What is Trojan_Guarder.exe?

Trojan_Guarder.exe is usually located in the 'c:\downloads\' folder.

Some of the anti-virus scanners at VirusTotal detected Trojan_Guarder.exe.

If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.

Vendor and version information [?]

Trojan_Guarder.exe does not have any version or vendor information.

Digital signatures [?]

Trojan_Guarder.exe is not signed.

VirusTotal report

2 of the 67 anti-virus programs at VirusTotal detected the Trojan_Guarder.exe file. That's a 3% detection rate.

ScannerDetection Name
CMC Trojan-FakeAV.Win32!O
Comodo Malware@#1z2czo2zi2jrn
2 of the 67 anti-virus programs detected the Trojan_Guarder.exe file.

Sandbox Report

The following information was gathered by executing the file inside Cuckoo Sandbox.

Summary

Successfully executed process in sandbox.

Summary

{
    "file_created": [
        "C:\\Program Files (x86)\\Trojan Guarder\\is-B1FT8.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder\\TG5.42.dll",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\INS5F2B.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-8AJE8.tmp",
        "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-2FOAU.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-RFVGO.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-0QUMH.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp\\_shfoldr.dll",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
        "C:\\Program Files (x86)\\Trojan Guarder\\unins000.dat",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-00ORD.tmp",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-GNPSC.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-KM98T.tmp",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk"
    ],
    "file_recreated": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\INS5F2B.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder\\unins000.dat"
    ],
    "directory_created": [
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches",
        "C:\\Users\\cuck\\Desktop",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer"
    ],
    "dll_loaded": [
        "C:\\Windows\\system32\\ntshrui.dll",
        "netutils.dll",
        "C:\\Windows\\system32\\odbcint.dll",
        "kernel32",
        "apphelp.dll",
        "LINKINFO.dll",
        "kernel32.dll",
        "UxTheme.dll",
        "C:\\Windows\\system32\\ole32.dll",
        "dwmapi.dll",
        "imm32.dll",
        "ntmarta.dll",
        "WSOCK32.dll",
        "comdlg32.dll",
        "PROPSYS.dll",
        "C:\\Windows\\syswow64\\MSCTF.dll",
        "user32",
        "OLEAUT32.DLL",
        "C:\\Windows\\system32\\EhStorShell.dll",
        "comctl32",
        "ole32.dll",
        "SHLWAPI.dll",
        "USER32.dll",
        "IMM32.dll",
        "API-MS-Win-Security-SDDL-L1-1-0.dll",
        "WindowsCodecs.dll",
        "shfolder.dll",
        "OLEAUT32.dll",
        "profapi.dll",
        "MFC42.DLL",
        "SHELL32.dll",
        "comctl32.dll",
        "COMCTL32.dll",
        "shell32.dll",
        "WS2_32.dll",
        "MSVCRT.DLL",
        "ADVAPI32.dll",
        "SETUPAPI.dll",
        "ntshrui.dll",
        "COMCTL32.DLL"
    ],
    "file_opened": [
        "C:\\ProgramData",
        "C:\\",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\desktop.ini",
        "C:\\Users\\cuck\\AppData\\Local\\Temp",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools",
        "C:\\Windows\\System32\\EhStorShell.dll",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\desktop.ini",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\INS5F2B.tmp",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Videos.library-ms",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Documents.library-ms",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows",
        "c:\\",
        "C:\\Users\\cuck\\Desktop\\desktop.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\Desktop.ini",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-B1FT8.tmp",
        "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
        "C:\\Users\\Public\\desktop.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk",
        "C:\\Windows\\System32\\imageres.dll",
        "c:\\program files (x86)\\trojan guarder\\trojan guarder.exe",
        "C:\\Windows\\AppPatch\\sysmain.sdb",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-KM98T.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-GNPSC.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-00ORD.tmp",
        "C:\\Windows\\System32\\en-US\\EhStorShell.dll.mui",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch",
        "C:\\Program Files (x86)\\Trojan Guarder\\Visit Our Site.url",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
        "C:\\Users\\cuck\\AppData\\Roaming",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\desktop.ini",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\b0fdc934c7f8c994633e99b9dcee1ccc70e222ee36e38082ad16d23b982a5b47.bin",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Pictures.library-ms",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_1024.db",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-RFVGO.tmp",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility\\Desktop.ini",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Network Shortcuts",
        "C:\\Program Files (x86)",
        "C:\\ProgramData\\Microsoft\\Windows",
        "C:\\Windows\\System32\\ntshrui.dll",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_idx.db",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Python 2.7",
        "C:\\Users\\Public\\Desktop",
        "C:\\Windows",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_sr.db",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db",
        "C:\\Windows\\Media\\Windows Navigation Start.wav",
        "C:\\Users\\Public\\Desktop\\desktop.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility",
        "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
        "c:\\Windows\\System32\\imageres.dll",
        "C:\\Users",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_96.db",
        "C:\\Users\\desktop.ini",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer",
        "C:\\Users\\cuck",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories",
        "C:\\Program Files (x86)\\Trojan Guarder\\Trojan Guarder Help.chm",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_256.db",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-8AJE8.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder\\",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games\\desktop.ini",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Music.library-ms",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Desktop.ini",
        "C:\\Users\\cuck\\AppData",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-2FOAU.tmp",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC\\Desktop.ini",
        "C:\\Users\\cuck\\Desktop",
        "C:\\Users\\cuck\\",
        "C:\\Windows\\System32\\en-US\\ntshrui.dll.mui",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries",
        "C:\\Windows\\System32",
        "C:\\Program Files (x86)\\Trojan Guarder\\Trojan Guarder.exe",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp\\_shfoldr.dll",
        "C:\\Users\\Public",
        "C:\\ProgramData\\Microsoft",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\desktop.ini",
        "C:\\Windows\\win.ini",
        "C:\\Program Files (x86)\\Trojan Guarder",
        "C:\\Users\\cuck\\Pictures\\desktop.ini",
        "C:\\Program Files (x86)\\Trojan Guarder\\unins000.exe",
        "C:\\Users\\cuck\\Desktop\\",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk",
        "C:\\Program Files (x86)\\desktop.ini",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft",
        "C:\\Windows\\System32\\",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-0QUMH.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder\\TG5.42.dll",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools\\Desktop.ini",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db"
    ],
    "regkey_opened": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Disk",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PeerDistSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ACPI\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0F4DC93AAA8AD1D448BC4E6A207F4FE0",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UI0Detect\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Psched\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\agp440",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\circlass\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPNP\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\11E2BA15171FE704B98E7505E58D7749",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinHttpAutoProxySvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SamSs",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F356843B045CC0A4BA0D83C1D85AAAFD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdbss",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DcomLaunch\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fvevol\\Parameters",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Disk\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Icons",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E429E5BC27530F4786481EC687D9EC9",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KSecPkg",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CB2182A03B6B11341A1F09A021991CE1",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adpahci\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Brserid",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\idsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srvnet\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrUsbMdm",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SamSs\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CF65AB832507EDB4BB357F9D8E0431BD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PNRPsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Npfs\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIP6\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pci\\Parameters",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSPCLOCK\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Netlogon\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Mup\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\DocObject",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wcncsvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetTcpPortSharing\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AudioEndpointBuilder\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Modem\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\p2pimsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\gagp30kx\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ebdrv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PortProxy\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FileInfo\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A558E619ABC4CE5479C1DA5070EFBF81",
        "HKEY_CLASSES_ROOT\\batfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\ShellEx\\IconHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adpu320\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HdAudAddService\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FDResPub\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EFS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Power\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adpu320",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\863CA21BBA4DFCE489FDF96EAB898616",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HomeGroupListener",
        "HKEY_CLASSES_ROOT\\.chm",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mouhid\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\blbdrive\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hwpolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WwanSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ws2ifsl",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AudioSrv",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\cmdfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hidserv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PlugPlay\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adp94xx\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PEAUTH\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18F5DB38C45303843B06B1B5025E4820",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dmvsc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iScsiPrt\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbhub\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Lsa",
        "HKEY_CURRENT_USER\\Control Panel\\Desktop",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WfpLwf\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TsUsbGD\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C4040CC509FB0DC4886F590DDF6B6132",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BTHMODEM",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volsnap\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9E40FDB6330EBA242A4BD5F4FDD0B803",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\isapnp\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ldap",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET Data Provider for Oracle\\",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Appinfo",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ehRecvr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\storvsc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSDTC",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cdfs\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\atapi",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\storflt\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ProtectedStorage",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisCap\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B06071FE021ECB04E8B3BF1E39AD5BB3",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffdisk\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ohci1394\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdide\\Parameters",
        "HKEY_CLASSES_ROOT\\Folder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UxSms\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\E1G60\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D3541DFF9B79C584284E8981624C04CB",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wscsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\QWAVE\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelService 3.0.0.0\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppIDSvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adpu320\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nfrd960\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MsRPC\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iphlpsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adp94xx\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AmdK8",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPDR\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PNRPAutoReg",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Null\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WfpLwf\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-699399860-4089948139-3198924279-1001\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TapiSrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppMgmt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IpFilterDriver\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Brserid\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ksthunk",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fvevol",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AcpiPmi\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SMSvcHost 3.0.0.0",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb20\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wmiApSrv",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WdiSystemHost\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\arc",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CLASSES_ROOT\\InternetShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\ShellIconOverlayIdentifiers\\SharingPrivate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HomeGroupProvider\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CNG\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wd\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\intelppm",
        "HKEY_CLASSES_ROOT\\.chm\\OpenWithProgids",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CertPropSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AxInstSV",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffp_mmc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89BBBC8A0D32B014696C4BA3C20CDD34",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LanmanServer\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CscService\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdyboost\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Browser\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbcir\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET Data Provider for SqlServer",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vmbus\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSSCNTRS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IKEEXT\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VMBusHID\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9753E3A35E3BDFB468DF95B5D19C8A04",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TSDDD\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\gpsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1C1ED53B8F25FD248955C15232E46886",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Netlogon\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WbioSrvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hwpolicy\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIP6",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84BBAC70FB00B6046881B55CB3122F0F",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPREFMP\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\USBSTOR",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\BidInterface\\Loader",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Serenum\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\OpenWithProgids",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cmdide\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cmdide",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinSock2",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdpbus\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TermService",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\agp440\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.chm\\OpenWithProgids",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vsmraid\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcLocator\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Netlogon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidUsb",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPWD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET CLR Networking\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TermDD",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPENCDD\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MegaSR",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TapiSrv\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wd\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B5C8B2FB95B57147954C18085D53ACE",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffdisk",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\THREADORDER\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cdfs\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSiSCSI\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_FC\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CmBatt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ebdrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SessionEnv\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdyboost\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lltdio\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Compbatt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CSC\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msahci",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rspndr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrFiltUp\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KtmRm",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ohci1394\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lltdio\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WPCSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Fax\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EapHost\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CDBF699A8F2EAC2438564C3D50E9E638",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nv_agp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\QWAVEdrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IpFilterDriver\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AmdK8\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TDPIPE\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ohci1394",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Modem\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PptpMiniport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fdc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisTapi\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SDRSVC\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\b57nd60a",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\clr_optimization_v2.0.50727_64\\",
        "HKEY_USERS\\.DEFAULT\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\Setup\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crcdisk\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WcsPlugInService\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tcpipreg",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rspndr\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.url\\OpenWithProgids",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0A191B45599EEB74CA305184EA3C2A94",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSPCLOCK\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Mup\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSKSSRV\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mpsdrv\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\i8042prt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AmdPPM\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\E1G60",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\udfs\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Dhcp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PortProxy\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\kbdhid\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfOS\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Browser",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ql40xx",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Browser\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinDefend\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vmbus\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FontCache3.0.0.0\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TrustedInstaller\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Rasl2tp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfProc\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\Trojan Guarder.exe",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AeLookupSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\StorSvc",
        "HKEY_CLASSES_ROOT\\Outlook.Application",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\uagp35\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfDisk\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbhub",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LDAP",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CscService\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfNet\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CNG\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sppuinotify\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcSs\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AeLookupSvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wmiApSrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wercplsupport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LanmanWorkstation",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\partmgr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wanarpv6\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\monitor",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\upnphost\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbccgp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mountmgr\\Parameters",
        "HKEY_CLASSES_ROOT\\.exe",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TrkWks\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetTcpPortSharing",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\USBSTOR\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ESENT\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BattC\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPENCDD\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSTEE",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ehSched\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\spldr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DPS\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mssmbios",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wscsvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\THREADORDER\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\storvsc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CertPropSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NETFramework\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mountmgr",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AcpiPmi",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Beep\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FileInfo",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lmhosts\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Spooler\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WSearch\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dot3svc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSDTC Bridge 3.0.0.0",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\COMSysApp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PNRPAutoReg\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Classes\\.ett\\Extension\\{223bd3fe-345e-ffae-3c9f-fe62375679e1}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Beep",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisWan\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_FC\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lmhosts\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adpahci",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WfpLwf",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\comfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\netprofm\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb10\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wbengine\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VSS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msahci\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iirsp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WMPNetworkSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CryptSvc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\INS5F2B.tmp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Themes\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE19F224928A59468049F045950CB08",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pcmcia\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84C584688CFC74A4E9D36E5EE2E02FA7",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WSearchIdxPi",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPBusEnum",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TSDDD\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mouclass\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nvstor\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCPolicySvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\umbus\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\296744B7EBFEB2741A47781AE6E32269",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbprint\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\seclogon\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MTConfig",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\b06bdrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\isapnp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\p2psvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wudfsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SSDPSRV\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4626147D107665540A84D43A5908E74D",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Serenum",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\batfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PlugPlay",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8ECC347096FA78C4E8291F449F71E16E",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mouclass\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinSock2\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIPTUNNEL\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CscService",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NDProxy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IRENUM",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ESENT",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\ShellEx\\IconHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\bowser\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\intelide\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BDESVC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hcw85cir\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WMPNetworkSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\THREADORDER",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WacomPen\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\s3cap\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iirsp\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F591EF48DE97A00428A5BC1AFFFAA868",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WdiServiceHost\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WdiSystemHost\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\717591555BCB1604BA9777E8A55D0E41",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\spldr\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msahci\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nv_agp\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NTDS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RemoteRegistry",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Parport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mpsdrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SessionEnv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\arc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\USBSTOR\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCardSvr\\",
        "HKEY_CLASSES_ROOT\\Outlook.Application.12",
        "HKEY_CLASSES_ROOT\\Outlook.Application.11",
        "HKEY_CLASSES_ROOT\\Outlook.Application.10",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SNMPTRAP\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msiserver\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\idsvc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Desktop\\General",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AudioEndpointBuilder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\stisvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NativeWifiP",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-699399860-4089948139-3198924279-1001\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tssecsrv\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffdisk\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cdfs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adp94xx",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tdx\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET CLR Data\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAuto\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WdiSystemHost",
        "HKEY_CLASSES_ROOT\\Applications\\notepad.exe\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WSearchIdxPi\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FDResPub",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1",
        "HKEY_CLASSES_ROOT\\SystemFileAssociations\\.chm",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DcomLaunch\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volsnap",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPNP\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\stexstor\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidIr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Appinfo\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volmgr\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPMIDRV",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TrustedInstaller\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\seclogon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\QWAVEdrv",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9BA984AD4F03E284382FFBB7A68BEE27",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TermDD\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAuto",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volmgrx",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ShellHWDetection\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcSs\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET CLR Networking\\",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\bthserv\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\circlass\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Schedule\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KSecDD\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Fax\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPCDD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msiserver\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\eventlog\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\30FAECE2400494D4FB69207288EB5B73",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelOperation 3.0.0.0\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\s3cap",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WANARP\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\b57nd60a\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iirsp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FltMgr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UI0Detect",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\gagp30kx\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET Data Provider for SqlServer\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Dnscache",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Mcx2Svc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSDTC\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NDIS\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BFE\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Netman\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdxata\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\storflt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdsata",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\Clsid",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Ndisuio\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sppsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SessionEnv",
        "HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\16AC40BE991DF1643B2800729063B2F9",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasPppoe\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\bthserv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\atapi\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TDTCP\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidBth\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iScsiPrt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nsi\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D725CB8E57307E64EB574E04214D8B5F",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SensrSvc\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSTEE\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DcomLaunch",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FontCache3.0.0.0",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Processor",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F21868A51A175874BB819DCA5FAA40A3",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pla",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\arcsas",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Dnscache\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F41A458014D57E54E8DBD0B0CBC361A2",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vhdmp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BTHPORT\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\intelide\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAgileVpn",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PortProxy",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\17E23EF6C775D324DB90E0E2B7D1CA72",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Processor\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mouhid\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCardSvr\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ProfSvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\stisvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wuauserv\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8020CF43278B2644190F51544810251E",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NDProxy\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\Clsid",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BFE\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdxata\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BFE",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HomeGroupListener\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIP6TUNNEL\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasMan\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E85E64F0A7FC58E47A87E5AB98A6F2DD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSiSCSI\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B1D5EA6004F809D48B117CE563261011",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPDR",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msisadrv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\defragsvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FsDepends",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPDD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb10\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ACPI",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelOperation 3.0.0.0",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Filetrace\\",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfOS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\netprofm\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\285499F23409ED14FB4A01230F5DFA91",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nvstor",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NlaSvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WerSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FEB01D34D0F67E4F9CD810B432C1B91",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4514EC211C8947C4B9BA24F353AFFD50",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIP6\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WmiApRpl\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\67C12EF40671B7342A2F990919031A57",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lltdsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET Data Provider for Oracle",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbhub\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SCSI\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinDefend",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adsi",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer\\run\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MpsSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppID\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellExecuteHooks",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ProtectedStorage\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CSC\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MpsSvc\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\315C767EFC72D8445B1D2D16F72653F0",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelEndpoint 3.0.0.0\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sermouse\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tcpipreg\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\QWAVEdrv\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mpio\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Modem",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KSecPkg\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Netman",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidBatt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\kbdhid\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KeyIso",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcSs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidIr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NativeWifiP\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Schedule",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\flpydisk\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\seclogon\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TBS\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\73964AA699D5B5140ADC41ED3F7DB38A",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\upnphost",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ShellHWDetection\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wecsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\bowser",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wmiApSrv\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AD21E12039BB3BC47B1938BC4ABDFEE2",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pla\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PNRPsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\eventlog\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mpio\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SstpSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSDTC\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SiSRaid4\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Compbatt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\luafv\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WcsPlugInService\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hkmsvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET Data Provider for SqlServer\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSPCLOCK",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Mup",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CompositeBus\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetBIOS\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iaStorV",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SNMPTRAP\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UxSms\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Spooler\\Parameters",
        "HKEY_CLASSES_ROOT\\SystemFileAssociations\\.url",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sbp2port\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidBth\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\Clsid",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3D197E722531D614AB40C182904D9A31",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AudioSrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasSstp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\StorSvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msdsm",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\87C48B95924E3294FBC1766C9225DD0C",
        "HKEY_CLASSES_ROOT\\cmdfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wlansvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinHttpAutoProxySvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NDProxy\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSPQM\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\idsvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\W32Time\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fdPHost",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MozillaMaintenance\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FsDepends\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPDD\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KSecDD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ehRecvr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SENS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PEAUTH\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\clr_optimization_v2.0.50727_64\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KSecPkg\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\b57nd60a\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TDPIPE",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pciide",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\Clsid",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SstpSvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\umbus\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\Clsid",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\xmlprov\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PNRPsvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SensrSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\megasas\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PcaSvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Processor\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\W3SVC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TermDD\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CLFS\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\{EF381EA0-4D07-418D-A490-68AF67CE948B}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelService 3.0.0.0\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FDResPub\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrUsbSer",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Spooler",
        "HKEY_CLASSES_ROOT\\.url\\OpenWithProgids",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nsiproxy\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adsi\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelOperation 3.0.0.0\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAcd",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vdrvroot\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ProtectedStorage\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srv2\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TrkWks\\Parameters",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.url",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Msfs\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdsbs\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AxInstSV\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\p2pimsvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Npfs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DXGKrnl",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\gagp30kx",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\kbdclass\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nvraid\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wudfsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PeerDistSvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tcpipreg\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AmdPPM",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Msfs\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volmgrx\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fvevol\\",
        "HKEY_CLASSES_ROOT\\AllFilesystemObjects",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vwifibus\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TsUsbFlt\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\UserChoice",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Dhcp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\secdrv\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rspndr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pcw\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srv\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET CLR Data",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Filetrace",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\intelppm\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tunnel\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sfloppy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NDIS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iphlpsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WmiAcpi",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Disk\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbprint",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WSearchIdxPi\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CryptSvc\\",
        "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\uliagpkx\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\103857F24A2EDA54A800A41FA570861F",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\xmlprov\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vhdmp\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAgileVpn\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wcncsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventSystem\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfHost\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\2FA90A429E82313489DAA2E2C2F0872C",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PcaSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srv2",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET CLR Networking",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DCLocator\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\umbus",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UmPass\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\ODBC\\ODBC.INI\\ODBC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TrkWks",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidBatt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\clr_optimization_v2.0.50727_64",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbprint\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\swprv",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\Explorer",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\intelppm\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetBIOS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbehci\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RemoteRegistry\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Ntfs\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KtmRm\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE462B32EFD81040A184ED17E00452B",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fastfat\\Parameters",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UGatherer\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mssmbios\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\CurVer",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\viaide\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Mcx2Svc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WIMMount\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\partmgr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BDESVC\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\DriveIcons\\C\\DefaultIcon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\swenum\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UGTHRSVC\\Parameters",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1\\KnownFolders",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WPDBusEnum",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffp_mmc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbcir\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\Setup\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\uagp35",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Serial\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfOS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CNG",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ProfSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdsbs\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vdrvroot",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vmbus",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DCLocator",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E116C831A95AB5B4787CE3086FE83631",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vsmraid\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\{EF381EA0-4D07-418D-A490-68AF67CE948B}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PEAUTH",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinHttpAutoProxySvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mshidkmdf\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\CurVer",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidBatt\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WudfPf",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\piffile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wanarpv6\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\swenum",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AFD\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPDR\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BITS\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ws2ifsl\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\atapi\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TBS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winmgmt\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vwifibus",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Beep\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TabletInputService\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NDIS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sfloppy\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SamSs\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3C68656E520593A45925ADFB41F821B5",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\002F6EFFA8A0A40498F3035BD153685A",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IpFilterDriver",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbehci",
        "HKEY_CLASSES_ROOT\\.url",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WPCSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\inetaccs",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0FD387D006FD9734FA65B249F36DE42A",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ACPI\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sbp2port",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\EEF8AA9EB45B5DB4BBE46B8634C910CD",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\E1G60\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SiSRaid2\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\megasas",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WIMMount\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nfrd960\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NTDS\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPWD\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidUsb\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Parport\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adpahci\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crcdisk\\Parameters",
        "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Themes\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\{AEFD33F3-CC73-4821-AD44-6915063E7FB1}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IRENUM\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinRM\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppMgmt\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iphlpsvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HdAudAddService\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\blbdrive\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IKEEXT\\Parameters",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\scfilter",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WdiServiceHost",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VaultSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wudfsvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ehSched\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Power\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelService 3.0.0.0",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\isapnp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\intelide",
        "HKEY_CLASSES_ROOT\\CLSID\\{FBF23B40-E3F0-101B-8488-00AA003E56F8}\\Implemented Categories\\{00021490-0000-0000-C000-000000000046}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MegaSR\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IRENUM\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srvnet",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Npfs\\",
        "HKEY_LOCAL_MACHINE\\Software\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msisadrv\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B4BBDDC88CEE4DD439E8BB261CE222A8",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdxata",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PropertyBag",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crcdisk",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\secdrv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\W3SVC\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Serial",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WSearch",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pcmcia\\Parameters",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer\\run\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E40FDF839772BEB41AC977860DBB4853",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSKSSRV\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Rasl2tp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\storflt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AudioSrv\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fastfat\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sppuinotify",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\eventlog",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SAS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\1394ohci\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ql2300\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dmvsc\\Parameters",
        "HKEY_CLASSES_ROOT\\*\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\i8042prt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HDAudBus\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Null",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WIMMount",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb10",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RemoteAccess\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BattC\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mssmbios\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\{AEFD33F3-CC73-4821-AD44-6915063E7FB1}\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\defragsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPMIDRV\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\p2pimsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\335F6F64CD461D9469519574D34757EB",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DfsC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vdrvroot\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pcmcia",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WwanSvc\\",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\Setup\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\W32Time",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F05C8358C56DAD54BB81D0A11DD52F41",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wuauserv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winmgmt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Themes",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisTapi\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BTHMODEM\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\drmkaud\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Psched\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CompositeBus",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbohci\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TermService\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mouhid",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPREFMP\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCardSvr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CertPropSvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adsi\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B04950B5EC5C924B8F428B5484A2720",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hidserv\\Parameters",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FileInfo\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WmiApRpl\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WudfPf\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ErrDev\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\s3cap\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\exfat",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\63B1AF366905AF641BA514CCBAE803C4",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vds\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mouclass",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPENCDD",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D0CBB37A94C46943A90AC5008CF1CC9",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AsyncMac\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sppuinotify\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\scfilter\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPNAT",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9F5ED6B416EF0A1448D94799D0FF20BA",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\QWAVE\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vds\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7814D91294731FF4DBBB840810BEB3BB",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B690B72A999998C47B5F93C94A8D43B2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UGatherer",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7C0477DE66D1A6749864FCE02A6DCB6C",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppIDSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MRxDAV\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfDisk",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hcw85cir",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FltMgr\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\StorSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCPolicySvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Dnscache\\Parameters",
        "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisWan",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A0256FF64030E0746A4AA95D3FFD0BE4",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D04063BE69797D4D8505462827A0D19",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dmvsc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\kbdclass",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Brserid\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\{EF381EA0-4D07-418D-A490-68AF67CE948B}\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FltMgr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WANARP",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SensrSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UmRdpService",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hkmsvc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DfsC\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ALG",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdbss\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ehRecvr\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrSerWdm\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\034A8F8E06031EF46BCB4C10469098E5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cdrom",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\ShellEx\\IconHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\flpydisk\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PptpMiniport\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CLFS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\agp440\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\CurVer",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KSecDD\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SDRSVC\\Parameters",
        "HKEY_CURRENT_USER\\SoftWare\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidIr\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nv_agp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mpsdrv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WMPNetworkSvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\p2psvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Fs_Rec\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\{AEFD33F3-CC73-4821-AD44-6915063E7FB1}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPBusEnum\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FontCache3.0.0.0\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hwpolicy\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AFD\\Parameters",
        "HKEY_CLASSES_ROOT\\exefile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffp_sd\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\bowser\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WSearch\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSDTC Bridge 3.0.0.0\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\stisvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\aliide",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wanarpv6",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPNAT\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\i8042prt\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\BE0BD5097A638224EB0DAAE870267F03",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BattC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbuhci\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UGTHRSVC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\drmkaud",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\aliide\\",
        "HKEY_CLASSES_ROOT\\chm.file",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetBT",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MsRPC",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FBEAAA6C37E8AF24B87AAEA0047433BD",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidUsb\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CmBatt\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPWD\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSKSSRV",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\IconHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PolicyAgent\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VaultSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UxSms",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinDefend\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Ndisuio",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mshidkmdf",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TDPIPE\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPCDD\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MTConfig\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CE5B971A0DBB8FD4F83AE0DADC348104",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PolicyAgent\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fdc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.chm",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\elxstor",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppID\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HomeGroupListener\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcEptMapper",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSDTC Bridge 3.0.0.0\\Parameters",
        "HKEY_CLASSES_ROOT\\exefile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NativeWifiP\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SENS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wdf01000",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\04C56B5D827A9194FA2CBFD014EAD0DA",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventSystem",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}",
        "HKEY_CLASSES_ROOT\\.exe\\OpenWithProgids",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EFS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Fax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfNet\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Null\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ql2300",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95E2C34402A93A14FA8CB3420B85375C",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TsUsbFlt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vsmraid",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ErrDev",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfHost",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C1EF68F348457B246A0AD0C18B3079AF",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIPTUNNEL\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbuhci\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\arcsas\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SNMPTRAP",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Netman\\",
        "HKEY_CLASSES_ROOT\\SystemFileAssociations\\.exe",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\secdrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WANARP\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HTTP",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EFS\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Lsa\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CompositeBus\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VgaSave\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wercplsupport\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasMan\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nsi\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FontCache\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPNAT\\",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BITS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pci",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TDTCP",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\W3SVC\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TSDDD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pcw",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UmRdpService\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AsyncMac",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PcaSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IKEEXT",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msiserver",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIP6TUNNEL",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nsi",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MozillaMaintenance\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\elxstor\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MsRPC\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SAS2\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TBS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\megasas\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HpSAMD\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\958C4A0DE6C8D5C428C6E9D875BC33B6",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vga",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AxInstSV\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WmiApRpl",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UGatherer\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wdf01000\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nfrd960",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HomeGroupProvider\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\62293D511DB84E5489074C5AFA18E882",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\inetaccs\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinRM\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HomeGroupProvider",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volmgr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\flpydisk",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FF9FDEA72CD9DDC47A6DAB85F9F76B81",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nvraid",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PptpMiniport\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventSystem\\",
        "HKEY_LOCAL_MACHINE\\Software\\Classes\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HTTP\\Parameters",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sbp2port\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSPQM",
        "HKEY_CLASSES_ROOT\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
        "HKEY_CLASSES_ROOT\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSTEE\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\CurVer",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\monitor\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DfsC\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelEndpoint 3.0.0.0",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LanmanServer",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tdx\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AmdK8\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\92F9143E715DEF045A539256438E41FB",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ql40xx\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Lsa\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SMSvcHost 3.0.0.0\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\swenum\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dot3svc\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\notepad.exe\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Smb\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sfloppy\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BTHPORT\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srvnet\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbuhci",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\exfat\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VgaSave\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbccgp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VaultSvc\\",
        "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TapiSrv",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunServices\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdpbus",
        "HKEY_CLASSES_ROOT\\Applications\\Explorer.exe\\Drives\\C\\DefaultIcon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ksthunk\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lltdsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrFiltLo\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\luafv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wdf01000\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FFFA6DF7EA9EDFC45A1F02FE6DF8F067",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VgaSave",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\spldr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RemoteAccess",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisCap",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DPS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\stexstor",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ws2ifsl\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Ntfs\\Parameters",
        "HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance\\Disabled",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\luafv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\90860AAA7BD3DE34EB32330DD29CAD62",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wercplsupport\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AcpiPmi\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SstpSvc",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SiSRaid4\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srv2\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WacomPen\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MegaSR\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppMgmt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SAS2\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ErrDev\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pciide\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPNP",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\swprv\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\ShellEx\\IconHandler",
        "HKEY_CLASSES_ROOT\\Directory",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrUsbSer\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vds",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\regfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0EF52818FCE3E7B488427C1F8266654E",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\669C9DC1419C0F240B35B36B99AAB50C",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdyboost",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1E82F31DC0D05AA4CB291B7BAA23FC8E",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ldap\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SiSRaid2\\",
        "HKEY_CURRENT_USER\\SOFTWARE\\ODBC\\ODBC.INI\\ODBC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb20",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A7E9995902A24964C9C5D461E1C86F19",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\drmkaud\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\b06bdrv\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4486F7CE8F022FB4EB0154C5226C27A0",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wd",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WmiAcpi\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TsUsbGD",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0411990C889EE9B47BB0B5D356564877",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Rasl2tp\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET CLR Data\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lmhosts",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Parport\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MozillaMaintenance",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\xmlprov",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7BF7ABF4D25C03F4582D4BC3082FB208",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\kbdclass\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fdPHost\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fdPHost\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CLFS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WerSvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HDAudBus",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winmgmt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPREFMP",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrSerWdm\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\uagp35\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TrustedInstaller",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\1394ohci\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LanmanWorkstation\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PropertyBag",
