserChoice
  • HKEY_CLASSES_ROOT\SystemFileAssociations\.
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\PropertySystem\PropertyHandlers\.
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome
  • HKEY_CURRENT_USER\SOFTWARE\Policies\Google\Chrome
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\Recommended
  • HKEY_CURRENT_USER\SOFTWARE\Policies\Google\Chrome\Recommended
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\3rdparty\extensions
  • HKEY_CURRENT_USER\SOFTWARE\Policies\Google\Chrome\3rdparty\extensions
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Time Zones\China Standard Time\Dynamic DST
  • HKEY_LOCAL_MACHINE\Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}
  • HKEY_CURRENT_USER\Control Panel\International
  • HKEY_CURRENT_USER\Control Panel\International\LocaleName
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugHeapFlags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\msasn1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
  • HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
  • HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\~MHz
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000\State
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000\Preference
  • HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}\metricsid
  • HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}\dr
  • HKEY_LOCAL_MACHINE\Software\Google\Update\ClientStateMedium\{8A69D345-D564-463c-AFF1-A69D9E530F96}
  • UserDataDir
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Time Zones
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\AUS Central Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\AUS Central Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\AUS Eastern Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\AUS Eastern Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Afghanistan Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Afghanistan Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Alaskan Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Alaskan Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Arab Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Arab Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Arabian Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Arabian Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Arabic Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Arabic Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Argentina Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Argentina Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Armenian Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Atlantic Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Atlantic Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Azerbaijan Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Azerbaijan Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Azores Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Azores Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Bangladesh Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Bangladesh Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Canada Central Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Canada Central Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Cape Verde Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Cape Verde Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Caucasus Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Caucasus Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Cen. Australia Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Cen. Australia Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central America Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central America Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Asia Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Asia Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Brazilian Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Brazilian Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Europe Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Europe Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central European Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central European Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Pacific Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Pacific Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Standard Time (Mexico)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Standard Time (Mexico)\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\China Standard Time
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\China Standard Time\TZI
读取的注册表键
  • ap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ConfirmFileDelete
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ConfirmFileDelete
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\NoFileFolderConnection
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\NeverShowExt
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MaxUndoItems
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Advanced\MaxUndoItems