        "HKEY_CLASSES_ROOT\\comfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\040E2A370D6DB2F45AE45A0032BC2179",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pla\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPCDD\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Smb",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sermouse\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MRxDAV\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidBth",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\kbdhid",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KeyIso\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ALG\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdsata\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffp_mmc\\Parameters",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ThumbnailCache",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pcw\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fastfat",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPMIDRV\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasPppoe\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\Clsid",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MMCSS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\circlass",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tunnel\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VSS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nvraid\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\gpsvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WPDBusEnum\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\storvsc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ql40xx\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSSCNTRS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volsnap\\Parameters",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbehci\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wlansvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TermService\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SAS",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\1394ohci",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AudioEndpointBuilder\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ALG\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E3DAE67887931944BCD7171908FA775",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iaStorV\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\netprofm",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\965742E8F65116F4BB2CB01341464FA7",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\inetaccs\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95EE473833000D6409127D1B85882AC9",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EapHost\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\swprv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdsbs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\uliagpkx\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TabletInputService\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\udfs\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffp_sd\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volmgrx\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\895805CC90C04694887EF6BD140A622D",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SAS2",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\clr_optimization_v2.0.50727_32",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisCap\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SysMain",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nsiproxy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ldap\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows Search",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CSC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NETFramework\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DCLocator\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WebClient",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dot3svc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPBusEnum\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DPS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RemoteAccess\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcEptMapper\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdsata\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TDTCP\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET Data Provider for Oracle\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SENS\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SysMain\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\75B368B60C908BA4E87C31F66B02F3F0",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\Explorer",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SAS\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Shell\\RegisteredApplications\\UrlAssociations\\Directory\\OpenWithProgids",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrFiltLo",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sppsvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAcd\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nvstor\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\partmgr\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vga\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Dhcp\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIP6TUNNEL\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VMBusHID\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdide\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\udfs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Serial\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msdsm\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NETFramework",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DXGKrnl\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hidserv\\",
        "HKEY_CLASSES_ROOT\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InProcServer32",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wlansvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinSock2\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\INS5F2B.tmp",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iScsiPrt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbccgp\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MMCSS",
        "HKEY_CLASSES_ROOT\\piffile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAuto\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WmiAcpi\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tunnel",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CryptSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MRxDAV",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SDRSVC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UmPass\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Compbatt\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\clr_optimization_v2.0.50727_32\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tssecsrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WdiServiceHost\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9DD74C0626DC33C479C1929714AB5295",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfProc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSSCNTRS\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UGTHRSVC\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\53F08364FFD17F14B8FD7CA7F52FAE76",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WebClient\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\uliagpkx",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrUsbMdm\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIPTUNNEL",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Power",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SysMain\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ProfSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\exfat\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FE547D6F0D72534A80F89C4AB727618",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WebClient\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinRM",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wcncsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\clr_optimization_v2.0.50727_32\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VSS\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\System",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pciide\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wuauserv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tdx",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Mcx2Svc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volmgr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\napagent\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Msfs",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D5FD8239A83FE564F97379EA15CE8CB6",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\viaide\\",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SMSvcHost 3.0.0.0\\Parameters",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetTcpPortSharing\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LanmanServer\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EapHost",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BTHPORT",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCPolicySvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SCSI\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7636A94AA21EDBB48B6AFFB17E5907B8",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wscsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfNet",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WacomPen",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msdsm\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\arc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrFiltUp\\Parameters",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\blbdrive",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FsDepends\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\ShellEx\\IconHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPDD\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sermouse",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSiSCSI",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\upnphost\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffp_sd",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HdAudAddService",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\33AB3CD4D27277545B5A93CD4ECB96B4",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Windows Workflow Foundation 3.0.0.0",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ksthunk\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WPDBusEnum\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Schedule\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cdrom\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89DF671CDA74E9D4EB10275B10D5CF3F",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9D22CD4619F5DBC499A083AAD70FE7B3",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\aliide\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\stexstor\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LanmanWorkstation\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NlaSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UmPass",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TsUsbFlt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdbss\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Fs_Rec\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasPppoe",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MTConfig\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\DocObject",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisTapi",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\Directory",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vwifibus\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\scfilter\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\gpsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wbengine",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AmdPPM\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisWan\\Parameters",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Ndisuio\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TsUsbGD\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PeerDistSvc",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Windows Workflow Foundation 3.0.0.0\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18D84E9490A485948A17A1F02CDAA62A",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasMan",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdpbus\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ShellHWDetection",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\discache\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AsyncMac\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FontCache",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D38A6F5FC8262149A9FAAE8C621EE3F",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lltdio",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\bthserv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AFD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\monitor\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cmdide\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbcir",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Serenum\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrUsbSer\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppIDSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\defragsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrFiltUp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WudfPf\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NTDS\\Parameters",
        "HKEY_CLASSES_ROOT\\txtfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UI0Detect\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcLocator\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FontCache\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WbioSrvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PolicyAgent",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetBT\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\QWAVE",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1A0857155A8EF604FA5D1648CF382DC7",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HpSAMD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasSstp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfProc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lltdsvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mpio",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\b06bdrv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pci\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_FC",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HpSAMD\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\discache\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TabletInputService",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HTTP\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WbioSrvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcLocator",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\ShellEx\\IconHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\arcsas\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WcsPlugInService",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mountmgr\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SSDPSRV",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fdc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Fs_Rec",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Windows Workflow Foundation 3.0.0.0\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SCSI",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wecsvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BITS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Psched",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\napagent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RemoteRegistry\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelEndpoint 3.0.0.0\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SiSRaid2",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iaStorV\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SiSRaid4",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ESENT\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DXGKrnl\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\napagent\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbohci",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WPCSvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfHost\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CmBatt\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\elxstor\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AE5A0040C41ACA642AF6DB16F4D2F638",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Filetrace\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tssecsrv",
        "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellExecuteHooks\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WwanSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msisadrv\\Parameters",
        "HKEY_CLASSES_ROOT\\scrfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\Clsid",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfDisk\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrUsbMdm\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8691BCC36FF121849A90B085BFAF5E5E",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vhdmp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wbengine\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PNRPAutoReg\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mshidkmdf\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ql2300\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrSerWdm",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\INS5F2B.tmp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vga\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\viaide",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\p2psvc\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcEptMapper\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wecsvc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MMCSS\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Smb\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FE056816E41FD2F4CACD03E7A2CA2E6E",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Appinfo\\Parameters",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb20\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetBIOS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasSstp\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\COMSysApp\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cdrom\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdide",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NlaSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PlugPlay\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BDESVC\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KtmRm\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\COMSysApp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HDAudBus\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Ntfs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunServices",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hcw85cir\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UmRdpService\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sppsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Applications\\INS5F2B.tmp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WerSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\discache",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hkmsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nsiproxy\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAgileVpn\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SSDPSRV\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AeLookupSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrFiltLo\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VMBusHID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BTHMODEM\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\scrfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MpsSvc\\Parameters",
        "HKEY_CLASSES_ROOT\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KeyIso\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ehSched",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\W32Time\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ebdrv\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAcd\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbohci\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}",
        "HKEY_CLASSES_ROOT\\regfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSPQM\\Parameters"
    ],
    "command_line": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\INS5F2B.tmp \/SL3 $40260 C:\\Users\\cuck\\AppData\\Local\\Temp\\b0fdc934c7f8c994633e99b9dcee1ccc70e222ee36e38082ad16d23b982a5b47.bin 1909330 1912744 61952 ",
        "\"C:\\Program Files (x86)\\Trojan Guarder\\Trojan Guarder.exe\""
    ],
    "file_written": [
        "C:\\Program Files (x86)\\Trojan Guarder\\is-B1FT8.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder\\TG5.42.dll",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\INS5F2B.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-8AJE8.tmp",
        "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-2FOAU.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-RFVGO.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-0QUMH.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp\\_shfoldr.dll",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
        "C:\\Program Files (x86)\\Trojan Guarder\\unins000.dat",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-00ORD.tmp",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-GNPSC.tmp",
        "C:\\Program Files (x86)\\Trojan Guarder\\is-KM98T.tmp",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk"
    ],
    "directory_removed": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp"
    ],
    "file_exists": [
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
        "C:\\Users\\cuck\\Desktop",
        "C:\\Python27\\pythonw.exe",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
        "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
        "C:\\Program Files (x86)\\Trojan Guarder\\Trojan Guarder.exe",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries",
        "C:\\Program Files (x86)\\Trojan Guarder\\Visit Our Site.url",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Videos.library-ms",
        "C:\\Python27\\python.exe",
        "C:\\cuckoo_1788.ini",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Documents.library-ms",
        "C:\\Users",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Pictures.library-ms",
        "C:\\Program Files (x86)\\Trojan Guarder",
        "C:\\Program Files (x86)",
        "C:\\Program Files (x86)\\Trojan Guarder\\unins000.exe",
        "C:\\Program Files (x86)\\Trojan Guarder\\Trojan Guarder Help.chm",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\ThumbCacheToDelete",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu",
        "C:\\Users\\Public\\Desktop",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Music.library-ms",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
        "C:\\cuckoo_1504.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk"
    ],
    "mutex": [
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwReaderRefs",
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer",
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer",
        "Local\\Shell.CMruPidlList",
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer",
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer",
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit",
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer",
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex"
    ],
    "file_failed": [
        "C:\\Users\\cuck\\Desktop\\Trojan Guarder.pif",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.pif",
        "C:\\Program Files (x86)\\Trojan Guarder\\WhiteList.txt",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.pif",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
        "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
        "C:\\ProgramData\\Microsoft\\desktop.ini",
        "C:\\cuckoo_1788.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
        "C:\\Program Files (x86)\\Trojan Guarder\\BlackList.txt",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.pif",
        "C:\\Program Files (x86)\\Trojan Guarder",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\desktop.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk",
        "C:\\cuckoo_1504.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.pif",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.pif",
        "C:\\Program Files (x86)\\Trojan Guarder\\TG5.42.dll",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.pif",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk"
    ],
    "guid": [
        "{fdada2fa-894d-47d8-ae78-adf1fd7f28df}",
        "{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}",
        "{1c1800c1-3258-44c2-be80-3deadb6c5e39}",
        "{00021401-0000-0000-c000-000000000046}",
        "{688c934d-0c26-40f6-8d29-d56d72c76b48}",
        "{c0a6c367-c264-4385-a704-9088bdc3640e}",
        "{d9144dcd-e998-4eca-ab6a-dcd83ccba16d}",
        "{b2952b16-0e07-4e5a-b993-58c52cb94cae}",
        "{660b90c8-73a9-4b58-8cae-355b7f55341b}",
        "{00000003-0000-0000-c000-000000000046}",
        "{0c6c4200-c589-11d0-999a-00c04fd655e1}",
        "{add8ba80-002b-11d0-8f0f-00c04fd7d062}",
        "{00000320-0000-0000-c000-000000000046}",
        "{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
        "{42aedc87-2188-41fd-b9a3-0c966feabec1}",
        "{000214f9-0000-0000-c000-000000000046}",
        "{00000000-0000-0000-c000-000000000046}",
        "{00000146-0000-0000-c000-000000000046}",
        "{cef04fdf-fe72-11d2-87a5-00c04f6837cf}",
        "{76765b11-3f95-4af2-ac9d-ea55d8994f1a}",
        "{75121952-e0d0-43e5-9380-1d80483acf72}",
        "{6746c347-576b-4f73-9012-cdfeea251bc4}",
        "{d5f569d0-593b-101a-b569-08002b2dbf7a}",
        "{fe841493-835c-4fa3-b6cc-b4b2d4719848}",
        "{000214e6-0000-0000-c000-000000000046}",
        "{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}",
        "{2fb499a3-cfce-480f-a5f3-2453db7a2b7a}",
        "{08244ee6-92f0-47f2-9fc9-929baa2e7235}",
        "{00000323-0000-0000-c000-000000000046}",
        "{6e682784-1eca-4cf2-988d-96b6e89e9a4d}",
        "{9113a02d-00a3-46b9-bc5f-9c04daddd5d7}",
        "{a1567595-4c2f-4574-a6fa-ecef917b9a40}",
        "{ab8902b4-09ca-4bb6-b78d-a8f59079a8d5}",
        "{cd773740-b187-4974-a1d5-e0ff91372277}",
        "{000214ee-0000-0000-c000-000000000046}",
        "{09b224bd-1335-4631-a7ff-cfd3a92646d7}",
        "{f676c15d-596a-4ce2-8234-33996f445db1}",
        "{896664f7-12e1-490f-8782-c0835afd98fc}",
        "{30a99515-1527-4451-af9f-00c5f0234daf}",
        "{35786d3c-b075-49b9-88dd-029876e11c01}",
        "{46a6eeff-908e-4dc6-92a6-64be9177b41c}",
        "{54410b83-6787-4418-9735-5aaaabe83a9a}",
        "{f02c1a0d-be21-4350-88b0-7367fc96ef3c}",
        "{50ef4544-ac9f-4a8e-b21b-8a26180db13f}",
        "{edb5f444-cb8d-445a-a523-ec5ab6ea33c7}",
        "{0af10cec-2ecd-4b92-9581-34f6ae0637f3}"
    ],
    "file_read": [
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Desktop.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\desktop.ini",
        "C:\\Windows\\Media\\Windows Navigation Start.wav",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
        "C:\\Users\\Public\\Desktop\\desktop.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC\\Desktop.ini",
        "C:\\Windows\\System32\\EhStorShell.dll",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
        "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\desktop.ini",
        "C:\\Program Files (x86)\\Trojan Guarder\\Trojan Guarder.exe",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\desktop.ini",
        "C:\\Users\\cuck\\Desktop\\desktop.ini",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\b0fdc934c7f8c994633e99b9dcee1ccc70e222ee36e38082ad16d23b982a5b47.bin",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\desktop.ini",
        "C:\\Users\\desktop.ini",
        "C:\\Windows\\win.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility\\Desktop.ini",
        "C:\\Users\\cuck\\Pictures\\desktop.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\Desktop.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk",
        "C:\\Windows\\System32\\ntshrui.dll",
        "C:\\Program Files (x86)\\desktop.ini",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games\\desktop.ini",
        "C:\\Users\\Public\\desktop.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
        "C:\\Program Files (x86)\\Trojan Guarder\\TG5.42.dll",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools\\Desktop.ini",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk"
    ],
    "regkey_read": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0A191B45599EEB74CA305184EA3C2A94\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\2\\0",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Favorites",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{NN198O3P-PQ8P-7QR1-98Q1-O460S637193O}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersLibraries\\NameSpace\\DelegateFolders\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\DisableProcessIsolation",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\LocalizedString",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\863CA21BBA4DFCE489FDF96EAB898616\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSSCNTRS\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\Content Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\FavoritesRemovedChanges",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Zngu Vachg Cnary.yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy VFR.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NTDS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.TrggvatFgnegrq",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F356843B045CC0A4BA0D83C1D85AAAFD\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Music",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PublishExpandedPath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\qsethv.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\103857F24A2EDA54A800A41FA570861F\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\UseInProcHandlerCache",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95E2C34402A93A14FA8CB3420B85375C\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\LoadWithoutCOM",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InfoTip",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Pnyphyngbe.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Search\\CurrentVersion",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\Start",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\SnippingTool.exe,-15051",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\RegisteredOwner",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\ShellEx\\IconHandler\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{11016101-E366-4D22-BC06-4ADA335C892B}\\SuppressionPolicy",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\StubPath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\\JvaqbjfCbjreFuryy\\i1.0\\CbjreFuryy_VFR.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Jvaqbjf CbjreFuryy Zbqhyrf.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9BA984AD4F03E284382FFBB7A68BEE27\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\inetaccs\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoWebView",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Pictures",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Znvagranapr\\Perngr Erpbirel Qvfp.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\IsShortcut",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\\rkcybere.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lnk\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\{5D76B67F-9B3D-44BB-B6AE-25DA4F638A67} 2",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\17E23EF6C775D324DB90E0E2B7D1CA72\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4626147D107665540A84D43A5908E74D\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Fvqrone.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4486F7CE8F022FB4EB0154C5226C27A0\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\StubPath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\qsethv.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\\SortOrderIndex",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9D22CD4619F5DBC499A083AAD70FE7B3\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InitFolderHandler",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\FbhaqErpbeqre.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\DefaultIcon\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\002F6EFFA8A0A40498F3035BD153685A\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\SortOrderIndex",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Windows Workflow Foundation 3.0.0.0\\ImagePath",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\NetworkExplorer.dll,-1",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\{5D76B67F-9B3D-44BB-B6AE-25DA4F638A67} 2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\717591555BCB1604BA9777E8A55D0E41\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Category",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\bqopnq32.rkr",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\displayswitch.exe,-320",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\StubPath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\R7PS176R110P211O",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{896664F7-12E1-490F-8782-C0835AFD98FC}\\InProcServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3C68656E520593A45925ADFB41F821B5\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\xmlprov\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jbeqcnq.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\FolderTypeID",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\2\\0\\MRUListEx",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Zrqvn Pragre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\HideDesktopIcons\\NewStartPanel\\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ett\\Extension\\{223bd3fe-345e-ffae-3c9f-fe62375679e1}\\Services",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{645FF040-5081-101B-9F08-00AA002F954E}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PublishExpandedPath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\erpqvfp.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\HomeGroup\\UIStatusCache\\UIStatus",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CE5B971A0DBB8FD4F83AE0DADC348104\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHPORT\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.chm\\PerceivedType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Rirag Ivrjre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InfoTip",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\GnoGvc.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\HideDesktopIcons\\NewStartPanel\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\batfile\\shell\\open\\command\\(Default)",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\mstsc.exe,-4000",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\958C4A0DE6C8D5C428C6E9D875BC33B6\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\DefaultIcon\\OpenIcon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\System.HideOnDesktop",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\Start",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\28\\Shell\\TV_TopViewID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Security",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\ColInfo",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\{5D76B67F-9B3D-44BB-B6AE-25DA4F638A67} 2",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\WindowsAnytimeUpgradeUI.exe,-1",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResource",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParentFolder",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\DefaultIcon\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfDisk\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flap Pragre.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Stream",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\{5D76B67F-9B3D-44BB-B6AE-25DA4F638A67} 2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B04950B5EC5C924B8F428B5484A2720\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Npprffvovyvgl\\Fcrrpu Erpbtavgvba.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FBEAAA6C37E8AF24B87AAEA0047433BD\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{daf95313-e44d-46af-be1b-cbacea2c3065}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\Clguba (pbzznaq yvar).yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\System.IsPinnedToNameSpaceTree",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Cresbeznapr Zbavgbe.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\bfx.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Gebwna Thneqre.yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_TrackProgs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\FuncrPbyyrpgbe.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_LargeMFUIcons",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\qvfcynlfjvgpu.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UGTHRSVC\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ESENT\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UGatherer\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResourceType",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{P804OON7-SN5S-POS7-8O55-2096R5S972PO}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Data\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\AppInit_DLLs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\Start",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\Mode",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6TUNNEL\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\kcfepuij.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\2FA90A429E82313489DAA2E2C2F0872C\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Pbzznaq Cebzcg.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\AlwaysShowExt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\{EF381EA0-4D07-418D-A490-68AF67CE948B}\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonPictures",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Roamable",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\aneengbe.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\Zbqhyr Qbpf.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\335F6F64CD461D9469519574D34757EB\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalizedName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Cache",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F41A458014D57E54E8DBD0B0CBC361A2\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiApRpl\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{35786D3C-B075-49B9-88DD-029876E11C01}\\InProcServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7814D91294731FF4DBBB840810BEB3BB\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Lsa\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\xmlprov\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\Max Cached Icons",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\comfile\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D0CBB37A94C46943A90AC5008CF1CC9\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\Segoe UI",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\System.HideOnDesktop",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\HomeGroup\\UIStatusCache\\OnlyMember",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfProc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\LoadWithoutCOM",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\Public",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane14",
        "HKEY_CURRENT_USER\\Control Panel\\Desktop\\Wallpaper",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane16",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane10",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane11",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane12",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane13",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiApRpl\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PublishExpandedPath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_NotifyNewApps",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DCLocator\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\freivprf.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\VQYR (Clguba THV).yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AE5A0040C41ACA642AF6DB16F4D2F638\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W3SVC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Roamable",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\FFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InfoTip",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Zrzbel Qvntabfgvpf Gbby.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Flfgrz Vasbezngvba.yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\SortOrderIndex",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfpbasvt.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf QIQ Znxre.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CB2182A03B6B11341A1F09A021991CE1\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.chm\\Content Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\11E2BA15171FE704B98E7505E58D7749\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NTDS\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\75B368B60C908BA4E87C31F66B02F3F0\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHPORT\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\P:\\Hfref\\phpx\\Qrfxgbc\\Gebwna Thneqre.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TSDDD\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\67C12EF40671B7342A2F990919031A57\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\90860AAA7BD3DE34EB32330DD29CAD62\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\rhqprqvg.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Erzbgr Qrfxgbc Pbaarpgvba.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NETFramework\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PreCreate",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zntavsl.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfNalgvzrHctenqrHV.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\System.HideOnDesktop",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InitFolderHandler",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\QIQ Znxre\\QIQZnxre.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPNP\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResource",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\FavoritesChanges",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\285499F23409ED14FB4A01230F5DFA91\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\System.DateModified",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{53123611-QN37-S8QN-SNP9-03R76QO9Q64Q}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A7E9995902A24964C9C5D461E1C86F19\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfNet\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\DefaultIcon\\OpenIcon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Start",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\IconSize",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\\System.HideOnDesktop",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalRedirectOnly",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ZrqvnCynlre32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E116C831A95AB5B4787CE3086FE83631\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetHood",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\System.IsPinnedToNameSpaceTree",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\RelativePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Jvaqbjf Rkcybere.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\regfile\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8ECC347096FA78C4E8291F449F71E16E\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D38A6F5FC8262149A9FAAE8C621EE3F\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{26EE0668-A00A-44D7-9371-BEB064C98683}\\System.IsPinnedToNameSpaceTree",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SeparateProcess",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\Jvaqbjf Wbheany.yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\ProfilesDirectory",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\\u5b8b\u4f53",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane15",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{04731B67-D933-450A-90E6-4ACD2E9408FE}\\SortOrderIndex",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SMSvcHost 3.0.0.0\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\895805CC90C04694887EF6BD140A622D\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\DeviceState",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89BBBC8A0D32B014696C4BA3C20CDD34\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\\SortOrderIndex",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F05C8358C56DAD54BB81D0A11DD52F41\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ServiceModelEndpoint 3.0.0.0\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_TrackProgs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Networking\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\System.IsPinnedToNameSpaceTree",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\efgehv.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.URL\\Content Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\DefaultIcon\\OpenIcon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9753E3A35E3BDFB468DF95B5D19C8A04\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\System.HideOnDesktop",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\LocalizedString",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InitFolderHandler",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{Q4N262QQ-PR44-Q105-S36O-9Q77N8PO65N4}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InitFolderHandler",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Zrqvn Cynlre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4514EC211C8947C4B9BA24F353AFFD50\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{26EE0668-A00A-44D7-9371-BEB064C98683}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Video",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A0256FF64030E0746A4AA95D3FFD0BE4\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{e345f35f-9397-435c-8f95-4e922c26259e}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7C0477DE66D1A6749864FCE02A6DCB6C\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zboflap.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\P:\\Clguba27\\clguba.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfProc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D725CB8E57307E64EB574E04214D8B5F\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 14",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Punenpgre Znc.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Windows Workflow Foundation 3.0.0.0\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{7SR8Q22N-SO1Q-N8OR-01R3-6P8693961R6R}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\AlwaysShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalizedName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\DefaultIcon\\OpenIcon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\lnkfile\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\ProgramFilesDir",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B06071FE021ECB04E8B3BF1E39AD5BB3\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PortProxy\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84BBAC70FB00B6046881B55CB3122F0F\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Vagrearg Rkcybere (64-ovg).yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Fgvpxl Abgrf.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\\SortOrderIndex",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\ArgCebw.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Abgrcnq.yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\\Gebwna Thneqre\\Gebwna Thneqre.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Lsa\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ErzbgrQrfxgbc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Attributes",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Fbhaq Erpbeqre.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{450D8FBA-AD25-11D0-98A8-0800361B1103}\\SortOrderIndex",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adsi\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\DefaultIcon\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9F5ED6B416EF0A1448D94799D0FF20BA\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\04C56B5D827A9194FA2CBFD014EAD0DA\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetCrawling",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{E345F35F-9397-435C-8F95-4E922C26259E}\\SortOrderIndex",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\NoOplock",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Favccvat Gbby.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\CLSID\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for Oracle\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParsingName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zvtjvm\\cbfgzvt.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Cevag Znantrzrag.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\92F9143E715DEF045A539256438E41FB\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\RelativePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Zntavsl.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Jvaqbjf Wbheany\\Wbheany.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ESENT\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F591EF48DE97A00428A5BC1AFFFAA868\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\{AEFD33F3-CC73-4821-AD44-6915063E7FB1}\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\87C48B95924E3294FBC1766C9225DD0C\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B1D5EA6004F809D48B117CE563261011\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalizedName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfvasb32.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\ImagePath",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\zvc.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\ZqFpurq.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\16AC40BE991DF1643B2800729063B2F9\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Description",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\OobeFldr.dll,-33056",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W3SVC\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\HideDesktopIcons\\NewStartPanel\\{645FF040-5081-101B-9F08-00AA002F954E}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\28\\Shell\\TV_FolderType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\shell",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSSCNTRS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClassicShell",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\System.NamespaceCLSID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0FD387D006FD9734FA65B249F36DE42A\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Name",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{OO044OSQ-25O7-2SNN-22N8-6371N93R0456}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FFFA6DF7EA9EDFC45A1F02FE6DF8F067\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\1",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\0",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\2",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{9343812E-1C37-4A49-A12E-4B2D810D956B}\\SortOrderIndex",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{31E4FA78-02B4-419F-9430-7B7585237C77}\\ProxyStubClsid32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for SqlServer\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ett\\Extension\\{223bd3fe-345e-ffae-3c9f-fe62375679e1}\\Cache",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InfoTip",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\load",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\EEF8AA9EB45B5DB4BBE46B8634C910CD\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Jvaqbjf Rnfl Genafsre.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\inetaccs\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SMSvcHost 3.0.0.0\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\LocalizedString",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIPTUNNEL\\ImagePath",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\XpsRchVw.exe,-102",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B5C8B2FB95B57147954C18085D53ACE\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfOS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\HideDesktopIcons\\NewStartPanel\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CF65AB832507EDB4BB357F9D8E0431BD\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E85E64F0A7FC58E47A87E5AB98A6F2DD\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D04063BE69797D4D8505462827A0D19\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Znvagranapr\\Erzbgr Nffvfgnapr.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PublishExpandedPath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Vagrearg Rkcybere.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC Bridge 3.0.0.0\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1E82F31DC0D05AA4CB291B7BAA23FC8E\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\UseDoubleClickTimer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0411990C889EE9B47BB0B5D356564877\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\ShellExecuteHooks\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D3541DFF9B79C584284E8981624C04CB\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7BF7ABF4D25C03F4582D4BC3082FB208\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8691BCC36FF121849A90B085BFAF5E5E\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy (k86).yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\FavoritesChanges",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{450D8FBA-AD25-11D0-98A8-0800361B1103}\\SuppressionPolicy",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\FavccvatGbby.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_LargeMFUIcons",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 13",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 14",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\ArgjbexCebwrpgvba.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\FavoritesRemovedChanges",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\StartMenu_Balloon_Time",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{35786D3C-B075-49B9-88DD-029876E11C01}\\InProcServer32\\LoadWithoutCOM",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParentFolder",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{15067OP1-P5N8-425R-37P6-SN0O891674S9}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.URL\\PerceivedType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\HideDesktopIcons\\NewStartPanel\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\62293D511DB84E5489074C5AFA18E882\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{89D83576-6BD1-4c86-9454-BEB04E94C819}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\{EF381EA0-4D07-418D-A490-68AF67CE948B}\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89DF671CDA74E9D4EB10275B10D5CF3F\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfcnvag.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\System.FileAttributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Category",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\_LabelFromReg",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Jvaqbjf Zrqvn Cynlre.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Nalgvzr Hctenqr.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Vagrearg Rkcybere.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\{EF381EA0-4D07-418D-A490-68AF67CE948B}\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\SNTSearch.dll,-505",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9DD74C0626DC33C479C1929714AB5295\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\DefaultIcon\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalizedName",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\2\\0\\NodeSlot",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\vFPFV Vavgvngbe.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Start",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\LogicalViewMode",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\System.IsPinnedToNameSpaceTree",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{98D99750-0B8A-4C59-9151-589053683D73}\\SortOrderIndex",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Erfbhepr Zbavgbe.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPNP\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Networking\\Start",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\2\\MRUListEx",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ServiceModelService 3.0.0.0\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\InProcServer32\\LoadWithoutCOM",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonMusic",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfCbjreFuryy\\i1.0\\cbjrefuryy.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearchIdxPi\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BattC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\System.HideOnDesktop",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PreCreate",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.VagreargRkcybere.64Ovg",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfOS\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Desktop",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\\SortOrderIndex",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\\InProcServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Sversbk.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for SqlServer\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3D197E722531D614AB40C182904D9A31\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{26EE0668-A00A-44D7-9371-BEB064C98683}\\{5D76B67F-9B3D-44BB-B6AE-25DA4F638A67} 2",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ServiceModelOperation 3.0.0.0\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PublishExpandedPath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\\JvaqbjfCbjreFuryy\\i1.0\\cbjrefuryy.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearchIdxPi\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\{5D76B67F-9B3D-44BB-B6AE-25DA4F638A67} 2",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JS.zfp",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\GnoGvc.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\FXSRESM.dll,-114",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\System.HideOnDesktop",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\63B1AF366905AF641BA514CCBAE803C4\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JSF.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\040E2A370D6DB2F45AE45A0032BC2179\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E40FDF839772BEB41AC977860DBB4853\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Name",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\FavoritesRemovedChanges",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\run",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PortProxy\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84C584688CFC74A4E9D36E5EE2E02FA7\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pbzrkc.zfp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for Oracle\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DontShowSuperHidden",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Frphevgl Pbasvthengvba Znantrzrag.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{896664F7-12E1-490F-8782-C0835AFD98FC}\\InProcServer32\\LoadWithoutCOM",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\AlwaysShowExt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDD\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Jvaqbjf Rnfl Genafsre Ercbegf.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Flfgrz Pbasvthengvba.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\RegisteredOrganization",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Attributes",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\Sort",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ServiceModelEndpoint 3.0.0.0\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DCLocator\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Gebwna Thneqre\\Gebwna Thneqre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\System.NamespaceCLSID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C1EF68F348457B246A0AD0C18B3079AF\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fs_Rec\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE19F224928A59468049F045950CB08\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\669C9DC1419C0F240B35B36B99AAB50C\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Stream",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W3SVC\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Stream",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{8NOQ94SO-R7Q6-84N6-N997-P918RQQR0NR5}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\\InProcServer32\\LoadWithoutCOM",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B690B72A999998C47B5F93C94A8D43B2\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersLibraries\\NameSpace\\DelegateFolders\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TSDDD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E3DAE67887931944BCD7171908FA775\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6TUNNEL\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfCbjreFuryy\\i1.0\\CbjreFuryy_VFR.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Aneengbe.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\DefaultIcon\\OpenIcon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\HideDesktopIcons\\NewStartPanel\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InitFolderHandler",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Jvaqbjf AG\\Npprffbevrf\\jbeqcnq.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\notepad.exe\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fs_Rec\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfen.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features\\TclTk",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIPTUNNEL\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pyrnazte.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Ba-Fperra Xrlobneq.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jrypbzr Pragre.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AD21E12039BB3BC47B1938BC4ABDFEE2\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18F5DB38C45303843B06B1B5025E4820\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\BE0BD5097A638224EB0DAAE870267F03\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CDBF699A8F2EAC2438564C3D50E9E638\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Attributes",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\vfpfvpcy.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{26EE0668-A00A-44D7-9371-BEB064C98683}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1C1ED53B8F25FD248955C15232E46886\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zvtjvm\\zvtjvm.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\30FAECE2400494D4FB69207288EB5B73\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\ImagePath",
        "HKEY_CURRENT_USER\\AppEvents\\Schemes\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResourceType",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Personal",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC Bridge 3.0.0.0\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.VagreargRkcybere.Qrsnhyg",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfDisk\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\ImagePath",
        "HKEY_CURRENT_USER\\AppEvents\\Schemes\\Apps\\Explorer\\Navigating\\.Current\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\FuncrPbyyrpgbe.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Jvaqbjf Sverjnyy jvgu Nqinaprq Frphevgl.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\DefaultIcon\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane9",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B4BBDDC88CEE4DD439E8BB261CE222A8\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\piffile\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Snk naq Fpna.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FE056816E41FD2F4CACD03E7A2CA2E6E\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\{AEFD33F3-CC73-4821-AD44-6915063E7FB1}\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\{5D76B67F-9B3D-44BB-B6AE-25DA4F638A67} 2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\\SortOrderIndex",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\CommonFilesDir",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{P1P6S8NP-40N3-0S5P-146S-65N9QP70OOO4}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UGatherer\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\freivprf.zfp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ServiceModelService 3.0.0.0\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FEB01D34D0F67E4F9CD810B432C1B91\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParentFolder",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FF9FDEA72CD9DDC47A6DAB85F9F76B81\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalRedirectOnly",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Qvfx Pyrnahc.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\296744B7EBFEB2741A47781AE6E32269\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.FgvpxlAbgrf",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Jvaqbjf Rkcybere.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.chm\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7636A94AA21EDBB48B6AFFB17E5907B8\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{98D99750-0B8A-4c59-9151-589053683D73}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{OQ3S924R-55SO-N1ON-9QR6-O50S9S2460NP}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E429E5BC27530F4786481EC687D9EC9\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\ImagePath",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\28\\Shell\\TV_TopViewVersion",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\AlwaysShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\FolderTypeID",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pnyp.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy VFR (k86).yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\System.IsPinnedToNameSpaceTree",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features\\DefaultFeature",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_MinMFU",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Flfgrz Gbbyf\\Cevingr Punenpgre Rqvgbe.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UGTHRSVC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResourceType",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfNet\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Desktop\\General\\Wallpaper",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_MinMFU",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NETFramework\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5\\DefaultFeature",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE462B32EFD81040A184ED17E00452B\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\SortOrderIndex",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersLibraries\\NameSpace\\DelegateFolders\\{896664F7-12E1-490f-8782-C0835AFD98FC}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\KCF Ivrjre.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane7",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8020CF43278B2644190F51544810251E\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Icon",
        "\\REGISTRY\\USER\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C4040CC509FB0DC4886F590DDF6B6132\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{26EE0668-A00A-44D7-9371-BEB064C98683}\\System.HideOnDesktop",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0EF52818FCE3E7B488427C1F8266654E\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\HideDesktopIcons\\NewStartPanel\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{35786D3C-B075-49b9-88DD-029876E11C01}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{374DE290-123F-4565-9164-39C4925E467B}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0F4DC93AAA8AD1D448BC4E6A207F4FE0\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\EnableShareDenyNone",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Desktop",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.URL\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\InProcServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResourceType",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Qngn Fbheprf (BQOP).yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\315C767EFC72D8445B1D2D16F72653F0\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 6",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\AppInit_DLLs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{89D83576-6BD1-4C86-9454-BEB04E94C819}\\SortOrderIndex",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NormalizeLinkNetPidls",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\{AEFD33F3-CC73-4821-AD44-6915063E7FB1}\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1A0857155A8EF604FA5D1648CF382DC7\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\System.IsPinnedToNameSpaceTree",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Sversbk.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Pbzcbarag Freivprf.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{04731B67-D933-450a-90E6-4ACD2E9408FE}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ServiceModelOperation 3.0.0.0\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\StubPath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{56784854-C6CB-462B-8169-88E350ACB882}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_NotifyNewApps",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Icon",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Gnfx Fpurqhyre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParentFolder",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C} {000214E6-0000-0000-C000-000000000046} 0xFFFF",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{9343812e-1c37-4a49-a12e-4b2d810d956b}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\cmdfile\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Start",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalRedirectOnly",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pzq.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonVideo",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Cnvag.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\\SortOrderIndex",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\LocalizedString",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalRedirectOnly",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\53F08364FFD17F14B8FD7CA7F52FAE76\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\DocObject",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Flfgrz Erfgber.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\ImagePath",
        "HKEY_CURRENT_USER\\AppEvents\\Schemes\\Apps\\Explorer\\Navigating\\.Current\\Default Flags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\puneznc.rkr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\abgrcnq.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\StartMenu_Balloon_Time",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\034A8F8E06031EF46BCB4C10469098E5\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 6",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BattC\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\TurnOffSPIAnimations",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lnk\\ShellEx\\{BB2E617C-0920-11D1-9A0B-00C04FC2D6C1}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\IsShortcut",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{8NN47365-O2O3-1961-69RO-S866R376O12S}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ZrqvnPragre",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Gnfx Fpurqhyre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Start",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU Size",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\inetaccs\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{11016101-E366-4D22-BC06-4ADA335C892B}\\SortOrderIndex",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHPORT\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\cevagznantrzrag.zfp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FE547D6F0D72534A80F89C4AB727618\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\33AB3CD4D27277545B5A93CD4ECB96B4\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{QNN168QR-4306-P8OP-8P11-O596240OQQRQ}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Data\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\PendingFileRenameOperations",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D5FD8239A83FE564F97379EA15CE8CB6\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\System.DateModified",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A558E619ABC4CE5479C1DA5070EFBF81\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5\\TclTk",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95EE473833000D6409127D1B85882AC9\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\LocalizedString",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Zbovyvgl Pragre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\965742E8F65116F4BB2CB01341464FA7\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\73964AA699D5B5140ADC41ED3F7DB38A\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\\SortOrderIndex",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane6",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane4",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane3",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane1",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane8",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Pbzchgre Znantrzrag.yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\qvfcynlfjvgpu.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Documents",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\xmlprov\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9E40FDB6330EBA242A4BD5F4FDD0B803\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\UseOutOfProcHandlerCache",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adsi\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\scrfile\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F21868A51A175874BB819DCA5FAA40A3\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSimpleStartMenu",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18D84E9490A485948A17A1F02CDAA62A\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\RelativePath"
    ],
    "directory_enumerated": [
        "C:\\Windows\\System32\\*.*",
        "C:\\Users\\cuck\\AppData",
        "d:\\AUTORUN.INF",
        "C:\\Users\\cuck\\Desktop",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp",
        "v:\\AUTORUN.INF",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp\\_shfoldr.dll",
        "C:\\Windows\\System32",
        "y:\\AUTORUN.INF",
        "f:\\AUTORUN.INF",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\INS5F2B.tmp",
        "e:\\AUTORUN.INF",
        "s:\\AUTORUN.INF",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
        "q:\\AUTORUN.INF",
        "m:\\AUTORUN.INF",
        "o:\\AUTORUN.INF",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp\\*",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\*",
        "C:\\*.*",
        "r:\\AUTORUN.INF",
        "c:\\AUTORUN.INF",
        "C:\\Users",
        "p:\\AUTORUN.INF",
        "t:\\AUTORUN.INF",
        "i:\\AUTORUN.INF",
        "w:\\AUTORUN.INF",
        "l:\\AUTORUN.INF",
        "h:\\AUTORUN.INF",
        "z:\\AUTORUN.INF",
        "C:\\Users\\cuck",
        "C:\\Program Files (x86)",
        "j:\\AUTORUN.INF",
        "k:\\AUTORUN.INF",
        "C:\\ProgramData\\Microsoft\\Windows",
        "C:\\Program Files (x86)\\Trojan Guarder\\unins???.*",
        "C:\\Users\\cuck\\AppData\\Local",
        "C:\\Windows\\System32\\ntshrui.dll",
        "x:\\AUTORUN.INF",
        "u:\\AUTORUN.INF",
        "g:\\AUTORUN.INF",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs",
        "C:\\Program Files (x86)\\*.*",
        "C:\\Windows",
        "C:\\Users\\cuck\\AppData\\Local\\Temp",
        "n:\\AUTORUN.INF"
    ],
    "regkey_written": [
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\Rev",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\LogicalViewMode",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1\\Inno Setup: Icon Group",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\Mode",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1\\DisplayName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ett\\Extension\\{223bd3fe-345e-ffae-3c9f-fe62375679e1}\\Cache",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1\\DisplayIcon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command\\(Default)",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\Vid",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1\\Inno Setup: App Path",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\\Gebwna Thneqre\\Gebwna Thneqre.rkr",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\28\\Shell\\TV_TopViewVersion",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1\\Inno Setup: Setup Version",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts\\C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\HRZR_PGYFRFFVBA",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1\\Inno Setup: User",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\ProgramsCache",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\28\\Shell\\TV_TopViewID",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\Sort",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\LanguageList",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\ColInfo",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\notepad.exe\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1\\UninstallString",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\IconSize",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\28\\Shell\\TV_FolderType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ett\\Extension\\{223bd3fe-345e-ffae-3c9f-fe62375679e1}\\Services",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\FFlags"
    ]
}

Dropped

[
    {
        "yara": [],
        "sha1": "f65e9b3f1677e19a1b06794902a71381573f3e7f",
        "name": "e65b483596bdd687_tg5.42.dll",
        "filepath": "C:\\Program Files (x86)\\Trojan Guarder\\TG5.42.dll",
        "type": "ASCII text, with no line terminators",
        "sha256": "e65b483596bdd6877d125d823f0995704d5110d908505205fc5f4cc3d0c8b549",
        "urls": [],
        "crc32": "389710A3",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/e65b483596bdd687_tg5.42.dll",
        "ssdeep": null,
        "size": 5,
        "sha512": "ec62c6bb590718263d7ffe2aedabbc0ce633dea200852ddc9a77f3931c7d9716454273b52f8bf331eefc1e2d3cb5724d45e15993134a42e54bc0e46ff32d2e37",
        "pids": [
            1504
        ],
        "md5": "f644402295a1fe723ce75a9138497437"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "8993525f8a4cf073d664afd40b4023c2a87bf211",
        "name": "009f83e5df89f322_help.lnk",
        "filepath": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Fri Dec  7 09:47:52 2007, mtime=Sun Apr 19 14:53:19 2020, atime=Fri Dec  7 09:47:52 2007, length=160163, window=hide",
        "sha256": "009f83e5df89f322be5923e833d07d38af0068d4e6b6c69a3b50def3d2256615",
        "urls": [],
        "crc32": "5E93F46E",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/009f83e5df89f322_help.lnk",
        "ssdeep": null,
        "size": 1046,
        "sha512": "a63c33a9e312dba39df85d0293582778ecc6fb4f088da040f6a126f71a084c43e1ef57fbac89dbd7fa91acb1f03ad539152aeca3c24c9644bcc73f34f7c43e9b",
        "pids": [
            1480
        ],
        "md5": "0457dec86c0e3ac6318f02dab0765471"
    },
    {
        "yara": [],
        "sha1": "dc82887a20c2eff851240b04745450198313630a",
        "name": "01293bb8d32d4164_unins000.exe",
        "filepath": "c:\\program files (x86)\\trojan guarder\\unins000.exe",
        "type": "PE32 executable (GUI) Intel 80386, for MS Windows",
        "sha256": "01293bb8d32d4164d5e5427aa9f3e36bbc7ed9f97d76ed7520ba92ca1224c09c",
        "urls": [],
        "crc32": "781DBD64",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/01293bb8d32d4164_unins000.exe",
        "ssdeep": null,
        "size": 82253,
        "sha512": "40b4beba5e8cbde974647b428a1d65d1a57c1457e628a6b79375f32bc884a967f90bb32bc96798774ce1d3307b4954822aad2f8b2bcbd7577fdb04add43ededd",
        "pids": [
            1480
        ],
        "md5": "c67114b6bed0149290aca5ddce032ebe"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "Contains an embedded PE32 file",
                    "author": "nex"
                },
                "name": "embedded_pe",
                "offsets": {
                    "b": [
                        [
                            1313012,
                            0
                        ],
                        [
                            1358052,
                            0
                        ],
                        [
                            1409012,
                            0
                        ],
                        [
                            1459972,
                            0
                        ],
                        [
                            1510932,
                            0
                        ],
                        [
                            1555972,
                            0
                        ],
                        [
                            1601012,
                            0
                        ],
                        [
                            1651972,
                            0
                        ],
                        [
                            1702932,
                            0
                        ]
                    ]
                },
                "strings": [
                    "VGhpcyBwcm9ncmFt"
                ]
            },
            {
                "meta": {
                    "description": "A non-Windows executable contains win32 API functions names",
                    "author": "nex"
                },
                "name": "embedded_win_api",
                "offsets": {
                    "api6": [
                        [
                            1025124,
                            2
                        ],
                        [
                            1086486,
                            2
                        ],
                        [
                            1119806,
                            2
                        ],
                        [
                            1163244,
                            2
                        ],
                        [
                            1206682,
                            2
                        ],
                        [
                            1250506,
                            2
                        ],
                        [
                            1293558,
                            2
                        ],
                        [
                            1338598,
                            2
                        ],
                        [
                            1383638,
                            2
                        ],
                        [
                            1434598,
                            2
                        ],
                        [
                            1485558,
                            2
                        ],
                        [
                            1536518,
                            2
                        ],
                        [
                            1581558,
                            2
                        ],
                        [
                            1626598,
                            2
                        ],
                        [
                            1677558,
                            2
                        ],
                        [
                            1728518,
                            2
                        ]
                    ],
                    "api2": [
                        [
                            1024732,
                            0
                        ],
                        [
                            1086094,
                            0
                        ],
                        [
                            1119414,
                            0
                        ],
                        [
                            1162852,
                            0
                        ],
                        [
                            1206290,
                            0
                        ],
                        [
                            1250114,
                            0
                        ],
                        [
                            1293166,
                            0
                        ],
                        [
                            1338206,
                            0
                        ],
                        [
                            1383246,
                            0
                        ],
                        [
                            1434206,
                            0
                        ],
                        [
                            1485166,
                            0
                        ],
                        [
                            1536126,
                            0
                        ],
                        [
                            1581166,
                            0
                        ],
                        [
                            1626206,
                            0
                        ],
                        [
                            1677166,
                            0
                        ],
                        [
                            1728126,
                            0
                        ]
                    ],
                    "api3": [
                        [
                            1024906,
                            1
                        ],
                        [
                            1086268,
                            1
                        ],
                        [
                            1119588,
                            1
                        ],
                        [
                            1163026,
                            1
                        ],
                        [
                            1206464,
                            1
                        ],
                        [
                            1250288,
                            1
                        ],
                        [
                            1293340,
                            1
                        ],
                        [
                            1338380,
                            1
                        ],
                        [
                            1383420,
                            1
                        ],
                        [
                            1434380,
                            1
                        ],
                        [
                            1485340,
                            1
                        ],
                        [
                            1536300,
                            1
                        ],
                        [
                            1581340,
                            1
                        ],
                        [
                            1626380,
                            1
                        ],
                        [
                            1677340,
                            1
                        ],
                        [
                            1728300,
                            1
                        ]
                    ]
                },
                "strings": [
                    "R2V0UHJvY0FkZHJlc3M=",
                    "TG9hZExpYnJhcnlB",
                    "V3JpdGVGaWxl"
                ]
            },
            {
                "meta": {
                    "description": "Matched shellcode byte patterns",
                    "author": "nex"
                },
                "name": "shellcode",
                "offsets": {
                    "shell6": [
                        [
                            1003783,
                            0
                        ],
                        [
                            1005661,
                            0
                        ],
                        [
                            1007797,
                            0
                        ],
                        [
                            1008530,
                            0
                        ],
                        [
                            1008933,
                            0
                        ],
                        [
                            1009434,
                            0
                        ],
                        [
                            1010563,
                            0
                        ],
                        [
                            1012241,
                            0
                        ],
                        [
                            1013388,
                            0
                        ],
                        [
                            1015028,
                            0
                        ],
                        [
                            1016404,
                            0
                        ],
                        [
                            1017874,
                            0
                        ],
                        [
                            1022228,
                            0
                        ],
                        [
                            1047221,
                            0
                        ],
                        [
                            1049099,
                            0
                        ],
                        [
                            1051235,
                            0
                        ],
                        [
                            1051968,
                            0
                        ],
                        [
                            1052371,
                            0
                        ],
                        [
                            1052872,
                            0
                        ],
                        [
                            1054001,
                            0
                        ],
                        [
                            1055679,
                            0
                        ],
                        [
                            1056826,
                            0
                        ],
                        [
                            1058466,
                            0
                        ],
                        [
                            1059472,
                            0
                        ],
                        [
                            1065145,
                            0
                        ],
                        [
                            1067023,
                            0
                        ],
                        [
                            1069159,
                            0
                        ],
                        [
                            1069892,
                            0
                        ],
                        [
                            1070295,
                            0
                        ],
                        [
                            1070796,
                            0
                        ],
                        [
                            1071925,
                            0
                        ],
                        [
                            1073603,
                            0
                        ],
                        [
                            1074750,
                            0
                        ],
                        [
                            1076390,
                            0
                        ],
                        [
                            1077766,
                            0
                        ],
                        [
                            1079236,
                            0
                        ],
                        [
                            1083590,
                            0
                        ],
                        [
                            1106923,
                            0
                        ],
                        [
                            1108070,
                            0
                        ],
                        [
                            1109710,
                            0
                        ],
                        [
                            1111086,
                            0
                        ],
                        [
                            1112556,
                            0
                        ],
                        [
                            1116910,
                            0
                        ],
                        [
                            1141903,
                            0
                        ],
                        [
                            1143781,
                            0
                        ],
                        [
                            1145917,
                            0
                        ],
                        [
                            1146650,
                            0
                        ],
                        [
                            1147053,
                            0
                        ],
                        [
                            1147554,
                            0
                        ],
                        [
                            1148683,
                            0
                        ],
                        [
                            1150361,
                            0
                        ],
                        [
                            1151508,
                            0
                        ],
                        [
                            1153148,
                            0
                        ],
                        [
                            1154524,
                            0
                        ],
                        [
                            1155994,
                            0
                        ],
                        [
                            1160348,
                            0
                        ],
                        [
                            1185341,
                            0
                        ],
                        [
                            1187219,
                            0
                        ],
                        [
                            1189355,
                            0
                        ],
                        [
                            1190088,
                            0
                        ],
                        [
                            1190491,
                            0
                        ],
                        [
                            1190992,
                            0
                        ],
                        [
                            1192121,
                            0
                        ],
                        [
                            1193799,
                            0
                        ],
                        [
                            1194946,
                            0
                        ],
                        [
                            1196586,
                            0
                        ],
                        [
                            1197962,
                            0
                        ],
                        [
                            1199432,
                            0
                        ],
                        [
                            1203786,
                            0
                        ],
                        [
                            1229165,
                            0
                        ],
                        [
                            1231043,
                            0
                        ],
                        [
                            1233179,
                            0
                        ],
                        [
                            1233912,
                            0
                        ],
                        [
                            1234315,
                            0
                        ],
                        [
                            1234816,
                            0
                        ],
                        [
                            1235945,
                            0
                        ],
                        [
                            1237623,
                            0
                        ],
                        [
                            1238770,
                            0
                        ],
                        [
                            1240410,
                            0
                        ],
                        [
                            1241786,
                            0
                        ],
                        [
                            1243256,
                            0
                        ],
                        [
                            1247610,
                            0
                        ],
                        [
                            1272217,
                            0
                        ],
                        [
                            1274095,
                            0
                        ],
                        [
                            1276231,
                            0
                        ],
                        [
                            1276964,
                            0
                        ],
                        [
                            1277367,
                            0
                        ],
                        [
                            1277868,
                            0
                        ],
                        [
                            1278997,
                            0
                        ],
                        [
                            1280675,
                            0
                        ],
                        [
                            1281822,
                            0
                        ],
                        [
                            1283462,
                            0
                        ],
                        [
                            1284838,
                            0
                        ],
                        [
                            1286308,
                            0
                        ],
                        [
                            1290662,
                            0
                        ],
                        [
                            1317257,
                            0
                        ],
                        [
                            1319135,
                            0
                        ],
                        [
                            1321271,
                            0
                        ],
                        [
                            1322004,
                            0
                        ],
                        [
                            1322407,
                            0
                        ],
                        [
                            1322908,
                            0
                        ],
                        [
                            1324037,
                            0
                        ],
                        [
                            1325715,
                            0
                        ],
                        [
                            1326862,
                            0
                        ],
                        [
                            1328502,
                            0
                        ],
                        [
                            1329878,
                            0
                        ],
                        [
                            1331348,
                            0
                        ],
                        [
                            1335702,
                            0
                        ],
                        [
                            1362297,
                            0
                        ],
                        [
                            1364175,
                            0
                        ],
                        [
                            1366311,
                            0
                        ],
                        [
                            1367044,
                            0
                        ],
                        [
                            1367447,
                            0
                        ],
                        [
                            1367948,
                            0
                        ],
                        [
                            1369077,
                            0
                        ],
                        [
                            1370755,
                            0
                        ],
                        [
                            1371902,
                            0
                        ],
                        [
                            1373542,
                            0
                        ],
                        [
                            1374918,
                            0
                        ],
                        [
                            1376388,
                            0
                        ],
                        [
                            1380742,
                            0
                        ],
                        [
                            1413257,
                            0
                        ],
                        [
                            1415135,
                            0
                        ],
                        [
                            1417271,
                            0
                        ],
                        [
                            1418004,
                            0
                        ],
                        [
                            1418407,
                            0
                        ],
                        [
                            1418908,
                            0
                        ],
                        [
                            1420037,
                            0
                        ],
                        [
                            1421715,
                            0
                        ],
                        [
                            1422862,
                            0
                        ],
                        [
                            1424502,
                            0
                        ],
                        [
                            1425878,
                            0
                        ],
                        [
                            1427348,
                            0
                        ],
                        [
                            1431702,
                            0
                        ],
                        [
                            1464217,
                            0
                        ],
                        [
                            1466095,
                            0
                        ],
                        [
                            1468231,
                            0
                        ],
                        [
                            1468964,
                            0
                        ],
                        [
                            1469367,
                            0
                        ],
                        [
                            1469868,
                            0
                        ],
                        [
                            1470997,
                            0
                        ],
                        [
                            1472675,
                            0
                        ],
                        [
                            1473822,
                            0
                        ],
                        [
                            1475462,
                            0
                        ],
                        [
                            1476838,
                            0
                        ],
                        [
                            1478308,
                            0
                        ],
                        [
                            1482662,
                            0
                        ],
                        [
                            1515177,
                            0
                        ],
                        [
                            1517055,
                            0
                        ],
                        [
                            1519191,
                            0
                        ],
                        [
                            1519924,
                            0
                        ],
                        [
                            1520327,
                            0
                        ],
                        [
                            1520828,
                            0
                        ],
                        [
                            1521957,
                            0
                        ],
                        [
                            1523635,
                            0
                        ],
                        [
                            1524782,
                            0
                        ],
                        [
                            1526422,
                            0
                        ],
                        [
                            1527798,
                            0
                        ],
                        [
                            1529268,
                            0
                        ],
                        [
                            1533622,
                            0
                        ],
                        [
                            1560217,
                            0
                        ],
                        [
                            1562095,
                            0
                        ],
                        [
                            1564231,
                            0
                        ],
                        [
                            1564964,
                            0
                        ],
                        [
                            1565367,
                            0
                        ],
                        [
                            1565868,
                            0
                        ],
                        [
                            1566997,
                            0
                        ],
                        [
                            1568675,
                            0
                        ],
                        [
                            1569822,
                            0
                        ],
                        [
                            1571462,
                            0
                        ],
                        [
                            1572838,
                            0
                        ],
                        [
                            1574308,
                            0
                        ],
                        [
                            1578662,
                            0
                        ],
                        [
                            1605257,
                            0
                        ],
                        [
                            1607135,
                            0
                        ],
                        [
                            1609271,
                            0
                        ],
                        [
                            1610004,
                            0
                        ],
                        [
                            1610407,
                            0
                        ],
                        [
                            1610908,
                            0
                        ],
                        [
                            1612037,
                            0
                        ],
                        [
                            1613715,
                            0
                        ],
                        [
                            1614862,
                            0
                        ],
                        [
                            1616502,
                            0
                        ],
                        [
                            1617878,
                            0
                        ],
                        [
                            1619348,
                            0
                        ],
                        [
                            1623702,
                            0
                        ],
                        [
                            1656217,
                            0
                        ],
                        [
                            1658095,
                            0
                        ],
                        [
                            1660231,
                            0
                        ],
                        [
                            1660964,
                            0
                        ],
                        [
                            1661367,
                            0
                        ],
                        [
                            1661868,
                            0
                        ],
                        [
                            1662997,
                            0
                        ],
                        [
                            1664675,
                            0
                        ],
                        [
                            1665822,
                            0
                        ],
                        [
                            1667462,
                            0
                        ],
                        [
                            1668838,
                            0
                        ],
                        [
                            1670308,
                            0
                        ],
                        [
                            1674662,
                            0
                        ],
                        [
                            1707177,
                            0
                        ],
                        [
                            1709055,
                            0
                        ],
                        [
                            1711191,
                            0
                        ],
                        [
                            1711924,
                            0
                        ],
                        [
                            1712327,
                            0
                        ],
                        [
                            1712828,
                            0
                        ],
                        [
                            1713957,
                            0
                        ],
                        [
                            1715635,
                            0
                        ],
                        [
                            1716782,
                            0
                        ],
                        [
                            1718422,
                            0
                        ],
                        [
                            1719798,
                            0
                        ],
                        [
                            1721268,
                            0
                        ],
                        [
                            1725622,
                            0
                        ]
                    ]
                },
                "strings": [
                    "VYvsgew="
                ]
            }
        ],
        "sha1": "8e6f7e7574e45fbfc5a63ee000f6f21b4bff9581",
        "name": "6e3470b8b18982cb_hook.dll",
        "filepath": "c:\\program files (x86)\\trojan guarder\\hook.dll",
        "type": "data",
        "sha256": "6e3470b8b18982cb35e05b915d75cea91cb95aa5c3ecfe14350951d968f89520",
        "urls": [],
        "crc32": "234BA377",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/6e3470b8b18982cb_hook.dll",
        "ssdeep": null,
        "size": 1753814,
        "sha512": "740701f8564056488f527a8f4e9f582cf5691491aeebb2c3b03cd924c1f3d4e70965dd77ad5e6a59ce2e2340fc6cdece762087aaf303c369a61d7274f853cff8",
        "pids": [
            1480
        ],
        "md5": "1770c40bd59c2f71dc09b33fd17d8238"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "397893091ecbf0d2ca4c2dcc302f07ce821e2746",
        "name": "36a3cfcb8fb9e099_trojan guarder.lnk",
        "filepath": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Mon Jan 21 10:30:01 2008, mtime=Sun Apr 19 14:53:19 2020, atime=Mon Jan 21 10:30:01 2008, length=247808, window=hide",
        "sha256": "36a3cfcb8fb9e09976b06b919ee1d911231b79be0d8e6d9f3804e24dcf0f792c",
        "urls": [],
        "crc32": "1BC676A9",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/36a3cfcb8fb9e099_trojan guarder.lnk",
        "ssdeep": null,
        "size": 1021,
        "sha512": "f35cf1af6a5ea497a60e732ae2344d7ee612b73eb270c4e9677102d51b957690cadd9ff87da3c7aabe62602507406b93b6dfd97ca3ed132a586760ffdc851f5e",
        "pids": [
            1480
        ],
        "md5": "157429d021534083cb716e31a693b279"
    },
    {
        "yara": [],
        "sha1": "d58eed3ad3f2ee7aba7d258bd92c72a0ac4b0b31",
        "name": "1a6b1dbd11e79fe8_unins000.dat",
        "filepath": "C:\\Program Files (x86)\\Trojan Guarder\\unins000.dat",
        "type": "data",
        "sha256": "1a6b1dbd11e79fe8497cce8d5ecafb55323e27ba83656d5d9e5add2e7cea2ca5",
        "urls": [],
        "crc32": "75A2A479",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/1a6b1dbd11e79fe8_unins000.dat",
        "ssdeep": null,
        "size": 2700,
        "sha512": "93ead1e6efa0462ad31a62a07f96a00217550e9f1775e39feea3e7181a8ec393548bf1de049ae2673bc64c8aee980baf2fe1c3a5922ae11d1bf470d7e43e370b",
        "pids": [
            1480
        ],
        "md5": "b557b765ec141c1c8b2b7b80df1af186"
    },
    {
        "yara": [],
        "sha1": "ac2384c4adcfcee1c68569103a0c01d15b0bf3d9",
        "name": "151413c5042b841c_contact.exe",
        "filepath": "c:\\program files (x86)\\trojan guarder\\contact.exe",
        "type": "PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed",
        "sha256": "151413c5042b841c7a312215515f9a78ac85c794f7564ea6c3e7918487d55bbe",
        "urls": [],
        "crc32": "5B232E1B",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/151413c5042b841c_contact.exe",
        "ssdeep": null,
        "size": 38912,
        "sha512": "811f375912a5339b7cf07ed385b5d231e9bb3eeec22c43764ef805f0b7881d3f2299f8f8fc16a3c516faf385d4e77c7a51ea7ed45add3317a47c7a80e04b8c3e",
        "pids": [
            1480
        ],
        "md5": "1ba66f3e31b80d9e2804ea762ce92e32"
    },
    {
        "yara": [],
        "sha1": "33e1f0889fb15d26f8da5e7fe2cfe10d05ba5199",
        "name": "03bb6c107f3b7374_trojan guarder help.chm",
        "filepath": "c:\\program files (x86)\\trojan guarder\\trojan guarder help.chm",
        "type": "MS Windows HtmlHelp Data",
        "sha256": "03bb6c107f3b73740b8d4fb624f5b6abcd2bd1a4a6a437ff9cbd1498e60be94d",
        "urls": [],
        "crc32": "7D9EA8B5",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/03bb6c107f3b7374_trojan guarder help.chm",
        "ssdeep": null,
        "size": 160163,
        "sha512": "fde21a3e7e00dacb9c54c93540fcd106ff654433ca360e2afa7e6960d6f06725386a412ef40291de02cd686147172d574150f3605a1324687d72a0d0201ac0d2",
        "pids": [
            1480
        ],
        "md5": "7d95bfd3733d8c10a0eaba3e896c58fc"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "7a1e76482984569fdb3487738947e2ff9793db70",
        "name": "f3b4013930300aba_visit our site.lnk",
        "filepath": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Sun Dec  8 02:31:42 2002, mtime=Sun Apr 19 14:53:19 2020, atime=Sun Dec  8 02:31:42 2002, length=126, window=hide",
        "sha256": "f3b4013930300aba9e5e3886b90e73be0f14c40085dc74a191cca4808f7133ce",
        "urls": [],
        "crc32": "D4B5ED79",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/f3b4013930300aba_visit our site.lnk",
        "ssdeep": null,
        "size": 1021,
        "sha512": "93d460465b5181ef82ffe23d6eee52e57524252b88c34214475d6e2f62b2bfa62fda1b5f437f52f464e465acbd98a75bd8ae75964671a9892e1c10b0688bfa6b",
        "pids": [
            1480
        ],
        "md5": "cdbb998f9412f302c121ea5ebe7d5271"
    },
    {
        "yara": [],
        "sha1": "15cbb0ace111c6d660101502dfebb9c524c1c508",
        "name": "c86a2fc5487bec94_visit our site.url",
        "filepath": "c:\\program files (x86)\\trojan guarder\\visit our site.url",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "c86a2fc5487bec944e651fed8a42a5bea7ac12febeab023142e2d1fbce422740",
        "urls": [
            "http:\/\/www.your-soft.com\/"
        ],
        "crc32": "1C558528",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/c86a2fc5487bec94_visit our site.url",
        "ssdeep": null,
        "size": 126,
        "sha512": "a9d818d8c7f087f75c2aa56bb3a6936f4dcf51d428ab1266c3d768666b218d6243c2d7221452a11367e0fd668e3c8aeac57cb152c11c80b90f09d80800813f60",
        "pids": [
            1480
        ],
        "md5": "46b7f2431d38cf078faa368fdadcfe10"
    },
    {
        "yara": [],
        "sha1": "af165edd876a5a1b3ee3954854df8a07a3bc7f87",
        "name": "bcdaaa6e3c67fea9_trojan.update",
        "filepath": "c:\\program files (x86)\\trojan guarder\\trojan.update",
        "type": "data",
        "sha256": "bcdaaa6e3c67fea909edb61c0d4bc1d00119f3063a4f20ee427c70addded0cda",
        "urls": [],
        "crc32": "FC14BBEC",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/bcdaaa6e3c67fea9_trojan.update",
        "ssdeep": null,
        "size": 30263,
        "sha512": "3f5e8312c650453126ba221778713c2fafd75fe97b66b7f8e514ed583e6dde960d7e3388fef7d069769bfe69f6ec4bcf18bd8847140ff0146863e686cdfed0a3",
        "pids": [
            1480
        ],
        "md5": "383fb5339eefff0c963cf9ac69c58dfd"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "cfa9d9c396a4c2580d456e891c1df70fe893f85b",
        "name": "12f71f0f0c8a37e2_uninstall.lnk",
        "filepath": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Dec 17 09:00:00 2002, mtime=Sun Apr 19 14:53:19 2020, atime=Tue Dec 17 09:00:00 2002, length=82253, window=hide",
        "sha256": "12f71f0f0c8a37e23c1b7caa151c9a42bdde37eabf6957abca8491278a1be0c1",
        "urls": [],
        "crc32": "4D7B5F6C",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/12f71f0f0c8a37e2_uninstall.lnk",
        "ssdeep": null,
        "size": 991,
        "sha512": "5a229e709deaf925c491bc7de3d50c2538c3b6bdfeb29ef6d76962f324eff7cdf94ab3269601e636346e370363d728103adf45e02dcf82d3573bd9b4cb9dc77f",
        "pids": [
            1480
        ],
        "md5": "ddb93c401d06f82332c31cba74f77325"
    },
    {
        "yara": [],
        "sha1": "3f03f28fcf6c9a26d1348c01a115d07b6b5f9f43",
        "name": "295046d4f32df2b7_trojan guarder.exe",
        "filepath": "c:\\program files (x86)\\trojan guarder\\trojan guarder.exe",
        "type": "PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed",
        "sha256": "295046d4f32df2b718d676e5f10f34dfc5225c875a4bd4a5efdc829a41a33ef3",
        "urls": [],
        "crc32": "8201D361",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/295046d4f32df2b7_trojan guarder.exe",
        "ssdeep": null,
        "size": 247808,
        "sha512": "f11440cea80f495eaa6922f383fdfeb1afaff2382ae72ffb85058adad99e7e966b2360f413adc338e6964cf1d55e834b4113095f6fd6e8f89467d222b8134d8e",
        "pids": [
            1480
        ],
        "md5": "318ed250c0430d0096b1474da009234f"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "ef9b20207cdf944e41aab8f85d90ce50cb48b868",
        "name": "6082cdf97c0fa7b0_trojan guarder.lnk",
        "filepath": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Mon Jan 21 10:30:01 2008, mtime=Sun Apr 19 14:53:19 2020, atime=Mon Jan 21 10:30:01 2008, length=247808, window=hide",
        "sha256": "6082cdf97c0fa7b0b1fc2fbb86690ef2b61f7c47bd32d4dd18072fb879d31a29",
        "urls": [],
        "crc32": "5354DCD6",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/6082cdf97c0fa7b0_trojan guarder.lnk",
        "ssdeep": null,
        "size": 1015,
        "sha512": "b22f9405055a4368d602b75f4480e92fdaa776be3199e14f656cde7ebace29a38dd5f7031aada77ccef0c105e26f7c9ed7140a9e81c82172874418bdb56c7275",
        "pids": [
            1480
        ],
        "md5": "e3f2640516304e15602bb12806262245"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "f46b0c0376c4c23865cf916ca43fdd0179283e51",
        "name": "4d4739216208c266_trojan guarder.lnk",
        "filepath": "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Mon Jan 21 10:30:01 2008, mtime=Sun Apr 19 14:53:19 2020, atime=Mon Jan 21 10:30:01 2008, length=247808, window=hide",
        "sha256": "4d4739216208c2664c2e40d3ec276aacf36455afaae1bd57bd25c8f934163bd5",
        "urls": [],
        "crc32": "3EE3C8AD",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/4d4739216208c266_trojan guarder.lnk",
        "ssdeep": null,
        "size": 1003,
        "sha512": "1ba91f062615aa7546ae2e905fa735538d64237d47e7891b0545df2dc98afada9dbead06db5e71007c63b9eba0f6b3b9028c8787fd7d43165e31b5076ecdd2fd",
        "pids": [
            1480
        ],
        "md5": "506838e5034fc1475cde891928d5d98e"
    },
    {
        "yara": [],
        "sha1": "e0893ab4863a3afb3789d75881bc393ffdd6dc41",
        "name": "baf192f3b18a50c5_products.htm",
        "filepath": "c:\\program files (x86)\\trojan guarder\\products.htm",
        "type": "HTML document, ISO-8859 text, with very long lines, with CRLF line terminators",
        "sha256": "baf192f3b18a50c5d1c3fcbc3072304f02175a276397d207d4311ef12b194a8c",
        "urls": [
            "http:\/\/www.download.com\/3000-2239-10165573.html",
            "http:\/\/yoursoft.ms11.net\/IconMaker.zip",
            "http:\/\/yoursoft.ms11.net\/Mp3Converter.exe",
            "https:\/\/www.qwerks.com\/order\/buynow.asp?ProductID=5222",
            "http:\/\/www.download.com\/3000-2239-10166958.html",
            "https:\/\/www.swreg.org\/cgi-bin\/currency-selector2.cgi?s=4802",
            "http:\/\/www.download.com\/Trojan-Guarder\/3000-2239_4-10327886.html",
            "http:\/\/www.your-soft.com",
            "http:\/\/yoursoft.ms11.net\/IEAssistant.exe"
        ],
        "crc32": "2E53FB94",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6953\/files\/baf192f3b18a50c5_products.htm",
        "ssdeep": null,
        "size": 11029,
        "sha512": "e0030ce6800e7c75b665303cda558d5c14b8ede502c3194846431935560dfc4d7381ac5ed17de4ff1c93bbdd7186260e80bf24b35f01445f7351f044b4d763c9",
        "pids": [
            1480
        ],
        "md5": "27bf38dc931861d51095dfcf5c1ce33c"
    }
]