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\FileSystem\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{217FC9C0-3AEA-1069-A2DB-08002B30309D}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\Sharing\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{40DD6E20-7C17-11CE-A804-00AA003CA9F6}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{40DD6E20-7C17-11CE-A804-00AA003CA9F6}\InProcServer32\LoadWithoutCOM
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{40DD6E20-7C17-11CE-A804-00AA003CA9F6} {000214FC-0000-0000-C000-000000000046} 0xFFFF
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\WinSCPCopyHook\(Default)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000\ProfileImagePath
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\475BA6DA2AFD5AE3ADAE78A261CA0E3E548B9532\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob
  • HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A7217F919843199C958C128449DD52D2723B0A8A\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D85213E038F309D02A40917B59E142368AE6B1C0\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\DBB84423C928ABE889D0E368FC3191D151DDB1AB\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1001\ProfileImagePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe\DontUseDesktopChangeRouter
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4A\AAF68885\@%SystemRoot%\system32\p2pcollab.dll,-8042
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4A\AAF68885\@%SystemRoot%\system32\dnsapi.dll,-103
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot\DisableRootAutoUpdate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.NamespaceCLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 6
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_JumpListItems
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Advanced\Start_JumpListItems
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRecentDocsHistory
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRecentDocsHistory
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_TrackDocs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Advanced\Start_TrackDocs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\\xe5\xae\x8b\xe4\xbd\x93
  • HKEY_CURRENT_USER\Control Panel\Desktop\SmoothScroll
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewAlphaSelect
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewShadow
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AccListViewV6
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\UseDoubleClickTimer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\Win
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\camp
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\rip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
  • HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}\brand
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
  • HKEY_CURRENT_USER\Control Panel\International\LocaleName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugHeapFlags
  • HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\~MHz
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000\State
  • HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}\metricsid
  • UserDataDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\AUS Central Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\AUS Eastern Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Afghanistan Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Alaskan Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Arab Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Arabian Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Arabic Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Argentina Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Atlantic Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Azerbaijan Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Azores Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Bangladesh Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Canada Central Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Cape Verde Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Caucasus Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Cen. Australia Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central America Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Asia Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Brazilian Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Europe Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central European Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Pacific Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Standard Time\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Standard Time (Mexico)\TZI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\China Standard Time\TZI
修改的注册表键
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4A\AAF68885\LanguageList
  • HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}\dr
删除的注册表键 无信息
API解析
  • ws2_32.dll.freeaddrinfo
  • ws2_32.dll.getaddrinfo
  • ws2_32.dll.WSASocketW
  • ws2_32.dll.#21
  • ws2_32.dll.WSAIoctl
  • ws2_32.dll.WSAEventSelect
  • ws2_32.dll.#4
  • ws2_32.dll.WSAEnumNetworkEvents
  • ws2_32.dll.#6
  • ws2_32.dll.#16
  • ws2_32.dll.WSASend
  • ws2_32.dll.WSAResetEvent
  • ws2_32.dll.WSARecv
  • advapi32.dll.GetSecurityInfo
  • advapi32.dll.SetSecurityInfo
  • advapi32.dll.GetSecurityDescriptorControl
  • shell32.dll.SHFileOperationW
  • oleaut32.dll.#200
  • comctl32.dll.#385
  • propsys.dll.PSLookupPropertyHandlerCLSID
  • propsys.dll.PSCreatePropertyStoreFromObject
  • propsys.dll.PropVariantToStringAlloc
  • propsys.dll.PropVariantToBoolean
  • propsys.dll.VariantToUInt64
  • propsys.dll.InitPropVariantFromBuffer
  • propsys.dll.PropVariantToBuffer
  • ws2_32.dll.WSAGetOverlappedResult
  • crypt32.dll.CertAddEncodedCertificateToStore
  • crypt32.dll.CertDuplicateCertificateContext
  • crypt32.dll.CryptHashCertificate
  • crypt32.dll.CryptDecodeObjectEx
  • crypt32.dll.CertRDNValueToStrW
  • crypt32.dll.CertFreeCertificateContext
  • crypt32.dll.CertOpenStore
  • crypt32.dll.CertAddCertificateContextToStore
  • crypt32.dll.CertCloseStore
  • crypt32.dll.CertGetCertificateChain
  • ole32.dll.CoCreateInstance
  • userenv.dll.GetUserProfileDirectoryW
  • comctl32.dll.#328
  • comctl32.dll.#386
  • ole32.dll.CreateBindCtx
  • ole32.dll.CoTaskMemRealloc
  • shell32.dll.#66
  • advapi32.dll.GetNamedSecurityInfoW
  • sechost.dll.ConvertStringSidToSidW
  • netutils.dll.NetApiBufferFree
  • advapi32.dll.RegOpenKeyExW
  • ole32.dll.CoTaskMemFree
  • userenv.dll.RegisterGPNotification
  • propsys.dll.PropVariantToUInt64
  • user32.dll.LoadStringW
  • ncrypt.dll.BCryptOpenAlgorithmProvider
  • bcryptprimitives.dll.GetHashInterface
  • ncrypt.dll.BCryptGetProperty
  • ncrypt.dll.BCryptCreateHash
  • comctl32.dll.#388
  • ncrypt.dll.BCryptHashData
  • ncrypt.dll.BCryptFinishHash
  • ncrypt.dll.BCryptDestroyHash
  • comctl32.dll.#321
  • cryptnet.dll.CryptGetObjectUrl
  • cryptnet.dll.I_CryptNetGetConnectivity
  • sensapi.dll.IsNetworkAlive
  • rpcrt4.dll.RpcBindingFromStringBindingW
  • rpcrt4.dll.RpcBindingSetAuthInfoExW
  • rpcrt4.dll.NdrClientCall2
  • bcryptprimitives.dll.GetAsymmetricEncryptionInterface
  • ncrypt.dll.BCryptImportKeyPair
  • ncrypt.dll.BCryptVerifySignature
  • ncrypt.dll.BCryptDestroyKey
  • crypt32.dll.CertVerifyCertificateChainPolicy
  • crypt32.dll.CertFreeCertificateChain
  • crypt32.dll.CryptFindOIDInfo
  • crypt32.dll.CertGetPublicKeyLength
  • bcryptprimitives.dll.GetSignatureInterface
  • cryptsp.dll.CryptAcquireContextA
  • cryptsp.dll.CryptGetKeyParam
  • cryptsp.dll.CryptDestroyKey
  • ole32.dll.CoGetMalloc
  • linkinfo.dll.CreateLinkInfoW
  • user32.dll.IsCharAlphaW
  • user32.dll.CharPrevW
  • ntshrui.dll.GetNetResourceFromLocalPathW
  • shlwapi.dll.PathRemoveFileSpecW
  • linkinfo.dll.DestroyLinkInfo
  • ws2_32.dll.#22
  • ws2_32.dll.WSACloseEvent
  • cryptsp.dll.CryptAcquireContextW
  • cryptsp.dll.CryptGenRandom
  • cryptsp.dll.CryptReleaseContext
  • comctl32.dll.#387
  • comctl32.dll.#327
  • comctl32.dll.RegisterClassNameW
  • imm32.dll.ImmIsIME
  • user32.dll.CreateIconIndirect
  • user32.dll.DestroyIcon
  • user32.dll.MoveWindow
  • user32.dll.GetForegroundWindow
  • gdi32.dll.GetLayout
  • advapi32.dll.RegQueryValueExA
  • advapi32.dll.RegEnumKeyExW
  • gdi32.dll.GetTextFaceAliasW
  • gdi32.dll.GetTextExtentExPointWPri
  • user32.dll.GetSysColorBrush
  • user32.dll.FrameRect
  • user32.dll.InflateRect
  • user32.dll.DrawFrameControl
  • user32.dll.DrawFocusRect
  • uxtheme.dll.BufferedPaintInit
  • uxtheme.dll.BeginBufferedPaint
  • uxtheme.dll.EndBufferedPaint
  • ntdll.dll.NtTerminateProcess
  • user32.dll.DestroyWindow
  • user32.dll.IsTouchWindow
  • dwmapi.dll.DwmSetWindowAttribute
  • user32.dll.EnumThreadWindows
  • user32.dll.GetWindow
  • user32.dll.GetMessageExtraInfo
  • user32.dll.GetCapture
  • user32.dll.UpdateLayeredWindow
  • uxtheme.dll.BufferedPaintUnInit
  • ole32.dll.CoRevokeInitializeSpy
  • user32.dll.OffsetRect
  • user32.dll.WaitMessage
  • kernel32.dll.FlsAlloc
  • kernel32.dll.FlsGetValue
  • kernel32.dll.FlsSetValue
  • kernel32.dll.FlsFree
  • shell32.dll.CommandLineToArgvW
  • kernel32.dll.SortGetHandle
  • kernel32.dll.SortCloseHandle
  • advapi32.dll.EventWrite
  • advapi32.dll.EventRegister
  • advapi32.dll.EventUnregister
  • lpk.dll.LpkEditControl
  • user32.dll.GetSysColor
  • ntdll.dll.RtlCaptureStackBackTrace
  • shell32.dll.SHGetFolderPathW
  • sechost.dll.ConvertSidToStringSidW
  • chrome.dll.ChromeMain
  • kernel32.dll.IsWow64Process
  • user32.dll.OpenInputDesktop
  • user32.dll.GetProcessWindowStation
  • user32.dll.OpenWindowStationA
  • user32.dll.SetProcessWindowStation
  • user32.dll.CreateWindowExW
  • uxtheme.dll.EnableThemeDialogTexture
  • user32.dll.CloseWindowStation
  • icudt.dll.icudt46_dat
  • user32.dll.PostThreadMessageW
  • user32.dll.PeekMessageW
  • advapi32.dll.SystemFunction036
  • cryptbase.dll.SystemFunction001
  • cryptbase.dll.SystemFunction002
  • cryptbase.dll.SystemFunction003
  • cryptbase.dll.SystemFunction004
  • cryptbase.dll.SystemFunction005
  • cryptbase.dll.SystemFunction028
  • cryptbase.dll.SystemFunction029
  • cryptbase.dll.SystemFunction034
  • cryptbase.dll.SystemFunction036
  • cryptbase.dll.SystemFunction040
  • cryptbase.dll.SystemFunction041
  • pdf.dll.PPP_GetInterface
  • pdf.dll.PPP_InitializeModule
  • pdf.dll.PPP_ShutdownModule
  • ppgooglenaclpluginchrome.dll.PPP_GetInterface
  • ppgooglenaclpluginchrome.dll.PPP_InitializeModule
  • ppgooglenaclpluginchrome.dll.PPP_ShutdownModule