Generic

[
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\INS5F2B.tmp",
        "process_name": "INS5F2B.tmp",
        "pid": 1480,
        "summary": {
            "file_created": [
                "C:\\Program Files (x86)\\Trojan Guarder\\is-B1FT8.tmp",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-8AJE8.tmp",
                "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-2FOAU.tmp",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-RFVGO.tmp",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-0QUMH.tmp",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp\\_shfoldr.dll",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
                "C:\\Program Files (x86)\\Trojan Guarder\\unins000.dat",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-00ORD.tmp",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-GNPSC.tmp",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-KM98T.tmp",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk"
            ],
            "file_recreated": [
                "C:\\Program Files (x86)\\Trojan Guarder\\unins000.dat"
            ],
            "directory_created": [
                "C:\\Program Files (x86)\\Trojan Guarder",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches",
                "C:\\Users\\cuck\\Desktop",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp"
            ],
            "dll_loaded": [
                "C:\\Windows\\system32\\ntshrui.dll",
                "netutils.dll",
                "apphelp.dll",
                "LINKINFO.dll",
                "kernel32.dll",
                "UxTheme.dll",
                "C:\\Windows\\system32\\ole32.dll",
                "dwmapi.dll",
                "ntmarta.dll",
                "PROPSYS.dll",
                "C:\\Windows\\syswow64\\MSCTF.dll",
                "OLEAUT32.DLL",
                "C:\\Windows\\system32\\EhStorShell.dll",
                "comctl32",
                "ole32.dll",
                "SHLWAPI.dll",
                "USER32.dll",
                "IMM32.dll",
                "API-MS-Win-Security-SDDL-L1-1-0.dll",
                "WindowsCodecs.dll",
                "shfolder.dll",
                "OLEAUT32.dll",
                "profapi.dll",
                "SHELL32.dll",
                "comctl32.dll",
                "shell32.dll",
                "ADVAPI32.dll",
                "SETUPAPI.dll",
                "ntshrui.dll"
            ],
            "file_opened": [
                "C:\\Windows\\System32\\imageres.dll",
                "C:\\Windows\\AppPatch\\sysmain.sdb",
                "C:\\",
                "C:\\Windows\\System32\\",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-2FOAU.tmp",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db",
                "C:\\Users\\cuck\\AppData\\Local\\Temp",
                "C:\\Windows\\System32\\en-US\\ntshrui.dll.mui",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
                "C:\\Windows\\System32\\EhStorShell.dll",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-00ORD.tmp",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-GNPSC.tmp",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-KM98T.tmp",
                "C:\\Windows\\System32",
                "c:\\Windows\\System32\\imageres.dll",
                "C:\\Program Files (x86)\\Trojan Guarder\\Trojan Guarder.exe",
                "C:\\Windows\\System32\\en-US\\EhStorShell.dll.mui",
                "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
                "C:\\Program Files (x86)\\Trojan Guarder\\Visit Our Site.url",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp\\_shfoldr.dll",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-B1FT8.tmp",
                "C:\\Users\\cuck\\Desktop\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\b0fdc934c7f8c994633e99b9dcee1ccc70e222ee36e38082ad16d23b982a5b47.bin",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-RFVGO.tmp",
                "C:\\Program Files (x86)\\Trojan Guarder",
                "C:\\Program Files (x86)",
                "C:\\Program Files (x86)\\Trojan Guarder\\unins000.exe",
                "C:\\Program Files (x86)\\Trojan Guarder\\Trojan Guarder Help.chm",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-8AJE8.tmp",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk",
                "C:\\Windows\\System32\\ntshrui.dll",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
                "C:\\Program Files (x86)\\Trojan Guarder\\",
                "c:\\",
                "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-0QUMH.tmp",
                "C:\\Program Files (x86)\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk"
            ],
            "regkey_opened": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\ShellEx\\IconHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\ShellEx\\IconHandler",
                "HKEY_CLASSES_ROOT\\Directory",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CLASSES_ROOT\\SystemFileAssociations\\.url",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\Clsid",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\Clsid",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\Folder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\IconHandler",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Icons",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1",
                "HKEY_CLASSES_ROOT\\SystemFileAssociations\\.chm",
                "HKEY_CLASSES_ROOT\\SystemFileAssociations\\.exe",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\ShellEx\\IconHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\Explorer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\Clsid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\CurVer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\Explorer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.chm",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\INS5F2B.tmp",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\BrowseInPlace",
                "HKEY_CLASSES_ROOT\\CLSID\\{FBF23B40-E3F0-101B-8488-00AA003E56F8}\\Implemented Categories\\{00021490-0000-0000-C000-000000000046}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\Clsid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\DocObject",
                "HKEY_CLASSES_ROOT\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\CurVer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\BrowseInPlace",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\Directory",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\Clsid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PropertyBag",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PropertyBag",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\INS5F2B.tmp",
                "HKEY_CLASSES_ROOT\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InProcServer32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}",
                "HKEY_CLASSES_ROOT\\InternetShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\ShellIconOverlayIdentifiers\\SharingPrivate",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.url\\OpenWithProgids",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\INS5F2B.tmp",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\DriveIcons\\C\\DefaultIcon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1\\KnownFolders",
                "HKEY_CLASSES_ROOT\\.exe\\OpenWithProgids",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}",
                "HKEY_CLASSES_ROOT\\.chm\\OpenWithProgids",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Shell\\RegisteredApplications\\UrlAssociations\\Directory\\OpenWithProgids",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\.url\\OpenWithProgids",
                "HKEY_CLASSES_ROOT\\chm.file",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\CurVer",
                "HKEY_CLASSES_ROOT\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked",
                "HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance\\Disabled",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\ShellEx\\IconHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\Clsid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\Clsid",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\CurVer",
                "HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LDAP",
                "HKEY_CLASSES_ROOT\\exefile",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\ShellEx\\IconHandler",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Applications\\INS5F2B.tmp",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\ShellEx\\IconHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
                "HKEY_CLASSES_ROOT\\Applications\\Explorer.exe\\Drives\\C\\DefaultIcon",
                "HKEY_CLASSES_ROOT\\.url",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\OpenWithProgids",
                "HKEY_CLASSES_ROOT\\.exe",
                "HKEY_CLASSES_ROOT\\AllFilesystemObjects",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.url",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PropertyBag",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\UserChoice",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.chm\\OpenWithProgids",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
                "HKEY_CLASSES_ROOT\\.chm",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
            ],
            "command_line": [
                "\"C:\\Program Files (x86)\\Trojan Guarder\\Trojan Guarder.exe\""
            ],
            "file_written": [
                "C:\\Program Files (x86)\\Trojan Guarder\\is-B1FT8.tmp",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-8AJE8.tmp",
                "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-2FOAU.tmp",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-RFVGO.tmp",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-0QUMH.tmp",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp\\_shfoldr.dll",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
                "C:\\Program Files (x86)\\Trojan Guarder\\unins000.dat",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-00ORD.tmp",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-GNPSC.tmp",
                "C:\\Program Files (x86)\\Trojan Guarder\\is-KM98T.tmp",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk"
            ],
            "directory_removed": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp"
            ],
            "file_failed": [
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.pif",
                "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.pif",
                "C:\\Users\\cuck\\Desktop\\Trojan Guarder.pif",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.pif",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.pif",
                "C:\\Program Files (x86)\\Trojan Guarder",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.pif",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.pif",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk"
            ],
            "guid": [
                "{08244ee6-92f0-47f2-9fc9-929baa2e7235}",
                "{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
                "{000214f9-0000-0000-c000-000000000046}",
                "{00021401-0000-0000-c000-000000000046}",
                "{76765b11-3f95-4af2-ac9d-ea55d8994f1a}",
                "{d9144dcd-e998-4eca-ab6a-dcd83ccba16d}",
                "{00000000-0000-0000-c000-000000000046}",
                "{000214ee-0000-0000-c000-000000000046}",
                "{0c6c4200-c589-11d0-999a-00c04fd655e1}",
                "{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}"
            ],
            "file_read": [
                "C:\\Windows\\System32\\ntshrui.dll",
                "C:\\Users\\cuck\\Desktop\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\b0fdc934c7f8c994633e99b9dcee1ccc70e222ee36e38082ad16d23b982a5b47.bin",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
                "C:\\Windows\\System32\\EhStorShell.dll",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
                "C:\\Program Files (x86)\\desktop.ini",
                "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.URL\\Content Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PreCreate",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Favorites",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Stream",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PublishExpandedPath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\Content Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\FolderTypeID",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PublishExpandedPath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\CommonFilesDir",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Attributes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParentFolder",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\LoadWithoutCOM",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParentFolder",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Personal",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResourceType",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.URL\\PerceivedType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\RegisteredOwner",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PreCreate",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\RelativePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SeparateProcess",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\ProfilesDirectory",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoWebView",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Pictures",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Name",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Description",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{374DE290-123F-4565-9164-39C4925E467B}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonVideo",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.chm\\PerceivedType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Attributes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Music",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\RelativePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Video",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonMusic",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalRedirectOnly",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Desktop",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.URL\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.chm\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Desktop",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Security",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\ShellEx\\IconHandler\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NormalizeLinkNetPidls",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\Max Cached Icons",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Security",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\ProgramFilesDir",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InfoTip",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{56784854-C6CB-462B-8169-88E350ACB882}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalRedirectOnly",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Roamable",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalRedirectOnly",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DontShowSuperHidden",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\RegisteredOrganization",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetCrawling",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 6",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Attributes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\CLSID\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\TurnOffSPIAnimations",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Category",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonPictures",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\IsShortcut",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResourceType",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Cache",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalizedName",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PreCreate",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\NeverShowExt",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\PendingFileRenameOperations",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClassicShell",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\System.NamespaceCLSID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\LoadWithoutCOM",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\Public",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Documents",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Security",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSimpleStartMenu",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.chm\\Content Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Category"
            ],
            "directory_enumerated": [
                "C:\\Windows\\System32\\ntshrui.dll",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp\\*",
                "C:\\Windows\\System32\\*.*",
                "C:\\Users\\cuck\\AppData",
                "C:\\Program Files (x86)\\Trojan Guarder\\unins???.*",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\*",
                "C:\\Users\\cuck\\Desktop",
                "C:\\Users\\cuck\\AppData\\Local\\Temp",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs",
                "C:\\Users\\cuck",
                "C:\\Program Files (x86)",
                "C:\\Program Files (x86)\\*.*",
                "C:\\Windows",
                "C:\\Users",
                "C:\\ProgramData\\Microsoft\\Windows",
                "C:\\*.*",
                "C:\\Users\\cuck\\AppData\\Local",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\is-OO559.tmp\\_shfoldr.dll",
                "C:\\Windows\\System32"
            ],
            "regkey_written": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1\\Inno Setup: Icon Group",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1\\DisplayName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1\\DisplayIcon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1\\Inno Setup: App Path",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1\\UninstallString",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1\\Inno Setup: User",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1\\Inno Setup: Setup Version"
            ]
        },
        "first_seen": 1587318789.655375,
        "ppid": 1512
    },
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\b0fdc934c7f8c994633e99b9dcee1ccc70e222ee36e38082ad16d23b982a5b47.bin",
        "process_name": "b0fdc934c7f8c994633e99b9dcee1ccc70e222ee36e38082ad16d23b982a5b47.bin",
        "pid": 1512,
        "summary": {
            "file_created": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\INS5F2B.tmp"
            ],
            "file_recreated": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\INS5F2B.tmp"
            ],
            "file_opened": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\INS5F2B.tmp",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\b0fdc934c7f8c994633e99b9dcee1ccc70e222ee36e38082ad16d23b982a5b47.bin"
            ],
            "command_line": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\INS5F2B.tmp \/SL3 $40260 C:\\Users\\cuck\\AppData\\Local\\Temp\\b0fdc934c7f8c994633e99b9dcee1ccc70e222ee36e38082ad16d23b982a5b47.bin 1909330 1912744 61952 "
            ],
            "file_written": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\INS5F2B.tmp"
            ],
            "file_read": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\b0fdc934c7f8c994633e99b9dcee1ccc70e222ee36e38082ad16d23b982a5b47.bin"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles"
            ],
            "directory_enumerated": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\INS5F2B.tmp",
                "C:\\Users\\cuck\\AppData",
                "C:\\Users\\cuck\\AppData\\Local\\Temp",
                "C:\\Users\\cuck",
                "C:\\Users",
                "C:\\Users\\cuck\\AppData\\Local"
            ]
        },
        "first_seen": 1587318787.578125,
        "ppid": 2892
    },
    {
        "process_path": "C:\\Windows\\System32\\lsass.exe",
        "process_name": "lsass.exe",
        "pid": 476,
        "summary": {},
        "first_seen": 1587318787.3125,
        "ppid": 376
    },
    {
        "process_path": "C:\\Windows\\explorer.exe",
        "process_name": "explorer.exe",
        "pid": 1788,
        "summary": {
            "directory_created": [
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer"
            ],
            "file_opened": [
                "C:\\Users\\cuck\\Pictures\\desktop.ini",
                "c:\\program files (x86)\\trojan guarder\\trojan guarder.exe",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories",
                "C:\\ProgramData",
                "C:\\",
                "C:\\Users\\cuck\\AppData",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC",
                "C:\\Users\\cuck\\Desktop",
                "C:\\Users\\Public\\Desktop",
                "C:\\ProgramData\\Microsoft",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
                "C:\\Users\\Public\\Desktop\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC\\Desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\desktop.ini",
                "C:\\Windows\\AppPatch\\sysmain.sdb",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance",
                "C:\\Users",
                "C:\\Program Files (x86)\\Trojan Guarder\\Trojan Guarder.exe",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
                "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Videos.library-ms",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\Desktop.ini",
                "C:\\Users\\cuck\\Desktop\\",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Documents.library-ms",
                "C:\\Users\\Public",
                "C:\\Users\\cuck\\AppData\\Roaming",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_96.db",
                "C:\\Users\\cuck\\Desktop\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_1024.db",
                "C:\\Users\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer",
                "C:\\Program Files (x86)\\Trojan Guarder",
                "C:\\Users\\cuck",
                "C:\\Windows\\Media\\Windows Navigation Start.wav",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
                "C:\\ProgramData\\Microsoft\\Windows",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_256.db",
                "C:\\Users\\cuck\\",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_sr.db",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility\\Desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Pictures.library-ms",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_idx.db",
                "C:\\Program Files (x86)\\Trojan Guarder\\",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Python 2.7",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games\\desktop.ini",
                "C:\\Users\\Public\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Music.library-ms",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Network Shortcuts",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools\\Desktop.ini",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db",
                "C:\\Program Files (x86)\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools"
            ],
            "regkey_opened": [
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F05C8358C56DAD54BB81D0A11DD52F41",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D0CBB37A94C46943A90AC5008CF1CC9",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0F4DC93AAA8AD1D448BC4E6A207F4FE0",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\895805CC90C04694887EF6BD140A622D",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\BE0BD5097A638224EB0DAAE870267F03",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B06071FE021ECB04E8B3BF1E39AD5BB3",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CDBF699A8F2EAC2438564C3D50E9E638",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B5C8B2FB95B57147954C18085D53ACE",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8020CF43278B2644190F51544810251E",
                "HKEY_CLASSES_ROOT\\Outlook.Application.12",
                "HKEY_CLASSES_ROOT\\Outlook.Application.11",
                "HKEY_CLASSES_ROOT\\Outlook.Application.10",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0EF52818FCE3E7B488427C1F8266654E",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\669C9DC1419C0F240B35B36B99AAB50C",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows Search",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1E82F31DC0D05AA4CB291B7BAA23FC8E",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FBEAAA6C37E8AF24B87AAEA0047433BD",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\103857F24A2EDA54A800A41FA570861F",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D3541DFF9B79C584284E8981624C04CB",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F356843B045CC0A4BA0D83C1D85AAAFD",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A7E9995902A24964C9C5D461E1C86F19",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\87C48B95924E3294FBC1766C9225DD0C",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E85E64F0A7FC58E47A87E5AB98A6F2DD",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\958C4A0DE6C8D5C428C6E9D875BC33B6",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4486F7CE8F022FB4EB0154C5226C27A0",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B1D5EA6004F809D48B117CE563261011",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\33AB3CD4D27277545B5A93CD4ECB96B4",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E429E5BC27530F4786481EC687D9EC9",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FE547D6F0D72534A80F89C4AB727618",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AE5A0040C41ACA642AF6DB16F4D2F638",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0411990C889EE9B47BB0B5D356564877",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\2FA90A429E82313489DAA2E2C2F0872C",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\75B368B60C908BA4E87C31F66B02F3F0",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B04950B5EC5C924B8F428B5484A2720",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89DF671CDA74E9D4EB10275B10D5CF3F",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CB2182A03B6B11341A1F09A021991CE1",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\62293D511DB84E5489074C5AFA18E882",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9D22CD4619F5DBC499A083AAD70FE7B3",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FF9FDEA72CD9DDC47A6DAB85F9F76B81",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7BF7ABF4D25C03F4582D4BC3082FB208",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E40FDF839772BEB41AC977860DBB4853",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CE5B971A0DBB8FD4F83AE0DADC348104",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CF65AB832507EDB4BB357F9D8E0431BD",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\63B1AF366905AF641BA514CCBAE803C4",
                "HKEY_LOCAL_MACHINE\\Software\\Classes\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8691BCC36FF121849A90B085BFAF5E5E",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F591EF48DE97A00428A5BC1AFFFAA868",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-699399860-4089948139-3198924279-1001\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\285499F23409ED14FB4A01230F5DFA91",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9BA984AD4F03E284382FFBB7A68BEE27",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE19F224928A59468049F045950CB08",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84C584688CFC74A4E9D36E5EE2E02FA7",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9F5ED6B416EF0A1448D94799D0FF20BA",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FEB01D34D0F67E4F9CD810B432C1B91",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4514EC211C8947C4B9BA24F353AFFD50",
                "HKEY_LOCAL_MACHINE\\Software\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE462B32EFD81040A184ED17E00452B",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7814D91294731FF4DBBB840810BEB3BB",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\67C12EF40671B7342A2F990919031A57",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B4BBDDC88CEE4DD439E8BB261CE222A8",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\296744B7EBFEB2741A47781AE6E32269",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\92F9143E715DEF045A539256438E41FB",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\040E2A370D6DB2F45AE45A0032BC2179",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B690B72A999998C47B5F93C94A8D43B2",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\30FAECE2400494D4FB69207288EB5B73",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\16AC40BE991DF1643B2800729063B2F9",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7C0477DE66D1A6749864FCE02A6DCB6C",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D5FD8239A83FE564F97379EA15CE8CB6",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\04C56B5D827A9194FA2CBFD014EAD0DA",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4626147D107665540A84D43A5908E74D",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A558E619ABC4CE5479C1DA5070EFBF81",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18D84E9490A485948A17A1F02CDAA62A",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\315C767EFC72D8445B1D2D16F72653F0",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\11E2BA15171FE704B98E7505E58D7749",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D38A6F5FC8262149A9FAAE8C621EE3F",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8ECC347096FA78C4E8291F449F71E16E",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FE056816E41FD2F4CACD03E7A2CA2E6E",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ThumbnailCache",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89BBBC8A0D32B014696C4BA3C20CDD34",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9DD74C0626DC33C479C1929714AB5295",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95E2C34402A93A14FA8CB3420B85375C",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\53F08364FFD17F14B8FD7CA7F52FAE76",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C1EF68F348457B246A0AD0C18B3079AF",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E116C831A95AB5B4787CE3086FE83631",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\863CA21BBA4DFCE489FDF96EAB898616",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A0256FF64030E0746A4AA95D3FFD0BE4",
                "HKEY_CLASSES_ROOT\\Outlook.Application",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D04063BE69797D4D8505462827A0D19",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FFFA6DF7EA9EDFC45A1F02FE6DF8F067",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\73964AA699D5B5140ADC41ED3F7DB38A",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9753E3A35E3BDFB468DF95B5D19C8A04",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-699399860-4089948139-3198924279-1001\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D725CB8E57307E64EB574E04214D8B5F",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1C1ED53B8F25FD248955C15232E46886",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1A0857155A8EF604FA5D1648CF382DC7",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18F5DB38C45303843B06B1B5025E4820",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3D197E722531D614AB40C182904D9A31",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AD21E12039BB3BC47B1938BC4ABDFEE2",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\034A8F8E06031EF46BCB4C10469098E5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C4040CC509FB0DC4886F590DDF6B6132",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84BBAC70FB00B6046881B55CB3122F0F",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F21868A51A175874BB819DCA5FAA40A3",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0A191B45599EEB74CA305184EA3C2A94",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3C68656E520593A45925ADFB41F821B5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\90860AAA7BD3DE34EB32330DD29CAD62",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\002F6EFFA8A0A40498F3035BD153685A",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F41A458014D57E54E8DBD0B0CBC361A2",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9E40FDB6330EBA242A4BD5F4FDD0B803",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E3DAE67887931944BCD7171908FA775",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\965742E8F65116F4BB2CB01341464FA7",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\717591555BCB1604BA9777E8A55D0E41",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\335F6F64CD461D9469519574D34757EB",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\17E23EF6C775D324DB90E0E2B7D1CA72",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0FD387D006FD9734FA65B249F36DE42A",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95EE473833000D6409127D1B85882AC9",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\EEF8AA9EB45B5DB4BBE46B8634C910CD",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7636A94AA21EDBB48B6AFFB17E5907B8"
            ],
            "file_exists": [
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
                "C:\\Users\\cuck\\Desktop",
                "C:\\Python27\\pythonw.exe",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
                "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
                "C:\\Program Files (x86)\\Trojan Guarder\\Trojan Guarder.exe",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries",
                "C:\\Program Files (x86)\\Trojan Guarder\\Visit Our Site.url",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Videos.library-ms",
                "C:\\Python27\\python.exe",
                "C:\\cuckoo_1788.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Documents.library-ms",
                "C:\\Users",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Pictures.library-ms",
                "C:\\Program Files (x86)\\Trojan Guarder",
                "C:\\Program Files (x86)",
                "C:\\Program Files (x86)\\Trojan Guarder\\unins000.exe",
                "C:\\Program Files (x86)\\Trojan Guarder\\Trojan Guarder Help.chm",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\ThumbCacheToDelete",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu",
                "C:\\Users\\Public\\Desktop",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\Music.library-ms",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
                "C:\\cuckoo_1504.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk"
            ],
            "mutex": [
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwReaderRefs",
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer",
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer",
                "Local\\Shell.CMruPidlList",
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer",
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer",
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit",
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer",
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex"
            ],
            "file_failed": [
                "C:\\cuckoo_1504.ini",
                "C:\\cuckoo_1788.ini",
                "C:\\ProgramData\\Microsoft\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db"
            ],
            "guid": [
                "{fdada2fa-894d-47d8-ae78-adf1fd7f28df}",
                "{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}",
                "{1c1800c1-3258-44c2-be80-3deadb6c5e39}",
                "{688c934d-0c26-40f6-8d29-d56d72c76b48}",
                "{c0a6c367-c264-4385-a704-9088bdc3640e}",
                "{b2952b16-0e07-4e5a-b993-58c52cb94cae}",
                "{660b90c8-73a9-4b58-8cae-355b7f55341b}",
                "{00000003-0000-0000-c000-000000000046}",
                "{add8ba80-002b-11d0-8f0f-00c04fd7d062}",
                "{00000320-0000-0000-c000-000000000046}",
                "{42aedc87-2188-41fd-b9a3-0c966feabec1}",
                "{00000000-0000-0000-c000-000000000046}",
                "{00000146-0000-0000-c000-000000000046}",
                "{cef04fdf-fe72-11d2-87a5-00c04f6837cf}",
                "{76765b11-3f95-4af2-ac9d-ea55d8994f1a}",
                "{75121952-e0d0-43e5-9380-1d80483acf72}",
                "{6746c347-576b-4f73-9012-cdfeea251bc4}",
                "{d5f569d0-593b-101a-b569-08002b2dbf7a}",
                "{fe841493-835c-4fa3-b6cc-b4b2d4719848}",
                "{000214e6-0000-0000-c000-000000000046}",
                "{2fb499a3-cfce-480f-a5f3-2453db7a2b7a}",
                "{00000323-0000-0000-c000-000000000046}",
                "{6e682784-1eca-4cf2-988d-96b6e89e9a4d}",
                "{9113a02d-00a3-46b9-bc5f-9c04daddd5d7}",
                "{a1567595-4c2f-4574-a6fa-ecef917b9a40}",
                "{ab8902b4-09ca-4bb6-b78d-a8f59079a8d5}",
                "{cd773740-b187-4974-a1d5-e0ff91372277}",
                "{09b224bd-1335-4631-a7ff-cfd3a92646d7}",
                "{f676c15d-596a-4ce2-8234-33996f445db1}",
                "{896664f7-12e1-490f-8782-c0835afd98fc}",
                "{30a99515-1527-4451-af9f-00c5f0234daf}",
                "{35786d3c-b075-49b9-88dd-029876e11c01}",
                "{46a6eeff-908e-4dc6-92a6-64be9177b41c}",
                "{54410b83-6787-4418-9735-5aaaabe83a9a}",
                "{f02c1a0d-be21-4350-88b0-7367fc96ef3c}",
                "{50ef4544-ac9f-4a8e-b21b-8a26180db13f}",
                "{edb5f444-cb8d-445a-a523-ec5ab6ea33c7}",
                "{0af10cec-2ecd-4b92-9581-34f6ae0637f3}"
            ],
            "file_read": [
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\desktop.ini",
                "C:\\Windows\\Media\\Windows Navigation Start.wav",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
                "C:\\Users\\Public\\Desktop\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC\\Desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
                "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\desktop.ini",
                "C:\\Program Files (x86)\\Trojan Guarder\\Trojan Guarder.exe",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\desktop.ini",
                "C:\\Users\\cuck\\Desktop\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\desktop.ini",
                "C:\\Users\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility\\Desktop.ini",
                "C:\\Users\\cuck\\Pictures\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\Desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk",
                "C:\\Program Files (x86)\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games\\desktop.ini",
                "C:\\Users\\Public\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools\\Desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0A191B45599EEB74CA305184EA3C2A94\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\P:\\Hfref\\phpx\\Qrfxgbc\\Gebwna Thneqre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\DefaultIcon\\OpenIcon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\67C12EF40671B7342A2F990919031A57\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\90860AAA7BD3DE34EB32330DD29CAD62\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\rhqprqvg.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Erzbgr Qrfxgbc Pbaarpgvba.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.VagreargRkcybere.Qrsnhyg",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\HideDesktopIcons\\NewStartPanel\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CF65AB832507EDB4BB357F9D8E0431BD\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E85E64F0A7FC58E47A87E5AB98A6F2DD\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D04063BE69797D4D8505462827A0D19\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\2\\0",
                "HKEY_CURRENT_USER\\AppEvents\\Schemes\\Apps\\Explorer\\Navigating\\.Current\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\FuncrPbyyrpgbe.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3D197E722531D614AB40C182904D9A31\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Jvaqbjf Sverjnyy jvgu Nqinaprq Frphevgl.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Znvagranapr\\Erzbgr Nffvfgnapr.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\DefaultIcon\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zntavsl.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{NN198O3P-PQ8P-7QR1-98Q1-O460S637193O}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersLibraries\\NameSpace\\DelegateFolders\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\System.HideOnDesktop",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\QIQ Znxre\\QIQZnxre.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\LocalizedString",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{15067OP1-P5N8-425R-37P6-SN0O891674S9}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\863CA21BBA4DFCE489FDF96EAB898616\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1E82F31DC0D05AA4CB291B7BAA23FC8E\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B4BBDDC88CEE4DD439E8BB261CE222A8\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0411990C889EE9B47BB0B5D356564877\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\InProcServer32\\LoadWithoutCOM",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D3541DFF9B79C584284E8981624C04CB\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\FavoritesRemovedChanges",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Zngu Vachg Cnary.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy VFR.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\FavoritesChanges",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\285499F23409ED14FB4A01230F5DFA91\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\System.DateModified",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{53123611-QN37-S8QN-SNP9-03R76QO9Q64Q}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7BF7ABF4D25C03F4582D4BC3082FB208\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A7E9995902A24964C9C5D461E1C86F19\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\bfx.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8691BCC36FF121849A90B085BFAF5E5E\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy (k86).yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Snk naq Fpna.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FE056816E41FD2F4CACD03E7A2CA2E6E\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{450D8FBA-AD25-11D0-98A8-0800361B1103}\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.TrggvatFgnegrq",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\FavccvatGbby.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\{5D76B67F-9B3D-44BB-B6AE-25DA4F638A67} 2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\\SortOrderIndex",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Gnfx Fpurqhyre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 13",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\qsethv.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 14",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\ArgjbexCebwrpgvba.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\103857F24A2EDA54A800A41FA570861F\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{P1P6S8NP-40N3-0S5P-146S-65N9QP70OOO4}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\DefaultIcon\\OpenIcon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AE5A0040C41ACA642AF6DB16F4D2F638\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\freivprf.zfp",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\FavoritesRemovedChanges",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\StartMenu_Balloon_Time",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\UseInProcHandlerCache",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95E2C34402A93A14FA8CB3420B85375C\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84BBAC70FB00B6046881B55CB3122F0F\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{35786D3C-B075-49B9-88DD-029876E11C01}\\InProcServer32\\LoadWithoutCOM",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.VagreargRkcybere.64Ovg",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\IconSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FF9FDEA72CD9DDC47A6DAB85F9F76B81\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\\System.HideOnDesktop",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Pnyphyngbe.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Search\\CurrentVersion",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Qvfx Pyrnahc.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\296744B7EBFEB2741A47781AE6E32269\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.FgvpxlAbgrf",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ZrqvnCynlre32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.URL\\PerceivedType",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Jvaqbjf Rkcybere.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\HideDesktopIcons\\NewStartPanel\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetHood",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.chm\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\62293D511DB84E5489074C5AFA18E882\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{89D83576-6BD1-4c86-9454-BEB04E94C819}\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7636A94AA21EDBB48B6AFFB17E5907B8\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{98D99750-0B8A-4c59-9151-589053683D73}\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Jvaqbjf Rkcybere.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8ECC347096FA78C4E8291F449F71E16E\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\\JvaqbjfCbjreFuryy\\i1.0\\CbjreFuryy_VFR.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Jvaqbjf CbjreFuryy Zbqhyrf.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{OQ3S924R-55SO-N1ON-9QR6-O50S9S2460NP}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{26EE0668-A00A-44D7-9371-BEB064C98683}\\System.IsPinnedToNameSpaceTree",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E429E5BC27530F4786481EC687D9EC9\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9BA984AD4F03E284382FFBB7A68BEE27\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\System.IsPinnedToNameSpaceTree",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89DF671CDA74E9D4EB10275B10D5CF3F\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfcnvag.rkr",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\28\\Shell\\TV_TopViewVersion",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\Jvaqbjf Wbheany.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A558E619ABC4CE5479C1DA5070EFBF81\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\System.FileAttributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{04731B67-D933-450A-90E6-4ACD2E9408FE}\\SortOrderIndex",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pnyp.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy VFR (k86).yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\_LabelFromReg",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Znvagranapr\\Perngr Erpbirel Qvfp.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\895805CC90C04694887EF6BD140A622D\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfen.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\System.IsPinnedToNameSpaceTree",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\\rkcybere.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\MMDevices\\Audio\\Render\\{c8ce7349-e519-42ea-bfb7-698f1844ee25}\\DeviceState",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lnk\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Jvaqbjf Zrqvn Cynlre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89BBBC8A0D32B014696C4BA3C20CDD34\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\{5D76B67F-9B3D-44BB-B6AE-25DA4F638A67} 2",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Nalgvzr Hctenqr.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4626147D107665540A84D43A5908E74D\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features\\DefaultFeature",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Fvqrone.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_MinMFU",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\\SortOrderIndex",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4486F7CE8F022FB4EB0154C5226C27A0\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Vagrearg Rkcybere.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\qsethv.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F05C8358C56DAD54BB81D0A11DD52F41\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\\SortOrderIndex",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zboflap.rkr",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\SNTSearch.dll,-505",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9D22CD4619F5DBC499A083AAD70FE7B3\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9DD74C0626DC33C479C1929714AB5295\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_TrackProgs",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\FbhaqErpbeqre.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\DefaultIcon\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\002F6EFFA8A0A40498F3035BD153685A\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\SortOrderIndex",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\DefaultIcon\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\efgehv.rkr",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\NetworkExplorer.dll,-1",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\{5D76B67F-9B3D-44BB-B6AE-25DA4F638A67} 2",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\2\\0\\NodeSlot",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\717591555BCB1604BA9777E8A55D0E41\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\vFPFV Vavgvngbe.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\bqopnq32.rkr",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\displayswitch.exe,-320",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_MinMFU",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9753E3A35E3BDFB468DF95B5D19C8A04\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\R7PS176R110P211O",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\System.HideOnDesktop",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{896664F7-12E1-490F-8782-C0835AFD98FC}\\InProcServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\LocalizedString",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{Q4N262QQ-PR44-Q105-S36O-9Q77N8PO65N4}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5\\DefaultFeature",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE462B32EFD81040A184ED17E00452B\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\SortOrderIndex",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\System.IsPinnedToNameSpaceTree",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{98D99750-0B8A-4C59-9151-589053683D73}\\SortOrderIndex",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3C68656E520593A45925ADFB41F821B5\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersLibraries\\NameSpace\\DelegateFolders\\{896664F7-12E1-490f-8782-C0835AFD98FC}\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\2\\MRUListEx",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\KCF Ivrjre.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Vagrearg Rkcybere.yax",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Zrqvn Cynlre.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jbeqcnq.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4514EC211C8947C4B9BA24F353AFFD50\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\2\\0\\MRUListEx",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{26EE0668-A00A-44D7-9371-BEB064C98683}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8020CF43278B2644190F51544810251E\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Zrqvn Pragre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\HideDesktopIcons\\NewStartPanel\\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A0256FF64030E0746A4AA95D3FFD0BE4\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C4040CC509FB0DC4886F590DDF6B6132\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{11016101-E366-4D22-BC06-4ADA335C892B}\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{e345f35f-9397-435c-8f95-4e922c26259e}\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{26EE0668-A00A-44D7-9371-BEB064C98683}\\System.HideOnDesktop",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfCbjreFuryy\\i1.0\\cbjrefuryy.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0EF52818FCE3E7B488427C1F8266654E\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\HideDesktopIcons\\NewStartPanel\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7C0477DE66D1A6749864FCE02A6DCB6C\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{35786D3C-B075-49b9-88DD-029876E11C01}\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{645FF040-5081-101B-9F08-00AA002F954E}\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0F4DC93AAA8AD1D448BC4E6A207F4FE0\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\LogicalViewMode",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\erpqvfp.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\HomeGroup\\UIStatusCache\\UIStatus",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\P:\\Clguba27\\clguba.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\EnableShareDenyNone",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D725CB8E57307E64EB574E04214D8B5F\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 14",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Punenpgre Znc.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CE5B971A0DBB8FD4F83AE0DADC348104\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.URL\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\InProcServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\System.HideOnDesktop",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\{5D76B67F-9B3D-44BB-B6AE-25DA4F638A67} 2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.chm\\PerceivedType",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Rirag Ivrjre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\GnoGvc.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\FavoritesRemovedChanges",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\\SortOrderIndex",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\\InProcServer32\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Sversbk.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Qngn Fbheprf (BQOP).yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\315C767EFC72D8445B1D2D16F72653F0\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{7SR8Q22N-SO1Q-N8OR-01R3-6P8693961R6R}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 6",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\FuncrPbyyrpgbe.rkr",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\mstsc.exe,-4000",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{89D83576-6BD1-4C86-9454-BEB04E94C819}\\SortOrderIndex",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\958C4A0DE6C8D5C428C6E9D875BC33B6\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\Clguba (pbzznaq yvar).yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\DefaultIcon\\OpenIcon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\System.HideOnDesktop",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jrypbzr Pragre.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\DefaultIcon\\OpenIcon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\lnkfile\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{26EE0668-A00A-44D7-9371-BEB064C98683}\\{5D76B67F-9B3D-44BB-B6AE-25DA4F638A67} 2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\28\\Shell\\TV_TopViewID",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\ColInfo",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1A0857155A8EF604FA5D1648CF382DC7\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\System.IsPinnedToNameSpaceTree",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\{5D76B67F-9B3D-44BB-B6AE-25DA4F638A67} 2",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Sversbk.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Pbzcbarag Freivprf.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JS.zfp",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\17E23EF6C775D324DB90E0E2B7D1CA72\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\GnoGvc.rkr",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\FXSRESM.dll,-114",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\System.HideOnDesktop",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfNalgvzrHctenqrHV.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\DefaultIcon\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_NotifyNewApps",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\63B1AF366905AF641BA514CCBAE803C4\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B06071FE021ECB04E8B3BF1E39AD5BB3\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flap Pragre.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C} {000214E6-0000-0000-C000-000000000046} 0xFFFF",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Flfgrz Gbbyf\\Cevingr Punenpgre Rqvgbe.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{9343812e-1c37-4a49-a12e-4b2d810d956b}\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Vagrearg Rkcybere (64-ovg).yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\NeverShowExt",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Fgvpxl Abgrf.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JSF.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\040E2A370D6DB2F45AE45A0032BC2179\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\{5D76B67F-9B3D-44BB-B6AE-25DA4F638A67} 2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B04950B5EC5C924B8F428B5484A2720\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pzq.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E40FDF839772BEB41AC977860DBB4853\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Cnvag.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Npprffvovyvgl\\Fcrrpu Erpbtavgvba.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\VQYR (Clguba THV).yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\ArgCebw.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FBEAAA6C37E8AF24B87AAEA0047433BD\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{daf95313-e44d-46af-be1b-cbacea2c3065}\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Abgrcnq.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\\Gebwna Thneqre\\Gebwna Thneqre.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84C584688CFC74A4E9D36E5EE2E02FA7\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\DisableProcessIsolation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\System.IsPinnedToNameSpaceTree",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\LocalizedString",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Cresbeznapr Zbavgbe.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\HideDesktopIcons\\NewStartPanel\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\53F08364FFD17F14B8FD7CA7F52FAE76\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\DocObject",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\cevagznantrzrag.zfp",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ErzbgrQrfxgbc",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\FFlags",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Fbhaq Erpbeqre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{896664F7-12E1-490F-8782-C0835AFD98FC}\\InProcServer32\\LoadWithoutCOM",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Gebwna Thneqre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{450D8FBA-AD25-11D0-98A8-0800361B1103}\\SortOrderIndex",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\AlwaysShowExt",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_TrackProgs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\ShellEx\\IconHandler\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Jvaqbjf Rnfl Genafsre Ercbegf.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\\DefaultIcon\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_LargeMFUIcons",
                "HKEY_CURRENT_USER\\AppEvents\\Schemes\\Apps\\Explorer\\Navigating\\.Current\\Default Flags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9F5ED6B416EF0A1448D94799D0FF20BA\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Flfgrz Pbasvthengvba.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\04C56B5D827A9194FA2CBFD014EAD0DA\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\puneznc.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{E345F35F-9397-435C-8F95-4E922C26259E}\\SortOrderIndex",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\abgrcnq.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\qvfcynlfjvgpu.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\034A8F8E06031EF46BCB4C10469098E5\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\NoOplock",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Favccvat Gbby.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\CLSID\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{P804OON7-SN5S-POS7-8O55-2096R5S972PO}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zvtjvm\\cbfgzvt.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Cevag Znantrzrag.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Flfgrz Erfgber.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Gebwna Thneqre\\Gebwna Thneqre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F356843B045CC0A4BA0D83C1D85AAAFD\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\System.NamespaceCLSID",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Zntavsl.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C1EF68F348457B246A0AD0C18B3079AF\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lnk\\ShellEx\\{BB2E617C-0920-11D1-9A0B-00C04FC2D6C1}\\(Default)",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\Mode",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Jvaqbjf Wbheany\\Wbheany.rkr",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\SnippingTool.exe,-15051",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\FavoritesChanges",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F591EF48DE97A00428A5BC1AFFFAA868\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE19F224928A59468049F045950CB08\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\669C9DC1419C0F240B35B36B99AAB50C\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\kcfepuij.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\2FA90A429E82313489DAA2E2C2F0872C\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Pbzznaq Cebzcg.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\aneengbe.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\IsShortcut",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{8NN47365-O2O3-1961-69RO-S866R376O12S}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\87C48B95924E3294FBC1766C9225DD0C\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\92F9143E715DEF045A539256438E41FB\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\Zbqhyr Qbpf.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ZrqvnPragre",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Gnfx Fpurqhyre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B1D5EA6004F809D48B117CE563261011\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\LocalizedString",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\335F6F64CD461D9469519574D34757EB\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\\JvaqbjfCbjreFuryy\\i1.0\\cbjrefuryy.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Cache",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfvasb32.rkr",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU Size",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F41A458014D57E54E8DBD0B0CBC361A2\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\zvc.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{11016101-E366-4D22-BC06-4ADA335C892B}\\SortOrderIndex",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\ZqFpurq.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{8NOQ94SO-R7Q6-84N6-N997-P918RQQR0NR5}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Frphevgl Pbasvthengvba Znantrzrag.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7814D91294731FF4DBBB840810BEB3BB\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\OobeFldr.dll,-33056",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\\InProcServer32\\LoadWithoutCOM",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FE547D6F0D72534A80F89C4AB727618\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{QNN168QR-4306-P8OP-8P11-O596240OQQRQ}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_LargeMFUIcons",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\33AB3CD4D27277545B5A93CD4ECB96B4\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{35786D3C-B075-49B9-88DD-029876E11C01}\\InProcServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.URL\\Content Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B690B72A999998C47B5F93C94A8D43B2\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\HideDesktopIcons\\NewStartPanel\\{645FF040-5081-101B-9F08-00AA002F954E}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\SortOrderIndex",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\28\\Shell\\TV_FolderType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersLibraries\\NameSpace\\DelegateFolders\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D0CBB37A94C46943A90AC5008CF1CC9\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E3DAE67887931944BCD7171908FA775\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D5FD8239A83FE564F97379EA15CE8CB6\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfCbjreFuryy\\i1.0\\CbjreFuryy_VFR.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Aneengbe.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\System.HideOnDesktop",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\HomeGroup\\UIStatusCache\\OnlyMember",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\chm.file\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\HideDesktopIcons\\NewStartPanel\\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\System.DateModified",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Jvaqbjf AG\\Npprffbevrf\\jbeqcnq.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0FD387D006FD9734FA65B249F36DE42A\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{OO044OSQ-25O7-2SNN-22N8-6371N93R0456}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E116C831A95AB5B4787CE3086FE83631\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FFFA6DF7EA9EDFC45A1F02FE6DF8F067\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D38A6F5FC8262149A9FAAE8C621EE3F\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\1",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\0",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{9343812E-1C37-4A49-A12E-4B2D810D956B}\\SortOrderIndex",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5\\TclTk",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95EE473833000D6409127D1B85882AC9\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features\\TclTk",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\LocalizedString",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Zbovyvgl Pragre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{31E4FA78-02B4-419F-9430-7B7585237C77}\\ProxyStubClsid32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\965742E8F65116F4BB2CB01341464FA7\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{645FF040-5081-101B-9F08-00AA002F954E}\\DefaultIcon\\OpenIcon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\73964AA699D5B5140ADC41ED3F7DB38A\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pyrnazte.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\\SortOrderIndex",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\StartMenu_Balloon_Time",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_NotifyNewApps",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Ba-Fperra Xrlobneq.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\freivprf.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Pbzchgre Znantrzrag.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\qvfcynlfjvgpu.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\EEF8AA9EB45B5DB4BBE46B8634C910CD\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Jvaqbjf Rnfl Genafsre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AD21E12039BB3BC47B1938BC4ABDFEE2\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{04731B67-D933-450a-90E6-4ACD2E9408FE}\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18F5DB38C45303843B06B1B5025E4820\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\BE0BD5097A638224EB0DAAE870267F03\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\\SortOrderIndex",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\\SortOrderIndex",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\InternetShortcut\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CDBF699A8F2EAC2438564C3D50E9E638\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\\System.IsPinnedToNameSpaceTree",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Zrzbel Qvntabfgvpf Gbby.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\vfpfvpcy.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9E40FDB6330EBA242A4BD5F4FDD0B803\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace\\{26EE0668-A00A-44D7-9371-BEB064C98683}\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Flfgrz Vasbezngvba.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\UseOutOfProcHandlerCache",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\16AC40BE991DF1643B2800729063B2F9\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1C1ED53B8F25FD248955C15232E46886\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zvtjvm\\zvtjvm.rkr",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\WindowsAnytimeUpgradeUI.exe,-1",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\30FAECE2400494D4FB69207288EB5B73\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfpbasvt.rkr",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\Sort",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf QIQ Znxre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CB2182A03B6B11341A1F09A021991CE1\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F21868A51A175874BB819DCA5FAA40A3\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.chm\\Content Type",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\XpsRchVw.exe,-102",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B5C8B2FB95B57147954C18085D53ACE\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FEB01D34D0F67E4F9CD810B432C1B91\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18D84E9490A485948A17A1F02CDAA62A\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\11E2BA15171FE704B98E7505E58D7749\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Erfbhepr Zbavgbe.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\AppEvents\\Schemes\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\75B368B60C908BA4E87C31F66B02F3F0\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pbzrkc.zfp"
            ],
            "regkey_written": [
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\Rev",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\28\\Shell\\TV_TopViewID",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\ColInfo",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\Mode",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\Sort",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\LanguageList",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts\\C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\LogicalViewMode",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\28\\Shell\\TV_FolderType",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\HRZR_PGYFRFFVBA",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\\Gebwna Thneqre\\Gebwna Thneqre.rkr",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\FFlags",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\28\\Shell\\TV_TopViewVersion",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\ProgramsCache",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\IconSize",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell\\{0B2BAAEB-0042-4DCA-AA4D-3EE8648D03E5}\\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}\\Vid"
            ]
        },
        "first_seen": 1587318800.3585,
        "ppid": 1740
    },
    {
        "process_path": "C:\\Program Files (x86)\\Trojan Guarder\\Trojan Guarder.exe",
        "process_name": "Trojan Guarder.exe",
        "pid": 1504,
        "summary": {
            "file_created": [
                "C:\\Program Files (x86)\\Trojan Guarder\\TG5.42.dll"
            ],
            "regkey_written": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ett\\Extension\\{223bd3fe-345e-ffae-3c9f-fe62375679e1}\\Cache",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\notepad.exe\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ett\\Extension\\{223bd3fe-345e-ffae-3c9f-fe62375679e1}\\Services"
            ],
            "dll_loaded": [
                "OLEAUT32.DLL",
                "comdlg32.dll",
                "C:\\Windows\\system32\\odbcint.dll",
                "kernel32",
                "C:\\Windows\\syswow64\\MSCTF.dll",
                "SHELL32.dll",
                "MSVCRT.DLL",
                "user32",
                "WSOCK32.dll",
                "C:\\Windows\\system32\\ole32.dll",
                "dwmapi.dll",
                "MFC42.DLL",
                "ole32.dll",
                "COMCTL32.DLL",
                "WS2_32.dll",
                "COMCTL32.dll",
                "imm32.dll"
            ],
            "file_opened": [
                "C:\\Windows\\win.ini",
                "C:\\Windows",
                "C:\\",
                "C:\\Program Files (x86)\\Trojan Guarder\\TG5.42.dll"
            ],
            "regkey_opened": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Disk",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PeerDistSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ACPI\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UI0Detect\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Psched\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\agp440",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\circlass\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPNP\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinHttpAutoProxySvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SamSs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdbss",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DcomLaunch\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fvevol\\Parameters",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Disk\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KSecPkg",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adpahci\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Brserid",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\idsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srvnet\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrUsbMdm",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SamSs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PNRPsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Npfs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIP6\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pci\\Parameters",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSPCLOCK\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Netlogon\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Mup\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wcncsvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetTcpPortSharing\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AudioEndpointBuilder\\Parameters",
                "HKEY_USERS\\.DEFAULT\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\Setup\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Modem\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\p2pimsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\gagp30kx\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ebdrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PortProxy\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FileInfo\\",
                "HKEY_CLASSES_ROOT\\batfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adpu320\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HdAudAddService\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FDResPub\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EFS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wercplsupport",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adpu320",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nv_agp\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HomeGroupListener",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mouhid\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\blbdrive\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hwpolicy",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WwanSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ws2ifsl",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AudioSrv",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\cmdfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hidserv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PlugPlay\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adp94xx\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PEAUTH\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dmvsc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iScsiPrt\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbhub\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Lsa",
                "HKEY_CURRENT_USER\\Control Panel\\Desktop",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WfpLwf\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TsUsbGD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BTHMODEM",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volsnap\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\isapnp\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ldap",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET Data Provider for Oracle\\",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Appinfo",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ehRecvr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\storvsc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSDTC",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\atapi",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\storflt\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ProtectedStorage",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisCap\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffdisk\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ohci1394\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdide\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UxSms\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\E1G60\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wscsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\QWAVE\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vwifibus\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppIDSvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adpu320\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nfrd960\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MsRPC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IKEEXT\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adp94xx\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BITS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPDR\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PNRPAutoReg",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Null\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WfpLwf\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TapiSrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppMgmt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IpFilterDriver\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Brserid\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdxata",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fvevol",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AcpiPmi\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SMSvcHost 3.0.0.0",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb20\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wmiApSrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WdiSystemHost\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\arc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HomeGroupProvider\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CNG\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wd\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\intelppm",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adsi\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CertPropSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AxInstSV",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffp_mmc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LanmanServer\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CscService\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdyboost\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Browser\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SDRSVC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPENCDD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET Data Provider for SqlServer",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vmbus\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSSCNTRS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IKEEXT\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VMBusHID\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TSDDD\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\gpsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Netlogon\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WbioSrvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hwpolicy\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIP6",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msiserver",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\USBSTOR",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\uliagpkx",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Serenum\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cmdide\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cmdide",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinSock2",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdpbus\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TermService",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\agp440\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vsmraid\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcLocator\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Netlogon",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidUsb",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPWD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET CLR Networking\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TermDD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPENCDD\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MegaSR",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TapiSrv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wd\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffdisk",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppID",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\THREADORDER\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cdfs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSiSCSI\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_FC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CmBatt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ebdrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SessionEnv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdyboost\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lltdio\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Compbatt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CSC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msahci",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rspndr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrFiltUp\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KtmRm",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ohci1394\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\upnphost",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WPCSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Fax\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EapHost\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nv_agp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\QWAVEdrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IpFilterDriver\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AmdK8\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TDPIPE\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ohci1394",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Modem\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PptpMiniport",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fdc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisTapi\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SDRSVC\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\b57nd60a",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\clr_optimization_v2.0.50727_64\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crcdisk\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WcsPlugInService\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tcpipreg",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rspndr\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mpio",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSPCLOCK\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Mup\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSKSSRV\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mpsdrv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\i8042prt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AmdPPM\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\E1G60",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\udfs\\Parameters",
                "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PortProxy\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\kbdhid\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfOS\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Browser",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ql40xx",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Browser\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinDefend\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vmbus\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\bowser",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Rasl2tp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfProc\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\Trojan Guarder.exe",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AeLookupSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\StorSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\uagp35\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfDisk\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbhub",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CscService\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfNet\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CNG\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sppuinotify\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcSs\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AeLookupSvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wmiApSrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Power\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LanmanWorkstation",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\partmgr",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wanarpv6\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\monitor",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\upnphost\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbccgp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mountmgr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TrkWks\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetTcpPortSharing",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\USBSTOR\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ESENT\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BattC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbcir\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSTEE",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ehSched\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\spldr",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DPS\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mssmbios",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wscsvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\THREADORDER\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\storvsc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CertPropSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NETFramework\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mountmgr",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AcpiPmi",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Beep\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FileInfo",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lmhosts\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Spooler\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WSearch\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dot3svc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSDTC Bridge 3.0.0.0",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\COMSysApp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PNRPAutoReg\\Parameters",
                "HKEY_LOCAL_MACHINE\\Software\\Classes\\.ett\\Extension\\{223bd3fe-345e-ffae-3c9f-fe62375679e1}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Beep",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisWan\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_FC\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbprint\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adpahci",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WfpLwf",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\comfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\netprofm\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\batfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wbengine\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VSS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msahci\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iirsp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WMPNetworkSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CryptSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Themes\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pcmcia\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WSearchIdxPi",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPBusEnum",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iirsp\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TSDDD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mouclass\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCPolicySvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\umbus\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lmhosts\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\seclogon\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MTConfig",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\b06bdrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\isapnp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\p2psvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HomeGroupProvider",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SSDPSRV\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Serenum",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb10\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PlugPlay",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mouclass\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinSock2\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIPTUNNEL\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WdiServiceHost\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NDProxy",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IRENUM",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ESENT",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\bowser\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\intelide\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BDESVC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hcw85cir\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WMPNetworkSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\THREADORDER",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WacomPen\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\s3cap\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\{AEFD33F3-CC73-4821-AD44-6915063E7FB1}\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WdiServiceHost\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WdiSystemHost\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\spldr\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msahci\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NTDS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RemoteRegistry",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Parport",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mpsdrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SessionEnv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\arc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\USBSTOR\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCardSvr\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SNMPTRAP\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msiserver\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\idsvc",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Desktop\\General",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AudioEndpointBuilder",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iaStorV",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NativeWifiP",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WIMMount",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tssecsrv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffdisk\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cdfs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adp94xx",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tdx\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET CLR Data\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAuto\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WdiSystemHost",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FDResPub",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WacomPen",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DcomLaunch\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volsnap",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPNP\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\stexstor\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidIr",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Appinfo\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volmgr\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPMIDRV",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TrustedInstaller\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\seclogon",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\QWAVEdrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TermDD\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAuto",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volmgrx",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ShellHWDetection\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcSs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET CLR Networking\\",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\bthserv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\circlass\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidBth\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KSecDD\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Fax\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPCDD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Null\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\eventlog\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelOperation 3.0.0.0\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\s3cap",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WANARP\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\b57nd60a\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iirsp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ldap\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UI0Detect",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\gagp30kx\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET Data Provider for SqlServer\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Dnscache",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Mcx2Svc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSDTC\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NDIS\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BFE\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ksthunk\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdsata",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Ndisuio\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sppsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SessionEnv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasPppoe\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\bthserv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\atapi\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TDTCP\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidBth\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iScsiPrt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nsi\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SensrSvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSTEE\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DcomLaunch",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FontCache3.0.0.0",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Processor",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pla",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\arcsas",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Dnscache\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TDTCP\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vhdmp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BTHPORT\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\intelide\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAgileVpn",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PortProxy",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Processor\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ql2300",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mouhid\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCardSvr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LanmanServer\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ProfSvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\stisvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wuauserv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NDProxy\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PeerDistSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BFE\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdxata\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BFE",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HomeGroupListener\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIP6TUNNEL\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasMan\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSiSCSI\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mountmgr\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPDR",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msisadrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\defragsvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FsDepends",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPDD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb10\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ACPI",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelOperation 3.0.0.0",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Filetrace\\",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfOS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\netprofm\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nvstor",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NlaSvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WerSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIP6\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WmiApRpl\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lltdsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET Data Provider for Oracle",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbhub\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SCSI\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinDefend",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adsi",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MpsSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppID\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellExecuteHooks",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ProtectedStorage\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CSC\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MpsSvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelEndpoint 3.0.0.0\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sermouse\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tcpipreg\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\QWAVEdrv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mpio\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Modem",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KSecPkg\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Netman",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FltMgr",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidBatt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\kbdhid\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KeyIso",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcSs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidIr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NativeWifiP\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Schedule",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\flpydisk\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vdrvroot\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TBS\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lltdio\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ShellHWDetection\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wecsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TrustedInstaller\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wmiApSrv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pla\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PNRPsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\eventlog\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mpio\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSDTC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SiSRaid4\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Compbatt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\luafv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WcsPlugInService\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hkmsvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET Data Provider for SqlServer\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSPCLOCK",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Mup",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CompositeBus\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetBIOS\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\stisvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SNMPTRAP\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UxSms\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Spooler\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sbp2port\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Schedule\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AudioSrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasSstp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\StorSvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msdsm",
                "HKEY_CLASSES_ROOT\\cmdfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wlansvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinHttpAutoProxySvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NDProxy\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSPQM\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\idsvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\W32Time\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fdPHost",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MozillaMaintenance\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FsDepends\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPDD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KSecDD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ehRecvr",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SENS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PEAUTH\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\clr_optimization_v2.0.50727_64\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KSecPkg\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\b57nd60a\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TDPIPE",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pciide",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SstpSvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\umbus\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\xmlprov\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PNRPsvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SensrSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\megasas\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PcaSvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Processor\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\W3SVC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TermDD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CLFS\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\{EF381EA0-4D07-418D-A490-68AF67CE948B}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelService 3.0.0.0\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FDResPub\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrUsbSer",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Spooler",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nsiproxy\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adsi\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelOperation 3.0.0.0\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAcd",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vdrvroot\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ProtectedStorage\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srv2\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TrkWks\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Msfs\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdsbs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AxInstSV\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\p2pimsvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Npfs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\gagp30kx",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\kbdclass\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nvraid\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wudfsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PeerDistSvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tcpipreg\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winmgmt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Msfs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volmgrx\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fvevol\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WudfPf\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelService 3.0.0.0\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TsUsbFlt\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Dhcp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\secdrv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rspndr",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pcw\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET CLR Data",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Filetrace",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\intelppm\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tunnel\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sfloppy",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NDIS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iphlpsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WmiAcpi",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Disk\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbprint",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WSearchIdxPi\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CryptSvc\\",
                "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\uliagpkx\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vhdmp\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAgileVpn\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wcncsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventSystem\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfHost\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PcaSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srv2",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET CLR Networking",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\umbus",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UmPass\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\ODBC\\ODBC.INI\\ODBC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TrkWks",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidBatt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\clr_optimization_v2.0.50727_64",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbprint\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\swprv",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srv2\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\intelppm\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetBIOS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbehci\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RemoteRegistry\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Ntfs\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KtmRm\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fastfat\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UGatherer\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mssmbios\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\viaide\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Mcx2Svc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WIMMount\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\partmgr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BDESVC\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\swenum\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UGTHRSVC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WPDBusEnum",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffp_mmc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbcir\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\Setup\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\uagp35",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Serial\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfOS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CNG",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ProfSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdsbs\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vdrvroot",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vmbus",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DCLocator",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vsmraid\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\{EF381EA0-4D07-418D-A490-68AF67CE948B}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PEAUTH",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinHttpAutoProxySvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mshidkmdf\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidBatt\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WudfPf",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\piffile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wanarpv6\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\swenum",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AFD\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BITS\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ws2ifsl\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\atapi\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TBS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winmgmt\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vwifibus",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Beep\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TabletInputService\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NDIS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sfloppy\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SamSs\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IpFilterDriver",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbehci",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WPCSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vga\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ACPI\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sbp2port",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\E1G60\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SiSRaid2\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\megasas",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WIMMount\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nfrd960\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NTDS\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPWD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidUsb\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Parport\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\adpahci\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crcdisk\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Themes\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\{AEFD33F3-CC73-4821-AD44-6915063E7FB1}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IRENUM\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinRM\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppMgmt\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iphlpsvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HdAudAddService\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\blbdrive\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iphlpsvc",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\scfilter",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WdiServiceHost",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VaultSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CscService",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wudfsvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ehSched\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Power\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelService 3.0.0.0",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\isapnp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\intelide",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MegaSR\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IRENUM\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srvnet",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Npfs\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msisadrv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ksthunk",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FontCache3.0.0.0\\",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crcdisk",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\secdrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\W3SVC\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Serial",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WSearch",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pcmcia\\Parameters",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer\\run\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nvstor\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSKSSRV\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Rasl2tp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\storflt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AudioSrv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fastfat\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sppuinotify",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\eventlog",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SAS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\1394ohci\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ql2300\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dmvsc\\Parameters",
                "HKEY_CLASSES_ROOT\\*\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\i8042prt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HDAudBus\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Null",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Netman\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb10",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RemoteAccess\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BattC\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mssmbios\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdxata\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\defragsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPMIDRV\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\p2pimsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DfsC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\seclogon\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pcmcia",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WwanSvc\\",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\Setup\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\W32Time",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wuauserv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AmdPPM",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Themes",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisTapi\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BTHMODEM\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\drmkaud\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Psched\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CompositeBus",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbohci\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DXGKrnl",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TermService\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mouhid",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPREFMP\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCardSvr",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CertPropSvc\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DCLocator\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hidserv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FileInfo\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WmiApRpl\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ErrDev\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\s3cap\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\exfat",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPDR\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vds\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mouclass",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPENCDD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AsyncMac\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sppuinotify\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\scfilter\\",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPNAT",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\QWAVE\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vds\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UGatherer",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppIDSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MRxDAV\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfDisk",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hcw85cir",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FltMgr\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\StorSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCPolicySvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Dnscache\\Parameters",
                "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisWan",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dmvsc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\kbdclass",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Brserid\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\{EF381EA0-4D07-418D-A490-68AF67CE948B}\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FltMgr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WANARP",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SensrSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UmRdpService",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hkmsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DfsC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ALG",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdbss\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ehRecvr\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrSerWdm\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cdrom",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\flpydisk\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PptpMiniport\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CLFS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\agp440\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KSecDD\\Parameters",
                "HKEY_CURRENT_USER\\SoftWare\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidIr\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nv_agp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mpsdrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WMPNetworkSvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\p2psvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Fs_Rec\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\{AEFD33F3-CC73-4821-AD44-6915063E7FB1}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPBusEnum\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FontCache3.0.0.0\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AFD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffp_sd\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AcpiPmi\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WSearch\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSDTC Bridge 3.0.0.0\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\stisvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\aliide",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wanarpv6",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPNAT\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\i8042prt\\",
                "HKEY_CLASSES_ROOT\\Applications\\notepad.exe\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BattC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbuhci\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UGTHRSVC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\drmkaud",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\aliide\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetBT",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MsRPC",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidUsb\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CmBatt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPWD\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSKSSRV",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RemoteAccess\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VaultSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UxSms",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinDefend\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Ndisuio",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mshidkmdf",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TDPIPE\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPCDD\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MTConfig\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PolicyAgent\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fdc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\storflt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\elxstor",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppID\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HomeGroupListener\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcEptMapper",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSDTC Bridge 3.0.0.0\\Parameters",
                "HKEY_CLASSES_ROOT\\exefile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NativeWifiP\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SENS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wdf01000",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\arcsas\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventSystem",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbohci",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EFS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfNet\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msiserver\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hwpolicy\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cdfs\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TsUsbFlt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Ntfs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ErrDev",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfHost",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIPTUNNEL\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbuhci\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\arcsas\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SNMPTRAP",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Netman\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\secdrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WANARP\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HTTP",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EFS\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Lsa\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CompositeBus\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VgaSave\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wercplsupport\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasMan\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nsi\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FontCache\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPNAT\\",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AmdK8",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pci",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TDTCP",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\W3SVC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TSDDD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pcw",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UmRdpService\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AsyncMac",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PcaSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IKEEXT",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPREFMP\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIP6TUNNEL",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nsi",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MozillaMaintenance\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\elxstor\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MsRPC\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SAS2\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TBS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\megasas\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HpSAMD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vga",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AxInstSV\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WmiApRpl",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UGatherer\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wdf01000\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nfrd960",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HomeGroupProvider\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\inetaccs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinRM\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wudfsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volmgr",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\flpydisk",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nvraid",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PptpMiniport\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventSystem\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HTTP\\Parameters",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sbp2port\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSPQM",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WSearchIdxPi\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSTEE\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\monitor\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DfsC\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelEndpoint 3.0.0.0",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LanmanServer",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tdx\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AmdK8\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ql40xx\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Lsa\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SMSvcHost 3.0.0.0\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\swenum\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dot3svc\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\notepad.exe\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Smb\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sfloppy\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BTHPORT\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\srvnet\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbuhci",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\exfat\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VgaSave\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbccgp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VaultSvc\\",
                "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TapiSrv",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunServices\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdpbus",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SstpSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lltdsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrFiltLo\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\luafv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wdf01000\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VgaSave",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\spldr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RemoteAccess",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisCap",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DPS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\stexstor",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ws2ifsl\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Ntfs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\luafv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\xmlprov\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wercplsupport\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\bowser\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SstpSvc",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WacomPen\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MegaSR\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppMgmt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SAS2\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ErrDev\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pciide\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPNP",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\swprv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrUsbSer\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vds",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\regfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SiSRaid4\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdyboost",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ldap\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SiSRaid2\\",
                "HKEY_CURRENT_USER\\SOFTWARE\\ODBC\\ODBC.INI\\ODBC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb20",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\drmkaud\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\b06bdrv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wd",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WmiAcpi\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TsUsbGD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Rasl2tp\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET CLR Data\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lmhosts",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Parport\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MozillaMaintenance",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\xmlprov",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\kbdclass\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fdPHost\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fdPHost\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CLFS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WerSvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HDAudBus",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winmgmt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPREFMP",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrSerWdm\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\uagp35\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TrustedInstaller",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\1394ohci\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LanmanWorkstation\\Parameters",
                "HKEY_CLASSES_ROOT\\comfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Fax",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pla\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPCDD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Smb",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sermouse\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MRxDAV\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HidBth",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\kbdhid",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KeyIso\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ALG\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdsata\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffp_mmc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pcw\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fastfat",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPMIDRV\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasPppoe\\",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MMCSS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\circlass",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tunnel\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VSS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nvraid\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\gpsvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WPDBusEnum\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\storvsc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ql40xx\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSSCNTRS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volsnap\\Parameters",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbehci\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wlansvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TermService\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SAS",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\1394ohci",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AudioEndpointBuilder\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ALG\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iaStorV\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\netprofm",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\inetaccs\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EapHost\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\swprv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdsbs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\uliagpkx\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TabletInputService\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\udfs\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffp_sd\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volmgrx\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SAS2",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\clr_optimization_v2.0.50727_32",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisCap\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SysMain",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nsiproxy",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CSC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NETFramework\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DCLocator\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WebClient",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dot3svc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPBusEnum\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DPS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PolicyAgent\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcEptMapper\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdsata\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NET Data Provider for Oracle\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SENS\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SysMain\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SAS\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrFiltLo",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sppsvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAcd\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nvstor\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\partmgr\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vga\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Dhcp\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIP6TUNNEL\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VMBusHID\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdide\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\udfs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Serial\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msdsm\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\.NETFramework",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DXGKrnl\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hidserv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wlansvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinSock2\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iScsiPrt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbccgp\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MMCSS",
                "HKEY_CLASSES_ROOT\\piffile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAuto\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WmiAcpi\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tunnel",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CryptSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MRxDAV",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SDRSVC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UmPass\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Compbatt\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\clr_optimization_v2.0.50727_32\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tssecsrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfProc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSSCNTRS\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UGTHRSVC\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WebClient\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\BidInterface\\Loader",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrUsbMdm\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TCPIPTUNNEL",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Power",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SysMain\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ProfSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\exfat\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WebClient\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinRM",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wcncsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\clr_optimization_v2.0.50727_32\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VSS\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\System",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pciide\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wuauserv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tdx",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Mcx2Svc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\volmgr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\napagent\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Msfs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\viaide\\",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SMSvcHost 3.0.0.0\\Parameters",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetTcpPortSharing\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EapHost",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BTHPORT",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCPolicySvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SCSI\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wscsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfNet",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer\\run\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msdsm\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\arc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrFiltUp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\blbdrive",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FsDepends\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RDPDD\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sermouse",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSiSCSI",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\upnphost\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sffp_sd",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HdAudAddService",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Windows Workflow Foundation 3.0.0.0",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ksthunk\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WPDBusEnum\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Schedule\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cdrom\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\aliide\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\stexstor\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LanmanWorkstation\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NlaSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UmPass",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TsUsbFlt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdbss\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Fs_Rec\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasPppoe",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MTConfig\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisTapi",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vwifibus\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\scfilter\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\gpsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wbengine",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AmdPPM\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NdisWan\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Ndisuio\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TsUsbGD\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Windows Workflow Foundation 3.0.0.0\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasMan",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\rdpbus\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ShellHWDetection",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\discache\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AsyncMac\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FontCache",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lltdio",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\bthserv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AFD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\napagent",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cmdide\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbcir",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Serenum\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrUsbSer\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AppIDSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\defragsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrFiltUp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WudfPf\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NTDS\\Parameters",
                "HKEY_CLASSES_ROOT\\txtfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UI0Detect\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcLocator\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\FontCache\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WbioSrvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PolicyAgent",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetBT\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\QWAVE",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HpSAMD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasSstp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfProc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\lltdsvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\b06bdrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\pci\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_FC",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HpSAMD\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\discache\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\TabletInputService",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HTTP\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WbioSrvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcLocator",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WcsPlugInService",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SSDPSRV",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\fdc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Fs_Rec",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Windows Workflow Foundation 3.0.0.0\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LSI_SCSI",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wecsvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BITS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Psched",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\monitor\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RemoteRegistry\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ServiceModelEndpoint 3.0.0.0\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SiSRaid2",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\iaStorV\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SiSRaid4",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ESENT\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DXGKrnl\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\napagent\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WPCSvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfHost\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CmBatt\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\elxstor\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Filetrace\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\tssecsrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Dhcp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellExecuteHooks\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WwanSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\msisadrv\\Parameters",
                "HKEY_CLASSES_ROOT\\scrfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfDisk\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrUsbMdm\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vhdmp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\wbengine\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PNRPAutoReg\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mshidkmdf\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ql2300\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrSerWdm",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\inetaccs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\viaide",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\p2psvc\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RpcEptMapper\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Wecsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MMCSS\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Smb\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Appinfo\\Parameters",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\mrxsmb20\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NetBIOS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasSstp\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\COMSysApp\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cdrom\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\amdide",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NlaSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PlugPlay\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BDESVC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KtmRm\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\COMSysApp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\HDAudBus\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vsmraid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunServices",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hcw85cir\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\UmRdpService\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\sppsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WerSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\discache",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\hkmsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\nsiproxy\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAgileVpn\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SSDPSRV\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\AeLookupSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BrFiltLo\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VMBusHID",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\BTHMODEM\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\scrfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MpsSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\KeyIso\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ehSched",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\W32Time\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ebdrv\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\RasAcd\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\usbohci\\Parameters",
                "HKEY_CLASSES_ROOT\\regfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MSPQM\\Parameters"
            ],
            "file_written": [
                "C:\\Program Files (x86)\\Trojan Guarder\\TG5.42.dll"
            ],
            "file_failed": [
                "C:\\Program Files (x86)\\Trojan Guarder\\BlackList.txt",
                "C:\\Program Files (x86)\\Trojan Guarder\\WhiteList.txt",
                "C:\\Program Files (x86)\\Trojan Guarder\\TG5.42.dll"
            ],
            "file_read": [
                "C:\\Windows\\win.ini",
                "C:\\Program Files (x86)\\Trojan Guarder\\TG5.42.dll"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TSDDD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\ImagePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC Bridge 3.0.0.0\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UGatherer\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfDisk\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NETFramework\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ServiceModelOperation 3.0.0.0\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC Bridge 3.0.0.0\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPNP\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\\u5b8b\u4f53",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\piffile\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NTDS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiApRpl\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane7",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\shell",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UGatherer\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ServiceModelService 3.0.0.0\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6TUNNEL\\ImagePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\StubPath",
                "HKEY_CURRENT_USER\\Control Panel\\Desktop\\Wallpaper",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\regfile\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\{EF381EA0-4D07-418D-A490-68AF67CE948B}\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Start",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\inetaccs\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SMSvcHost 3.0.0.0\\ImagePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane10",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane12",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\ShellExecuteHooks\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane2",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ServiceModelEndpoint 3.0.0.0\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Icon",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for Oracle\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Networking\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UGTHRSVC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Windows Workflow Foundation 3.0.0.0\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfNet\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane11",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\ImagePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NETFramework\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Networking\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ServiceModelService 3.0.0.0\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane4",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane5",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\Start",
                "\\REGISTRY\\USER\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ett\\Extension\\{223bd3fe-345e-ffae-3c9f-fe62375679e1}\\Services",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearchIdxPi\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\xmlprov\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Windows Workflow Foundation 3.0.0.0\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHPORT\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIPTUNNEL\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BattC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfOS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for SqlServer\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\batfile\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\AppInit_DLLs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ett\\Extension\\{223bd3fe-345e-ffae-3c9f-fe62375679e1}\\Cache",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\ImagePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\load",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6TUNNEL\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\{AEFD33F3-CC73-4821-AD44-6915063E7FB1}\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearchIdxPi\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\ImagePath",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\ProgramFilesDir",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfDisk\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane14",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PortProxy\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for Oracle\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\cmdfile\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UGTHRSVC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfNet\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\ImagePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\run",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PortProxy\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane15",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Lsa\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adsi\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\ImagePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Parameters\\ServiceDll",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\AppInit_DLLs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BattC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ServiceModelEndpoint 3.0.0.0\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ESENT\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DCLocator\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfProc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Data\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\xmlprov\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fs_Rec\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ESENT\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\{AEFD33F3-CC73-4821-AD44-6915063E7FB1}\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\{EF381EA0-4D07-418D-A490-68AF67CE948B}\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\ImagePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Desktop\\General\\Wallpaper",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W3SVC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSSCNTRS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Start",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\ImagePath",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\inetaccs\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHPORT\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NTDS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Lsa\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\scrfile\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\comfile\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Name",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Data\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ServiceModelOperation 3.0.0.0\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSSCNTRS\\ImagePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\ImagePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\{EF381EA0-4D07-418D-A490-68AF67CE948B}\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\Segoe UI",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfProc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Start",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Security",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\notepad.exe\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\Start",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\UseDoubleClickTimer",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fs_Rec\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane16",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane13",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for SqlServer\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TSDDD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane6",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiApRpl\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane3",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane1",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\{AEFD33F3-CC73-4821-AD44-6915063E7FB1}\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane8",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\SimSun\\Plane9",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Stream",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DCLocator\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\inetaccs\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W3SVC\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W3SVC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SMSvcHost 3.0.0.0\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\xmlprov\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\ImagePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adsi\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIPTUNNEL\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPNP\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfOS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHPORT\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Parameters\\ServiceDll"
            ],
            "directory_enumerated": [
                "d:\\AUTORUN.INF",
                "k:\\AUTORUN.INF",
                "p:\\AUTORUN.INF",
                "v:\\AUTORUN.INF",
                "j:\\AUTORUN.INF",
                "y:\\AUTORUN.INF",
                "f:\\AUTORUN.INF",
                "e:\\AUTORUN.INF",
                "s:\\AUTORUN.INF",
                "q:\\AUTORUN.INF",
                "o:\\AUTORUN.INF",
                "r:\\AUTORUN.INF",
                "c:\\AUTORUN.INF",
                "h:\\AUTORUN.INF",
                "t:\\AUTORUN.INF",
                "w:\\AUTORUN.INF",
                "l:\\AUTORUN.INF",
                "z:\\AUTORUN.INF",
                "g:\\AUTORUN.INF",
                "u:\\AUTORUN.INF",
                "m:\\AUTORUN.INF",
                "x:\\AUTORUN.INF",
                "i:\\AUTORUN.INF",
                "n:\\AUTORUN.INF"
            ]
        },
        "first_seen": 1587318806.20225,
        "ppid": 1480
    }
]

Signatures

[
    {
        "markcount": 8,
        "families": [],
        "description": "Queries for the computername",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameA",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1587318799.921375,
                    "tid": 1516,
                    "flags": {}
                },
                "pid": 1480,
                "type": "call",
                "cid": 3171
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1587318800.327375,
                    "tid": 1516,
                    "flags": {}
                },
                "pid": 1480,
                "type": "call",
                "cid": 3967
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1587318800.374375,
                    "tid": 1516,
                    "flags": {}
                },
                "pid": 1480,
                "type": "call",
                "cid": 5095
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1587318800.390375,
                    "tid": 1516,
                    "flags": {}
                },
                "pid": 1480,
                "type": "call",
                "cid": 5348
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1587318800.405375,
                    "tid": 1516,
                    "flags": {}
                },
                "pid": 1480,
                "type": "call",
                "cid": 5610
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1587318800.405375,
                    "tid": 1516,
                    "flags": {}
                },
                "pid": 1480,
                "type": "call",
                "cid": 5841
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1587318800.421375,
                    "tid": 1516,
                    "flags": {}
                },
                "pid": 1480,
                "type": "call",
                "cid": 6115
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1587318800.437375,
                    "tid": 1516,
                    "flags": {}
                },
                "pid": 1480,
                "type": "call",
                "cid": 6389
            }
        ],
        "references": [],
        "name": "antivm_queries_computername"
    },
    {
        "markcount": 3,
        "families": [],
        "description": "The executable contains unknown PE section names indicative of a packer (could be a false positive)",
        "severity": 1,
        "marks": [
            {
                "category": "section",
                "ioc": "CODE",
                "type": "ioc",
                "description": null
            },
            {
                "category": "section",
                "ioc": "DATA",
                "type": "ioc",
                "description": null
            },
            {
                "category": "section",
                "ioc": "BSS",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "pe_features"
    },
    {
        "markcount": 3,
        "families": [],
        "description": "One or more processes crashed",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "__notification__",
                    "status": 1,
                    "stacktrace": [],
                    "raw": [
                        "stacktrace"
                    ],
                    "api": "__exception__",
                    "return_value": 0,
                    "arguments": {
                        "stacktrace": "0\nx\n2\nc\n1\n1\n9\n0\n4\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0",
                        "registers": {
                            "r14": 0,
                            "r9": 0,
                            "rcx": 48,
                            "rsi": 2154373139,
                            "r10": 0,
                            "rbx": 0,
                            "rdi": 0,
                            "r11": 82968400,
                            "r8": 2007859596,
                            "rdx": 8796092863056,
                            "rbp": 82967520,
                            "r15": 131498,
                            "r12": 4294967295,
                            "rsp": 82967400,
                            "rax": 46209280,
                            "r13": 8791721239232
                        },
                        "exception": {
                            "instruction_r": "83 3d 8d d1 02 00 00 68 53 12 69 fb c7 44 24 04",
                            "instruction": "cmp dword ptr [rip + 0x2d18d], 0",
                            "exception_code": "0xc0000005",
                            "symbol": "",
                            "address": "0x2c11904"
                        }
                    },
                    "time": 1587318379.799769,
                    "tid": 2388,
                    "flags": {}
                },
                "pid": 1788,
                "type": "call",
                "cid": 11182
            },
            {
                "call": {
                    "category": "__notification__",
                    "status": 1,
                    "stacktrace": [],
                    "raw": [
                        "stacktrace"
                    ],
                    "api": "__exception__",
                    "return_value": 0,
                    "arguments": {
                        "stacktrace": "0\nx\n2\nc\n1\n1\n9\n0\n4\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0",
                        "registers": {
                            "r14": 1,
                            "r9": 0,
                            "rcx": 48,
                            "rsi": 106319872,
                            "r10": 0,
                            "rbx": 0,
                            "rdi": 237332784,
                            "r11": 192936176,
                            "r8": 2007859596,
                            "rdx": 8796092404304,
                            "rbp": 192932768,
                            "r15": 0,
                            "r12": 0,
                            "rsp": 192932648,
                            "rax": 46209280,
                            "r13": 0
                        },
                        "exception": {
                            "instruction_r": "83 3d 8d d1 02 00 00 68 53 12 69 fb c7 44 24 04",
                            "instruction": "cmp dword ptr [rip + 0x2d18d], 0",
                            "exception_code": "0xc0000005",
                            "symbol": "",
                            "address": "0x2c11904"
                        }
                    },
                    "time": 1587318380.361769,
                    "tid": 1296,
                    "flags": {}
                },
                "pid": 1788,
                "type": "call",
                "cid": 11688
            },
            {
                "call": {
                    "category": "__notification__",
                    "status": 1,
                    "stacktrace": [],
                    "raw": [
                        "stacktrace"
                    ],
                    "api": "__exception__",
                    "return_value": 0,
                    "arguments": {
                        "stacktrace": "R\nt\nl\nI\nn\ni\nt\ni\na\nl\ni\nz\ne\nE\nx\nc\ne\np\nt\ni\no\nn\nC\nh\na\ni\nn\n+\n0\nx\n6\n3\n \nR\nt\nl\nA\nl\nl\no\nc\na\nt\ne\nA\nc\nt\ni\nv\na\nt\ni\no\nn\nC\no\nn\nt\ne\nx\nt\nS\nt\na\nc\nk\n-\n0\nx\na\n1\n \nn\nt\nd\nl\nl\n+\n0\nx\n3\n9\ne\nd\n2\n \n@\n \n0\nx\n7\n7\nb\nc\n9\ne\nd\n2\n\n\nR\nt\nl\nI\nn\ni\nt\ni\na\nl\ni\nz\ne\nE\nx\nc\ne\np\nt\ni\no\nn\nC\nh\na\ni\nn\n+\n0\nx\n3\n6\n \nR\nt\nl\nA\nl\nl\no\nc\na\nt\ne\nA\nc\nt\ni\nv\na\nt\ni\no\nn\nC\no\nn\nt\ne\nx\nt\nS\nt\na\nc\nk\n-\n0\nx\nc\ne\n \nn\nt\nd\nl\nl\n+\n0\nx\n3\n9\ne\na\n5\n \n@\n \n0\nx\n7\n7\nb\nc\n9\ne\na\n5",
                        "registers": {
                            "esp": 1638276,
                            "edi": 0,
                            "eax": 0,
                            "ebp": 1638292,
                            "edx": 4198400,
                            "ebx": 2130567168,
                            "esi": 0,
                            "ecx": 0
                        },
                        "exception": {
                            "instruction_r": "89 08 50 45 43 6f 6d 70 61 63 74 32 00 a8 f0 93",
                            "symbol": "trojan guarder+0x1016",
                            "instruction": "mov dword ptr [eax], ecx",
                            "module": "Trojan Guarder.exe",
                            "exception_code": "0xc0000005",
                            "offset": 4118,
                            "address": "0x401016"
                        }
                    },
                    "time": 1587318806.43725,
                    "tid": 2572,
                    "flags": {}
                },
                "pid": 1504,
                "type": "call",
                "cid": 0
            }
        ],
        "references": [],
        "name": "raises_exception"
    },
    {
        "markcount": 13,
        "families": [],
        "description": "Allocates read-write-execute memory (usually to unpack itself)",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 1480,
                        "region_size": 4096,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "allocation_type": 4096,
                        "base_address": "0x00470000"
                    },
                    "time": 1587318789.718375,
                    "tid": 1516,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE",
                        "allocation_type": "MEM_COMMIT"
                    }
                },
                "pid": 1480,
                "type": "call",
                "cid": 89
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 1480,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x74ad1000"
                    },
                    "time": 1587318789.765375,
                    "tid": 1516,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 1480,
                "type": "call",
                "cid": 817
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 1480,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x74a11000"
                    },
                    "time": 1587318791.655375,
                    "tid": 1516,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 1480,
                "type": "call",
                "cid": 2362
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 1480,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x75b61000"
                    },
                    "time": 1587318791.655375,
                    "tid": 1516,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 1480,
                "type": "call",
                "cid": 2364
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 1480,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x74a01000"
                    },
                    "time": 1587318800.327375,
                    "tid": 1516,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 1480,
                "type": "call",
                "cid": 3943
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 1504,
                        "region_size": 8192,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "allocation_type": 4096,
                        "base_address": "0x003f0000"
                    },
                    "time": 1587318806.43725,
                    "tid": 2572,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE",
                        "allocation_type": "MEM_COMMIT"
                    }
                },
                "pid": 1504,
                "type": "call",
                "cid": 1
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 1504,
                        "region_size": 1966080,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "allocation_type": 4096,
                        "base_address": "0x024b0000"
                    },
                    "time": 1587318806.43725,
                    "tid": 2572,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE",
                        "allocation_type": "MEM_COMMIT"
                    }
                },
                "pid": 1504,
                "type": "call",
                "cid": 11
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 1504,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x75141000"
                    },
                    "time": 1587318806.46825,
                    "tid": 2572,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 1504,
                "type": "call",
                "cid": 24
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 1504,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x74b51000"
                    },
                    "time": 1587318806.46825,
                    "tid": 2572,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 1504,
                "type": "call",
                "cid": 26
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 1504,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x77351000"
                    },
                    "time": 1587318806.48325,
                    "tid": 2572,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 1504,
                "type": "call",
                "cid": 550
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 1504,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x74ac1000"
                    },
                    "time": 1587318806.48325,
                    "tid": 2572,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 1504,
                "type": "call",
                "cid": 552
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 1504,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x77311000"
                    },
                    "time": 1587318806.49925,
                    "tid": 2572,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 1504,
                "type": "call",
                "cid": 694
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 1504,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x77b61000"
                    },
                    "time": 1587318806.49925,
                    "tid": 2572,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 1504,
                "type": "call",
                "cid": 696
            }
        ],
        "references": [],
        "name": "allocates_rwx"
    },
    {
        "markcount": 3,
        "families": [],
        "description": "Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetDiskFreeSpaceExW",
                    "return_value": 1,
                    "arguments": {
                        "root_path": "C:\\",
                        "free_bytes_available": 23512920064,
                        "total_number_of_free_bytes": 0,
                        "total_number_of_bytes": 34252779520
                    },
                    "time": 1587318793.718375,
                    "tid": 1516,
                    "flags": {}
                },
                "pid": 1480,
                "type": "call",
                "cid": 2737
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetDiskFreeSpaceExW",
                    "return_value": 1,
                    "arguments": {
                        "root_path": "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer",
                        "free_bytes_available": 23510847488,
                        "total_number_of_free_bytes": 0,
                        "total_number_of_bytes": 0
                    },
                    "time": 1587318380.033769,
                    "tid": 2808,
                    "flags": {}
                },
                "pid": 1788,
                "type": "call",
                "cid": 11422
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetDiskFreeSpaceExW",
                    "return_value": 1,
                    "arguments": {
                        "root_path": "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer",
                        "free_bytes_available": 23510847488,
                        "total_number_of_free_bytes": 0,
                        "total_number_of_bytes": 0
                    },
                    "time": 1587318380.440769,
                    "tid": 1880,
                    "flags": {}
                },
                "pid": 1788,
                "type": "call",
                "cid": 11697
            }
        ],
        "references": [],
        "name": "antivm_disk_size"
    },
    {
        "markcount": 7,
        "families": [],
        "description": "Creates a shortcut to an executable file",
        "severity": 2,
        "marks": [
            {
                "category": "file",
                "ioc": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Help.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Trojan Guarder.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Uninstall.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\Desktop\\Trojan Guarder.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Trojan Guarder\\Visit Our Site.lnk",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "creates_shortcut"
    },
    {
        "markcount": 3,
        "families": [],
        "description": "Queries for potentially installed applications",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "registry",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741772,
                    "api": "RegOpenKeyExA",
                    "return_value": 2,
                    "arguments": {
                        "access": "0x00000001",
                        "base_handle": "0x80000001",
                        "key_handle": "0x00000000",
                        "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1",
                        "options": 0
                    },
                    "time": 1587318790.108375,
                    "tid": 1516,
                    "flags": {}
                },
                "pid": 1480,
                "type": "call",
                "cid": 1834
            },
            {
                "call": {
                    "category": "registry",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741772,
                    "api": "RegOpenKeyExA",
                    "return_value": 2,
                    "arguments": {
                        "access": "0x00000001",
                        "base_handle": "0x80000002",
                        "key_handle": "0x00000000",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Trojan Guarder_is1",
                        "options": 0
                    },
                    "time": 1587318790.108375,
                    "tid": 1516,
                    "flags": {}
                },
                "pid": 1480,
                "type": "call",
                "cid": 1835
            },
            {
                "call": {
                    "category": "registry",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741772,
                    "api": "RegOpenKeyExA",
                    "return_value": 2,
                    "arguments": {
                        "access": "0x00000009",
                        "base_handle": "0x80000001",
                        "key_handle": "0x00000000",
                        "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                        "options": 0
                    },
                    "time": 1587318800.452375,
                    "tid": 1516,
                    "flags": {}
                },
                "pid": 1480,
                "type": "call",
                "cid": 6565
            }
        ],
        "references": [],
        "name": "queries_programs"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Installs itself for autorun at Windows startup",
        "severity": 3,
        "marks": [
            {
                "category": "file",
                "ioc": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Trojan Guarder.lnk",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "persistence_autorun"
    },
    {
        "markcount": 3,
        "families": [],
        "description": "Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config",
        "severity": 3,
        "marks": [
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegSetValueExA",
                    "return_value": 0,
                    "arguments": {
                        "key_handle": "0x00000154",
                        "value": "6-\n\u001eD\\)\u0004C\u001c!,]\u0013'8& )\u001d_!@\u001f\u001c\u001aQ\u0013TS'A0V\u0004VHQ\u0005@1\u0007Z`,U\u0016\r!\u00193'\u0010+Z\/%\u0014\u001a\u0002\u0012?!>=c?28\u000e\bD\u000e\u001bJ\n9\u0001^.R\u0018]\u0002[H\u0005?\f[\u0005UAa\u0001\u001c\u001fO\u0015ID9\u001f@?+\/Z,[\u001d`!@,\u0001%_2\u000bHU\b0\u0012\u0002\u000f,\/R:+\u000f\u000b4+aMT.)^3,V(\u0010 H_\u0001EZ#@+3M\"1K\u001d\t]@\u0018Y6\u0002\u000fA)>$\/\u0004%\u0010[;=\u0018,00K24]$M2\u001fL\u000b7\u001f\u0007L3\u0006__W\u001fMZO\u0001O&#,\u001e\u0018H\u0005YG\u00187F2\n\r#=\u0002];'!a.W\u0004,\u000e\u0018b3cP3B>XV\r-\r3\u001aJCV\b>\u0006RE,P]<\u0006\t3RE\u001c\r\u00167[\b\u0016B:\u001e4<\u0014\u001c\u0005\u0006J]!!TN[Y\u0001O\u0006\f\u001c #\u0014c\u000eS!-PW4_c@Z<$\u0019\u0018$CH\rVC\\*\u001e'$\u0002\f\u001aI\u001293_X\u000b]&`\"9\u0006\u0001^LW\u0004J23FLZ\fQ\n@\u0003\u00053\r\u0001O*\u00168\u0016^4=T\u0017ZS:O[0H`\u000eZ\u000fU7\t\u001d\b(\u0003bDPM?GJ,[\u0015\u001d\"\r=;\u00051N``6\n\u0018=` ++!D;:Q<_W\u001e\/4XE\u001c)_2$3F\u000e\u0018\f3SSG1\f\u0007)'\u000e\u0019\u0006F&\u001e\u00075Oc:@R\u001c3\u0016!!251\u0019\t\u0001\u0017H\u000785&1S\u001cH\u001c9([\u0003\u001a0\u000f^!\f%?\u0012D\u0014A-\u0001Vb.\u0010\/V\u0002c#\u0011\u0016\u0005\u0019%N\u0011\u001a#%S\u001aM\u0007;:(]\u0004#6)\u0006\u0010:)\u001a.OW\u0005B\u000f:N9\\\u0003868E++]^H\u001dGO7BM\"\u001c_)*1\/$2\\MRJ(\u001d).P\u00060\u0018C\u000e*D9KKN\u001fLFCLMQH\u0018\/MZ);$:6\u00140%828K\u0015\u0014\u0002>6\u0012\u000f65!\u0007#\u0002\u0003 ERO\u0016K\u001c\t`H\u001c^\u0019A\u001dR\u001f\u001c&\b$\u0015\u0018\u001cLP*\nD<#R.`K-bT1K\u001e\u00010DWR_ccW\u001a\u000b\u001f?\u001aJV\u0006\bG_Q0:\u0004\u001cCB\u0014J\/F\u001ba>\u0001\u0011$V\u0004]0\nK[]W@\":'.`$B\"\u0019\fV`66\u0018$00DGIa'?\u0002\u000eRU\u0011a4[U\nE\u0019]>,4G\u001a$\u0017'SR\u001d$M\u001cN\nE$!1\u0010\nEU\u0014\u0010;\u001eM]?b0`\u001f\u0005\u0013b8TV-\u000e-\bV\u001a9=5R\u000fFGM\u0015\u001d-\u0017-[\u000f\u000f\u0002KC b=@QRcA$GZ4\u0011Q\u0015\u0002&LE\u001eE\u0002\u0011\u001d\t?\u0019XK6@+\u001db\u0015\\G6+PQ\f0\u0018:\u000f_?+Q<<[\u0015\u0003KM\u000e]5[\u000b*\u001c\u001aX\u0012\u000f=\u001b\u001dV\u001f\t\u0016'<\/C\u0010\\\u0010>B\u0016J`7\u0015c\u000f!5\u0004\u0002(^\u0015\u000b'@\u00166\u0006\u0004-\u001cB\u0017\u0007O\u0004\u0003\u0017$\u000f\u001e\u0018\u0004(=\u0013+#)\t\u0002\u0013>\u000f@V$^\\\u0006ZSY$\u0013\u0014\u0001?\u0013$*?:\u0005\u001e\"TO\u000e\u001a\f#\u0005\t&\rN]\u000f\u000e\u0003@\u000bZ'[\u0006I;UVF8BH\u0019\u0010%\u0018\u0005F\u001f\u001a]\u001fIB-W(X\u0017+\u001e,\u0013$ 0\u0002#\"LF*B%b$Q%\u0013\t\u00162\bD(-&,\u001a\t\u000bH\u0015\\\u0017.J\u0010\u00147\u0005\u0012F\tY\u001f6A%\u0004\u0005\u0005>\u0018ON(5)*-.=P37;W2\"\u0003cHS1\u0006`JN\u001d%\u0014Ab6\u0010\u0017N$\u001f\u0017\\%6*\u001b+>)\r\u001c\u0017A\u001c(J,5\r%PK9]A]9>\u000e\u0014a\bAG\f27G\u00012B\u0015\u0002(!\t\u0018$\u001f% 9[\u001b@0S(=\u0017\u001d5?\u0002\u000f\u001eEWF\f[\u0011\u001f+aDS\u001d.O\r\u001e\u0019F\u001b`7\u0018;\b\t0\u000eB?LH\u001e\u0018V\u0011\u0003(N\u0013\u0014TW!\u0005\u0012\u00164OQ,HSU\u000bY\baS2#\\)Z\u0002B\u001d\u0001\\!]EL-a,\n$:\u0004^\/\u0011,&,0\u001a^\n\u0019_\u0002?G7bFa\u000e5\nDFD6aK<+B*\/\u0013^>\u000b*\u0012S(:&\n1\f\u0004W\u000f\u001e,Y^_`:\u0017V\u001f\n^EM(*)BQU5\u0018\u0010\u000b\u000e\u001a\u001bY&\u0001BE[N&M\nLF#W0\u001504>\u001a2.1D6\u00036\u0010*<\u0019I\u00015DV\t\u0006X2a\\\u0005@\u001fQ>,\u0012)\u0002\na\f\tI\u000f\u0017S\u0014\u000b$\u000b\"T1;\u0015KEc<]\u0012Q)^Y;SE\u0002^@\u0005\t\u0010\u0015N>9\t\u00119Q:K)A]\u0011\tJ\u0015DCB'KEB\b9\nR'B\u0016@\u0013(N\u0010\u001a+'bPNPW1\u001d\u0010WUQ5\u001b\u001f+-M#LNM\u0016_I\u0014K\u000bV\u000f'.YBX\/PaJ\u0004\u000b\u0013\u0012cTR\u001b\u0006\u0018>\u0011X\u0016a'&\u001f>\u0016\"U\u0010\u0010O\u0013\u001aB\u0005\t94\u000b\u001dE,I\u001dS270W\u0014\/\u0016:\u001e\u0001J.\u000b\u0012\/ \b1b=\u0014^'\u0001I\u00108E6\u001aPQ(O\u001b'`\u0004\/:4`\u0013bQH\u000fW\u0019L\t\u001e\u001dN\u0002K5\u001aJ\u00053*\u0017X\u000fZ\/\u0007\u001b7\u0015\fQG\u000bT5@U7%7\u001c\\>@\u000bO\u0014%9\t]6\u00149c\b\u0015'\u001a,\u0001#?,#P;]\u001fSD!U\u0015P.5\u001d\u001dX2;,\u001c\fJ0.61!0K`M#9K#\u0019`@G_`]^6\u0015DF\r6\u0016G\t\u0014937,V\r\u0010; \u001f\u001ea!`a,\ra@-\u0013\u001aX\u0004\f\u001b\u00064-4),ZP\f\u000b&\u001ec.\u000f\u00016%A\u001e\u0017[\u000e\/\u001e\u001d=*EN\u001bKE05V\rF38)!L$PSTa\u0016&>:\u0001I\u001aL4\u000e\n[a\\[\u0018c\u001dF\n;GW\fL\nb&@Y\u001db9:IT';\u0004)<\u000e+\u0001JWO?4]Y%H\n\u001a 7TL\u0011\u001a4S)+H'::\/NV\u0006\u001b8\u00076(\b\t7:\u000fbY<7P\t\u001e\u001c\u001a\u0018\t\u0011\u0018DQbYFJR$$@V\u0001a_bMOMCX\u00075R.;G\u0004@\u0019Q\u000b)\u0012\n )\u0019\u0019Y`I55T^]\u001d-\"\u001aK\\(D\n\u0015=QY'!b\u001dJ,Y= K#<\u0015\u0001\u0001\u0001\u0017\u001d\u000f@\r?\"(\u001a^[?2\u0002\\\u000e\n+ULE\\ \/K\u0003\f\"=]F\u0010>)J_$\u001750S@\u0001\u0004\u0007\u0014*\u0002\u0018\u0002 H3.0'W1`'\r\u0002I>W&\/SZ] J7%1\u000e3\u001a\u0015\u000f76Zb\u001bK%\n\u0011\u0017]LH\b?8I $5\u001aB0OZ!F\b`\u00157\"\u0017\u0004GF\u0005N\u001e\u000fN\u0004\u00175L\u001e\u0003`X\u0003\u0010\u001e`M8WC=`\u0012@,\u0010%\u000f+\u0014\u0015\f\u001c'T\u0016A_^+\u001c\u0006M(<\u001cT\u0007#\u0018[+Y\u0013<\t,\u0012%8<(\u001d\u0002Y\u0004\u0005BTGR\u0004;;\u0005c\u0006(\u0011XaM\u0007\u0004\u0002\u0018D\u0007*Y\u001fG\fD\"&;\r\u0001\u0017\u0019\u000f.)+1\u0018VJ[\t7\u0016W>G\u0007\u0013R`-\"\u0019MPQRc\u0010P\u0007Z[%\u0018$G G\u001f\u0003C\u0012VD,Q\"\u0004Y\"\u0012[HR)XWY\u0005>=\rH\u0004\u001a\u000b\n\n\u001f\u001bV\u0019B*ZDT0@'?\u0003\u0005S81b\u001b\\JK\u0011\u0004\u0014H\u000e`Y\r+\u001668I\u0011\u0019N\"$\u0016\u001e\u0001\t%C2\u0011VHa\u0016E5\u0010\"4\u0007?>+\u0013\b\u001f\u0003L\u001f$>&c8N\/\u0019\u0001.,\"\r)O\u0014G&,=N\u000f8VY\u001e:\u0005G%(IYY\b[D\u0011C\u001a\"\fZ\u0002b@\u0017\t\u001cM6%\r\u0015EZ2UH\u0016IXE^?Nc\u0019-X\u0006\"F\\PV\u0011F1QN\u001d:38\u0002\u0013\u0019a\u0010]c'\u0017a\u0006\t\u0012\\_\"=\u001c\u0004RK;?c C`.;\u0019\u0019\u001aNM:(=ZCOL'5&+\u0016E\u0004\u0011'Q:\bO@\b^B ]MG>(KZ\u0013U\b@A4\u0016\u0016\u0001\u0019\u0016.\\\u0005G\u001a\u001f<\u0001\u001f)\u0007\u000bW\n7$bI1\u0006\u000eX\u001b;\u000e)D3\u0014B:A>(\u001f\u0006[%\u0006SJ\u001d8\u000fO\u0002.\u001cL\u001e4$\u0006$#SPN\u0003\u000f,\u0006\u0010\u0018a\f:\u0005\f7\u00027J2\/(1,MS&#a*bb%\\_\u0005a0*\u0001S&\u001b R\fQ\u0006QG\u000eP\u0016 UYYIB'[\u001c\u0005\fJ:\u001bIWHRF\u0015\u0006D+\u0018\\I1\u0016\u0019\u0010\u0010-Q\"]\u0001B\t3\u0002\u000b\u0001\u001a=Y0;US\n(\"GQc\u000f5\u0010Q\u0004\u0002.*!^7\t\u001e7\"_\u0019(=_:\">@)[Y[Y\u0019K3+\u00055;@!QG\u000b\u000f\f\u0015\u0002;-\u001dXC-.C<\u0007 G\u001c\u000e'\u0003\u0016)YR!F#\u0018\u0005\u001a\/\u0017\"O:,S_8>\n\r\u0004\u0015\f*S\u0017O%[+\u00166\fZ\u0019\u001b\u0001J2\u0004\u00139+\tS\u001a\u0015Y\u0019a\u0014\n\u001dY\u0004\u0006]]\bSC\u0007\u0018OPE8UY\u001dG$ZT2\u001d\u0004J\u0006W\u000bX#S?\u0005\u0019<\u0002=F0C:^'6\t<\u0010\u0010\t*>`^6\bN6I(VNI\u0019\\Gc[\u0007\u0017G\u0003]&\u000f1-\/_I>E-!6%\u0016D\\\u001c\u0019S!OcP\u0011U,#7\u0005\u001d5&=*QaZ\na\u0005!\t^UE\u0012V6R\u0005=<1.EM1\u0012+\u0011\u0011-;\u0016\u0007\u0011\u0017A\t\u0013BT\u000e#>\u0011G\u00155_\n\u0005LS\u001eN\r\u000e\u0015\u0006NU\u0007,\u001d\u00057\u0018\tA\/X\u000bP\u001f[V\u0003\u0016^D\n=(\f.\\.+\\J\u0017\u0014\u000f^>\u0013,[\u0006*Aa9!\u0006J(\b\u0007\u0010*KYWOR\u0005\u0015.\u0004GP*)\u00104&=aA\u001c+MLKRHacbN#,b\u0017K\u0011Y@\u001aPSO._\nJ\u00038$5\"1\u0002!\u0012=U7\u001d+X\n15\u0006D3K&P\u0003\u0015P\b\u0016\u00016_<\u0006\u001f\u0001ZRbMK\f. \u0002I$U\f<*,I=7W@\u0014GVV\u0005AA\u00171R@ab\u000b\u0005\u0019 \u0012\n\u000f\r =@\"\u001f\b\u0006\nBJL\u001fQE\u001b*\u001c6L\\F9\u0012^N>;`<`JJ<4\u0003S\u0007J\u0012\u000b\u0017I=6\t\rAIZ,\u0017M1&\u0017Y\u001eF\u0018Y\f \u0011a^\r\u000765\u001f-\/I\u0005]:D*\\\r;\u00057\u0018\u001a62\u001c\u001fK\u0015\"\u001a55M\bW.$:?;\u0017\\ a7PM#G\u000341\u001aN9(+F\u001fF@?cb\u001eE \u0006<\u00183G\u00020H5@0D\u001b\u000b[1E\u000e\u001f^%]>P\n\u0013B& &J\u0013\u001c\u001b\"-\u001a%IX\u001cN\u0011HD\u0014OL#B8\u000f8\u001b7\b#N\u0014&*\u001fN\u0004GTP[\b(\u001c[\b@Q&\u001e\/\u0015a.;\u0002C\u000fT\u0016Y\u0017=\u0014#\u0012!a[\u0011PC\u0003\u0001N\u0001O\u001f_'U5[C8\u001c3MM]H\u00040`TL\u001aS.6\f\u001b'-\u001cINB #\b\u00138\u00051\u00037\u000f6W\u0006!D1\u001bHOR$!\rU;%B\u001d_\u000fC+1UXH\u0010*\u001b;\nTV\"\bc\/\\\u0014\u0012\u000e6aG>\u000eG:TKM?\t\n\u0001\b?.2\u000bM?\u001dW<>B>\/A\u0010?!\u000b9J33W!\n\u001c0FUC\u0001a\u0006OV\u000f\u001b2\u0003=?\tb[\u001d)V\u001d\u0005,H\u000e[\u0018\b*8.\u000eCZ\u0015\u0005\u001cO#,\u0016]\bS\b@\u000bYYM\u0002?_V9c\u0006\"\u001d\u00125\n\u0019\"PO*5#\u0012#\u0006\u001eZ\u000baa)JP\u0016=F\u000b0D?^BN\\$I+OD\u0017\\B\u0017\u0001^\fW.\u0014D\u000b+\\\u0010\n\tN\f-%\b4\\E$0D7\u001e\u0010\f\u0017K\u0018)\t\f\u0003'^U9\u0012\/\u0005\u0013@G\u00065V;\tM2c\b\u0002\u0010US&TU\u001f:6=c;S@b-\"C\u0018H+I\u0018P\u00031%5\u000e\fC3AMH\u000f\u001d:\b\u0017S,\u0018V\u0013#\u001a.-D\u0017\u000fE\u0015b\u001e\u0001=52',FY'A8^H'5!EA](\u0007I\u0014L!J\u0015<\u0019H\u0005>II>1IF.6C_*U\u0006S6F\u000eR\u00041\u0019\u0006S\u001f\u0016\u001a\u0017--\u0011_\f>TW\u0011.HX<\u0006\/Wb\u0007)#\u001e\u0001'\u0001*M?\u0019WPB\n-\u001e2:\u001b\u001b\n\u000f\u0007\u001d\u0018JE&b6R\b\u0007[\u001e^\\KY]8W\u001b\u0010\u00146-2CaS6\u0015C\u001d\u0011\u0004X\u0007,\u0019T4\u0018`\u0018%\u001b\r\u0018\u0007\u000e2U8%3\u0015\u00106M?\u0012*\u001eU0`8\u0006\u0011SP)\t\u0006\u0014\u00176N\b\r^4\u0016.\u0003P\u0005R>b\u00033K\u0006\u001dbUIN\u0019\u0001\u0019.OANN\u001d\nQQ\u0006QU<\u0016\u000fBD-]>!\u0019WZSC_W\u0014\f\u0006)\u0007,\u0007H\u001e0\/0$\r\u0017\u0016>@POK\u0003(\r\u001dGa(O\u0004?\u0003\u0014b!#\u0004&]\u000f\u0005T\u0010S>\u0018^E-\u0010\f\\\u001e\u001b5D\u0013PDV3a9[P\u00108\u001fKC:&\u0006\u001315U\u000e\u0001$QB8F@\u0019Z:H\u0014Q0IV\u000fD\u0001]\u000eY \u0019I\u00106\u0004F\u001d\tR#\u0014\u0010\\5\u001b`#1bE\u0010N\u000fS\"\u0014P%937&\u0016GT:\u0019\u0016\u0018\/V\u000e*,\u001b2Z2L'aR<\u0003\\J4\b\u001aLR^\u0004;\u0013C<\u0006S\u001aQ\u0012B;LZ\u001cHX*\u0003\u0005\u0014B\u0018?P =\u0014\u0005\u00199\u000e\u0014`I\u001a\b'\u0019= Y>3b$S+^!=3+F0@\u0013'\u0006I6\u00046\f\u0001.\u0012\u001dNL\\\u00063\u0014\u0013^\u0006\n\u00076\b\\N\u0001S#KO@1\u0010\u001cQ[8Fa\u001cD4\"\u0003:\t\u0018&? >P\u0015%\u0016D\u001d4,2%(+)\u0006\u001b\u0013\u0011`\u0010b\u0010NI\u001a43\n6^!&\u0001%\u0004\bO4\u0003@]:_ c$\u0004-DGDZ\u0006S\u0001GN._\"\u001f..6Z\"!c,\tb\u0002\u0007\u001c1\"\u001d3\u0016Da\u001f\fN\u000fOZ4AK3=; 6\u0002J\u000b\u0016%+\u0018\u0018b3DH>\u0019>\u001eZ>\"7^\u0004_\u0006\u0007\u000e\u0002R\t\u0007>\bQ:F*^A\u00058N,\bb[\u0005\u0012\u0012*_\nYT 7\u0002X6'\u0005\u0002!\u0007_GXc\/;E0@(;3\/)\u001fA[:a\u001e\u0005Z3CcJ>\u0017` \\3?\u0004\u000eP[\u0015\u000f)TD4\u0016\u0016XU)\nb\u0014'KSM\u001b]\u0002VB\u0007`[\u001e\u0017\u0015N`\u0013+E6,9\f\u0016a$$\u0019\u0013E,\u001fW9\u001cVA)UM'c\u000b+\u0001A6L\f,R\/\f(\t \u0017b;!\u001f\u000e;`\u0017;\r\u00134OIN\u0001O\/0-B% P<\u0011\n\u0019\"\b\u0003\u0016%\u0006\u0001\u0011<>V%>* 01+\\Z7\u0001S+\u001a\u001bH.\"`NHF!\u0007\u001cI)L\u0006\u0006L \u00190\u0018PL(L&Nc0R\u0018\u0007:\u0006)@S\u0010?VY\u000e_C\f`\u000bT\u00050'!]'5\u0018\nN..6\u0003F\u0010\t\u001c\u00013= 7\/H\u001d\u001d\u0005Q6EK^&4$\u000e55(M\nI5`4I3V\u0010 !KN\u0012\u0018Y\u0004\u0003\u0013\f\u0011(X\u0002.6\u0002+2\u0010\u001c]Y@$'N-\u0004\u000fV$9%4\u001b0b\u000f\u0011RRP\u0013:2!\u001a2,\u001a\u0012\/\u001eQ'\u0019!a\u00022OJF\u000fD\r\u001b,:6R\u0005\nMKNX\u0005DMb%\u0007\u0011\u0019%\u00051\u0005Ya)%#5B[R\u001d$N\u001c\u0003L\u001c^\u0013?\/\u0018P\u001eOMY\u001b\u0013[C*G\u0005\u0011\u000f\\\u000e`@^\u0014`AZP6\u001e\u000fL35\u0003Z)\t\u0001\u000bUV-L)\u0005Y\u000b3&?bAI\u0011\u0007?NOW\u0016-\u0003Z\u001c=)NB&.\u0016P3S\u0015M>\r`P1\u00124+OR\u00035\u0010#D.\u001cFE+D\r\u001a\u0007BNAb\u0014\u0011\u00168\u0001>__U+_0\u0001\u0019X\u001c,U\fY41HN\u0003T+OR3Z\u0004\u0003\b;!O[\u0011^:@\u0001<-@Z\u001a\u001c!CZ9Y)?\u0019*O\u001a\n=\u0002\u001e5F\u0014\u0018\u0015b\u0006\u000b4\u001c\u001a-LY*b8SIX4\u0018%#*b\u001f&\u0017NW\u0002)2\u000b3\u0012?MTI\u0016\u0002\"D!\u0012$9\u0016ZZ\u001d$\u0019\u0017\"]NK_CI&Z;5)UW\u0001)X&%\u0013\u0019\u001fA\u0014N<>H\";\bUC\u0015\u001eTT\n&0G\u0011bR\u0015\u001f\u0003I>:\u000f-@\u0014?\u000eO&P\u0012'P\u000b@\u000f2\u001c 4\u0005\u0007(`\u000f-K.\u0001\u000f(][R8\r\r(c$Mc$*.\\D\fS\u0011I+:S\u0013a;6*K716K\"F0,\u0005\u0001%O\\;03L:2\"\u0016UC\u001e\f>LR\r\u0004'F\u0015>-&J[\u001f_ $K6GM,YK;\u001b\u0006_!7\u001c:>0`\u0006[=]-\u0016\u001bX\u0002N6\u001fOG53@_\u001f\u0001\u001b\u001b_\u0004\u0005H\u0005\u0015\u000f\u0015NE\u0018K4`8$;1\u0015\u0002*<\\`_PY\u0001=b6\u001f]D\u0005\u001d[!\u00118?V\u000b64U>\r[9\u0013\u0006\u001b\u0016\r\rWM@(\u0004*HKU5]K [()P9\b,L6\u0002\u0015\u0011\u0011Z\u0004F\t7\u0004\u0016\u001c9\u001f#*\f\u000e6*L\u0001P\u00153\u0013\u0017b?\u00014.-Q\u001f&(\u0001\u001f\u0001J\u0018X][ #\u0004\fI\u0017\u0004!\u0014\u001b\u001b\n\u0006\u0007X4A>)[&:WS*\u001d6F)K(\"\u0002\nKQI\u0012X%1\f8]\u001b\u0019&\u001dW? 1:82\u0005\b2a\u000f^J>&JS\n\u0016aPbV7N[9?*P62\u00102\"\u001a>\u0007#Q_ZbOb:J\"4\u001b\u0014\\\u001c=\u0001 '(;.D\u00104,\u0012GU\u0019\u000f5>\u001a\u001eO?\u0003\u0010\u001fI\u0004$IP\r9' \u001fK^\u000bA#X\u0018I& OQ\u001fV4O]\u0018\"cM\b\u0018\u0014Z=\u00152B#*GX(?95;G\u0016:\u0001\tB\u0019:\u00077\tS\/C?BK]\u0002-=\t:&S\u0005P^=<=\u0019\r.\"\u0019Z7'\u001a0\u0012\u0017I+5\\3\u0003\nD\u00030QJbD`7\u001d\u000e\bG\u0003\u000e\u000e?@0,&6\n@\u0013[\rYA$NTBX1Lc8S\u000fM\u0016]\f@\u0012O\u00194\u0001VP,,\u00140Q9Z+@@Y\u0007?\u0012`\u001aH6>PB%\"\u000fB<\u000e\bC$\\D\u001b\u0014\u0004R(\n>\u0012\u001dM@G\u000b?\u0010Z\u000bM\u0005A\u0017MA\u000fObW\n=\u0014'LJ)B,(F3YD 4D\u0012\u0003c\rF\u0010\u0014H\u0003\u001e,^F3\u000f\b5X\u0014\t\u0004cMcc)AU`J.\u0015\u001fbXW >V\u0016!I;\u0013J\"J8\u0005\u000fD&\u000b(\u000f\f\u0003GV\u0019\u0002\u000bX\/ \u001c\nbO\u0017c\u0003&@\bL5$P\u0003M?\u000eN\u0016\u0013\u0013^c\u0011K\u0017\u0010\u0012\bXZ9\u0011\\\rV\u000bW;H\u0012\n\u0007\u0010=ac\u0010G>PAD[_R\u001aA!N\"@URP.V\u0002\tbJ\u0014H)O`S\u0012D<\u001faN:\u00072\u001bYK'<2'1\b3U\u0018_\b [\u0019c4F\u001fX9bbcb.VG\u0018\u0017F\u0016,\u001d\"\u0019#\u000f\u0004*QQS\u001e-\u001b\u00010^ICG4!.\u00079(L\u001bbY\u0013=\u0016S\u0012>\tM\"S Sb!U\u001e\u0005F)?K(\t]\u000f1\r E\u0017\u0012J$\u0004\u0004D\u0005\u0005KH\u0015EU\u000e\u000f8\fYM\/BD\u000f\u001b]\u00063X2(3\":a-%\u0002\u001e\/\u0017$)U$0\/\f&8X*2<\u0002]*[\u000b`5\u0005J4\u0018a%\u00033;\u001e[cMDQ\u001dG\u0011\u001b\u000b\u0013#c\u0005.D1V\rMA\\C\u001f$\"+Q_9@\u00181\u0015';<=6\b?92\/\f\bG\u0004<4\b@\n6*\u0002K7\f O\u001db2H!\u0001SE0]D&>L+7V\u00124:K\u0005@Y'\u0010SZ>\u0003V\u001dU0=_\f\\UQ\/%PB1I\u0002H:(\rTT^^\u000e@!YA\u0011Y_6Ob(`8].\u001b?Vb>T!)2561\\PMZK\u000bO]\u000b&5\u0002CY\u0012\u0005\u001a\u0006\t\fF\u001fbEc5\u0010^[\u0019\u0007\f\u001eMC%\f:\u0015S)\u0011=\r\u0007'\u0005QRa\u0004\u0003\/B8\u0002\u0012a\u000e\u0006$)\\A!98+\u000e\u0006,K =0\u0016J\u000f?01;\u000b\u0016\u0011\u0007WP\t\u000f Cc\n\u0005)_\"%PF\u0013PQ\u0005?\u0002F6%\u001a\u0005NT\u0006N`]Qc(\u0013\r!TQ\n&$\u001dc=(\u0005c\u0019\u001d+K\u001e\u0017aN\u0018E\u0004TV\u0012`T\u0012\t\u000149?\u001c\"\u001d\u001b%@\r]\u000f\u0011O5Q?a\b\u00101\u000b\u0015.(4!J499\u000f5':HR]N@?]@\u001f@\u0011>H\u0004]\u000b\bX\u001b\u000bV)>\u000b1'G@(\n\b,D\u0010b\u000e?1\"9\u0002@\/1@_V\u0005\nHZ\u0018\u00029?\"\u0014!HI94<1VI\r[YI:@bc\/\u0006\t\u0006)\u0017:3(>9;\u001f\u0002\/+;0D\u0006EF+W\u001c\u0006L\u0005aFF\"EW6.\u0014$\u001b^VB^9\u0016=Y]WO\u0013>P\u000f=8\u001eG2;.%\u001a\u0015\u000f@0\u0015\u0017_$\u00019\u001f\u0016R]>\\!\u0003W\u000b\u000b\\b^72\u001dK\u001dU\u0014`*,0\u0015L\u0007L^\u0003`\u001c\u001e!\u0012Z\u001f\f\t'(\u0012.]P-\u000585UEQ;J5,W-\u001f\u001f\f\/\u0016#RK-4@\u0017P\u00173%\u001e+C\u0013W\u0010Y$\f!0W\fO\u0014\r1`\u001c\u0006\u0007\u0005\u000b\u000b-`9#\"S\u000e\/\u001a5c,\u00154H\u001fV7?><\b\u0013B\u0011R\u001f7\u0010)G[\u0011\u0002[#2\u001d;J\b\\7DV\u000eP.J\u001b\u0013JZ\n\f1 \\\u0001WD' \u0003>[\u001eXDG\u0016'\tWN\u0012?)$9b\n_\u0002\u0015VKZa+\u000e>L\u0019\rS\u0017^JZS,\u0014.\u0001+,\u0013<)T\u001fVG)\u001f>JDI\u0015]\/+H\u0011.;\u0011W\u0014,S,\u0013[\u001f\u000b`\u0007)\u000e\u00106+^$\rLA@\"\u00184J@3\u001eO&CZ^X.D28SL.\u0018\u0015$\u001c\rH\u0018HX\u000f\u0011<\u001dD$;>I\fY&\u0004\u001a`%?\u001f\u0016CD[,\\5$NO+\u0011DN-$=\u0001#\u0006%\f\u0010Y`\"H*-WRY<%P-H+\u001b4T\"Z[<1B*c\u000f_\u0016&B\u0019+_BR$SJc$$*VNL\u0006Y\u0005\n\tJ6\u0012b2E7\u000f :J\u000b\u001c0N6#b>J\u00142Ja7\u001a\u0002@\raG-!\u000e(L\"'`;\b\r`<,\u0001\u0014\u001bJVA\u0010L^6^\t:C9#\r\u0005ZVOC\\13P%A:619+6\u0011[\u00175\u0018@'\u0003B+,:3V\u0016F?=5J-3XM\u0015\u0017\u001bFI\u000b \u001cV\u001c2)'\/+\u0011A1ADZ&K<\u001f)G\u001c=444LWEPO*R\u0016H;\u0014\u00041Y\b\u001a`I\u000e\u0014C;TS\u000f\r\bY^Z1R\"&OO`\u001fDJIC?HKY[R\u001f\u0011\u0003\fAD,)\n'\"\u001f:b\u0004B4L?&\u0016EAV7\u0004\u000f\u001e8\u0013c\rR+>#=\\\u001dU\u0016\u0011\u00053\u00198%D\u001b![L1\u000b#^$6OV\u001ccB2F1;\n\u001b-9H\u00055MD<<\u0013>E%a*\u001e\u0018<\f'!G3a\u0006\u0005Z^\u0004\r]6I!\u0016)\t_ZV\u000b\u0019!\u0010Z(\bb\t\u0015:\u0016)V!8;\u0016)C'\u0015_\u0005*2S#?\u0004\u001a=\f\u0010B\u000ea< &S$+=)TK($74b1B\u001cKLJ5!\u0010\u0018AQ \fPaY*6>F!\u000b^GbC4RK6\r\u0019`\u0015`N 4\t\u0005OD,JU[9=;3;\u0005.\/\b[\u0017\f=T'\u0006R87\u000e]\u001a\u00023.aQJ7&\u0006\u000b1\u0002G-\u001c2\u001b\u001aC\fD%\u0018OS(\u0003M\"Y,\u000fA\/\u0012\"^<9NXR ,J3LP\u0018\u001d\u000b;+2<\u0015*\u0017\u00166#[WI;_OZYS1@Q\u001f\u001d\"\u0018\u001b\u000f\u001c)$\u0013,H$R\u0002\u0002\u0018D70T\u001aM\rF\u0001O\t\/76+bM]IF\/1\u001f.08-O9'A;\f\u0019\\c\u0017\u001d'\"\u0017c]WV\u001cXO0\u0018\tT\u0019_<\u0011\u001e\u001e\u0013\u0003\u000e\/2\u001fc\u0017\u0012&Ac>A\"Y\/L\u000f \u0007U\u0019K0\u0001$\u000f\u000eWD*R@BX!0\u0011,'>\u000f8@\u0015BN;\u0005\u0004'\u0015\u001d\"\u000b@\r\u0010[QJ\u0011[9\\DANTWY+\u000f?\/3U]\u0016Q)\u000bN\u0007[JL\u000f[\"I\u000f\":@0VR,\\K^!=\u000f\u001dIAa\n\u000f\u0019B2\u001b\u000f0*\u001c\u0014F:4\u0005\n6#%#\u0005\u001b0V>\u0016.\u0004S)8D)\u0014\u0006\u001c\u000eA9TW\t'\u0006-J\u0018\u0006VN\f\/L\u001fZcQH;\u0004\u00177,Kb96A\t<#\u000b\u001a0M\u001bI\u0004\u0018!\u0010E\u0011WD\u0016N\u0013NFE$H\u000b\/\fb\u0014\/\rU&\u00173G.\u00130\u000e;\"!E\n)UM5`OI+.\t$^Y\u001a4\u0007\u001a+42^\f\u0006:\u001c\u000e\u001e\fOP]\u0005Q\u0012!\u00194E\nV\u0015^TTX]WKC]P1B)F`6QU\u0013\f`b<94+B`$L<\u0017E\u0002\u0002=I7*T\u0018O\u0002Z+U7*\u001e\t\"8,\u00142M6\bIL*\/_#\rS:LME\u0014_\\ XSS!\u00045T\u001b\u001b@\u001fD)?\b0\/5'\\-W]V\/B4,IW\u0016\u001f:\u000ec+\\GK05\b\u0010%\u001b+\u0014?Ec\u0006\u0017T>>@1\u00074\u0013\u000ea'\u0002.V`K\b\u0019D\u0016J2Qc\tAT$^R^8U^\u0002\u00183\u001e\u0005\u0016LY3*JVY9JG\u000b\u001aB=\u0011\u0013\u00131,A\b\u0012\u0002>\u0002R]\u001e P3\ba\u00156\u00112)O\u0002\tFKBL=H\u0006\u001eb\u0005\u0010\u0014!\u0004+\\2EAJ87\u00189%`YX\\T&>\u0019*Z&R4\u0013\u00172\u0004# R\/?\u0013QE`\u0017TA6*R\u000e\/\u0010N>D-7\u0016\u0002\t\u0013\u001fD6[G_QZG\u0016ATGO$<:]\\=\u0010c\t&Q\u0016\u000b9L\u0012#U7cM\n\t\rU\u001eLVVR6U\u00129\u0001\u000e&\"\u0019Y\u000f\u00125Z\u0017\"UGVV\u0015N32\nA:Q%HF\t\"\u001f:\u0006ZD@6*\u0012\u001a\u000e\u0018C\u000b\u001f\/F@K2 W\u0014-,\u0002\u0019\/V`P?V\tB` 1\u0019\u0019.@[\u001bT#\u0001\u0013\u0002M_\u000f;+.%X7\u0001\u0014]L\u001dR8<\u00130=b@T\"\rL\u0001.%4T-><2H\b\u0014\u0004\u0004SI4KKW\u000eX\u00010DV0A2[+\n\u001a#..\n1Z\u00043EQ^YM\u001e:($\u001b(W\/9\u000f\u0011*\f*)\u0003H\"\u0012L>+\u001fO':W\r^9<\u0004\u00181\u0011^9\u00079V$&Fa\u0017H\u0017c=\u001b\rG\u0010\u0012L 7`\\>\u0012(\"DG:aK\u0005\fT3V=9!#\u0016R!\u000f\u0002\u0010\f3^8\u0015YK\u0013\u0003_*\u0001^L`R\u000eH\u00028;3\u001dM\u0012\u0001\u0018\u0013J>^[I \u000b\u001f:\"\u0003\u0004+\u0013\u0018G\u00124>CZ\u000f\u001d\/O\u0001GHAXaK1G8\bVA\u0001:\u0013HT_\fD\u000bK\u001a\u0004C\/\u0004]\"\u0001:\u001aP8\b[\/\u0015#\u0003\u00131X(+\rWJQ\u001a\u0011'S]]\u0015`\u001aO\u001c\u001c\u0016\u001eBL\u0017Y,5'\b[)L\f_C\u0013J>\u001aB3PTLJ\u000e76:XEK\u000f\\\u0010Q\"\u0003$9\u0013>\u001c=*\u0002\u000e\u000b\u00053C9%+N\u001bP\u0005\u0007MUbAQS *)(?5*`\u001a\u001a\u000e'\u001c\u00116\u0004=\u001f14PN=,I\u00049C\u001cW\u001f\u0010\u0013O:\u0006]!CI\u0014\u000f_V\u0010[X6PX)`P[B_\u0018#%\r\b[B9P\u001c>\u0002\u0006\u0001\u0006A!)\\\u001d\u0019\u0014V9I\u001d>\r_\u0010S1B\u0007\u0011\u0007\f2^\u000bB7#@Y\u0016=\u0014\u000e=b\u000b.S\u0006@'6JUQF.6H8V\u0014T\u000f7\u000e\u0012:\/OG\u0003#\u0019c:7\u001eODGE\u001e53\u0007%T\\b\tOJM1\u000f\u0016MH\u001c1XW`_!O\b8\u0004\",\u0001>_T\u0013\u001eCc5\u0004\u001e#CVC8A*3V\u0004X.a+$'4JB]Z4(\"bU;\u0015!\u001eb2,\u001b\u000bI8\u0015;#O>Y3\n\u001e69KL\u001e\u0007\u0002*(\u0005\u00120\u0014\u0015*FW\u0004C,O\u001b-a\u000f6[$\t<\n8S%\t0 XVD1\u000fRO$\\%6\u0007]8='\u00110\u001fE3U(\u0005L7\u0002Y\f\u001eA\u0004J<\u000b!\b\u0005`\r\u000bR8>\u0007!IM%_\u000727\u00036\u0002\\S\u0014NMaG\"W@\u0012P\u0001\"N\u0007'JV!;'\u0011O%'>\u001b\n\n_$\u0014\u001bSNEI*E6\u0019;\u00053\r9Q.M\u001fX\f1\u0017#B4 \t_`\b\u0018.MBT'\u0016%U\u0017M\u001c@L&N=A<-\u0018=\u000f\/-M\tV2\u0005^1[P\u0001:\u001f7^\t\u0016&=0\u001d\u0010\u0010\u0005&H\u0018)\u001c$P6\u0005+\u0016\/FN\u0012JZR\fW;X\u001d\u001fV\b-LU'(S:0W\u001d\u0019Y0Z\u001eK0\u0007X*\u0007[A\u0016=Q,F`GVY C\u0018ccW*DY\t\u0012\u0011I#\u0002\u0017\u0006^9\u001fQ.K%[`\u0006a\u0010a*\\\u001b\u0014\u0017\\XXOM8E\u0015A\u001bbID?\u0003X`#\u000f;b+a\/\u0016_SK,\u0007\u0017&?\r\u0001\u001fRK(bIZP+%K\u0019IOYNH>\u001b<3&`0\r\u0004D:\u0002D\t\u00144\u001a^\"#L\u0003W^\u0012I\u001c\"'^K\u001cL0C\u0002S\u0006V\u001aQP\u0007WJ=\u0019$`\u0006c\u0012+ FX\u0004aP@\u0019\u001fZ]D\u0015<\\\nJ\bK\u0016;\u0014\u0004*,,YY\u000e\u000b\u0004Y,A.c#M[\t';4'&\u0015\bIO*\u0004\u0010;OC;\u001f5LH\u0003S\u0015?\u001c\u0018'N4\u0013\/6\u0016CQ](9S,9\u001c\r\u001b6\u001f\u001a\u001e\u0014L\r\u001acY`AF\/]Z\u0017\u0003D\rL,$M*\f\r\u0013L\u001a\u0011Z[8\u0002[)ZDC\bFcVU\u000eV:D\u0017Ya>KA0H\u001aB4!(\u0019Q\u001f\u001e\u000f=RQ`V\u000e\u0003@OR\u0019S\/8(\u0013+cYc!G&\u000eZ\u000f^\u0019\u0016\r\u0001Z*\/+\u001a@\u000f\u001f\\a>S'\u0006#D\u0017\u00015:`#K\u001e\\\/_0\u0002\u0010>M\"K\u001e\u0006^]O?R&\r\u0011DD@.(F\u0015!RT\u0004ZQ=\/\\_\u0006S\u0011UU\u0006\u001aY\u001e1Hb,3\u0017\b\\9-\u0017\u0011G0$G\u000736A]VC1+Q0,1'D\t'O'Z>Z\u000e\u0014\u0001\u0006\u001f^I\u000b\u0003=+5\u000eV4EV@)\u0017R`\u0011[)?\u0007\u0006\u0017cH';\u0018@WQ\\,bO=\u0011\u0007\u000fIZF_\u0010ODGRTW\u0016'HV\/W4&\u0016=\/\u000e\u0018cS%\u001f7\u001f?\u0005L6\u0001\nP8\f\\!\b2c=\u0016S*\"\u001a\/8:\fU\u001a`EO#\u0007ZG\u0019&Lb8(\u0004\u0012M\r\\:\u0005a)\u0016QBJ\u0018;\u0019>S\u001a^M:\u001b4\u0003@QA!3\u0014\r\/[%\b\u001cQN?\u001b\\S;5\u00101\f]W$O\u001b\t\u001d:\u0011\u0016YH\u001d=8Q1\u0007H\u0013-ZZ>\u0005(Y%G\/\u00149\u001dYRIN# #\u0019V\/\u001a6>c5&\u001b?ZU42\u000b\u0002>AI\u0015-QQ?\u0014\u001c@WGW\u0001LTGNHS]8S\u0013\"\u000f?0F5\u0006:\u001f\\\u001cE\u000e\t2\u00036 K0 17<]Y^\u000e\u0011J:?\\[G8(49\\\u0004\u0012\u0004\/\u0017\t\u0005\bT:$\u001e\u0006CW\u0016C2*\u001b\u0012L_I\u0003\u0006\u001c\u0006H\u0006' SE^W* \u0015!aUH\u0001V\u0007\u0001\u001eYaV\u0014#B;+)MOZ%[WULMK+`,P\u001e\u000bV]857R_W\u0004\u0002`0\ncA$\u001e\u0014ZWDR(+5CI\u001d*WSJ\u0006[\r4#\u0010VVKLS`4P\u000e\u0018R\u0019LN\u00182\u00055ZZ*JQ^8\tc;ZVA)2]7b\f(?\b4\u0010`$3_K%\u0007.7 2[Q\u0002\u0004P#3\b\r;H\u001dU#3UDK,9=L\u0018\u0016\u0006B\"`%\u001cN\u0001;\u0017\u001d\\\u001aX\u001a\u0011\\,\r1SV\b7\u0010a>VJ\u001d\u001e\u0006$P&\u000f!\nB3\u000e)HY;>\u0006G!K\u000bK\u000f\u0015\u0016F\u000b9\u0017\u0014WV[T\u0011EVK\u0007-[\u001f:4 Z\u0006:N*Q\\7\u001fXGF$\u0007\u001e,'\u0017\u0001U\/JH\u0010ZA 62X\u001c\/W+\u001a\u000bT\u001cO\u001d;IT\u0002%4'TV@IC`]MXCcU$4_0\u00032\u001fX)J_@%\u00043(OV\u0013]1L&;[aX\r_\u000e\u0012\u0019JCG\u0006\u0011\u0005:L\u0012`;\"X1W68N\\A9\"\u001c3\u000b\u001b\u0019=b9I\b(\u0015O\r$\r6\u001cLN\u0018\u001d+G!\u0012\\\u0018]\u0015.Z,\b`=8R\u0007X \/!?H`\u000b[\b\n\u00036EA;\u0015`.\u00067M0\u0019+\"!\u0011>0F \u001a\bc\u000f\u001c(P!\u001c\u001a\u0014\u0019-\u001cG:\u0004\"?\u001c%F\u0005(H\n\u0015\u0019\fS_@R\r+9\"0G[_5T\n\u0013?.?KC\u0010\u000f\/:L\u0018^R\"4\r\\\u000f\u000bZ\fG'[\u0019'F[S1a4\u0016\u0019\u00069\u0016]\u001aR\u00037TN\u0001\u0005\u001c9L\u0006->\\G6\u0011- b\u001dA8\u001d,B.\u0018\u001c\u0001\n\rRWG\u001d\/4\u000f+.9\u0004%!\u0006\/K\u0004\u0017\u0016\u0002P.^#\u001e\"S\u001dQF\u001c\f\u001a>\u0011\u000b6)Z\u001f\u001b>Q\u001b@\u0014E48\u0015\u000f$b\u001d\u001f\u001b.&!K9\u0019S\u001e>0\tG*LTR \t\u000fA-\\W\u001fN\u0001I7\u001aS16\u001f1\u000f\u00141>!\\!\u0017\r]6c0c\u00118\u001f\u0013.0@\\\f'0K9\u0017,\b\u001c\u0013`4>\u0010`\t> -\r&E\u00160S:#X\u00019\u0019\u0015SEP`3@\u0019X\u0019\/a \b\tV\u00186\u001eB&\u0011-\u0015b&\u00102=\u0001A\u000eO! \u0011\u000b=L\u0015G3C,,<3\b\u00134EHI'\u001f2@!<\u00032\u001e\u0006\u001bE\ra\u0002D\"F*\t1\u000e=?\u0011@\u00112P\u0005?-U\u0013!? [7\u001a)_Pc3B\u0018F\u000e.\u0018Y'\u0010\u0012VKV[N+6\u0006G\u001a\f.\u001aOJJQH[\b7\\\t#QE05+\u0011%MH:H\u0018\u000bS+ZB@\u0014\u0013?\u0003`Db,D;3\\;WDH\u0003\r@)Pb39A8\u001f_P\u0003A\u000fH\u0012N\b9?0-D+\u001c\r\u0017AF^$(\u001f8a\u0003F_\u0012!4WbB4\u000b'H'TD\u001d4&(P&]\u0012@*\u001a\/3+H\u0010\u00115GD`8M:JY\u0006Ic\u0016\u0006\u001baS`Q1A\u001fD@\u0018N\\\",*#799.H\u0015\u001d9\u0002+\u000eQ\u0006a8N'Q%\u000b\u000f28\u0011S:G#\u0014]\u001e\u000fZU!^\u001dDLU 7a1\u0011\u0004\u001e\u0014\":\u000f\u0010-,VDLSE\u0011\"X<\u0006=\u0011\u0014&\u001a*'!FQ\u0002!\u001e-Z[95\u0011!\b\u0003\u001f\n-\u0014\u001c)0O$@b:.E\t\u0012!\u000e\u0011\tN\u0004SAC:M\"\u0016cI\\%Y\u00018XTa\u0013cJ2]^\u0010 \u00183!?>\u0003YG\u001ec)\u001b\u001a0\u0001\u0016)aJM\u001f \u0019\u0001M\u0007\u001bAL\u0004G*NC\u0015M\bWH\\c\u0004\u0013A\u0016\f\u0012\/\u001e;,W\u0002\u0003\u001c\u001e\u0012Cc[K\u00018U\u0002NXWG9C\u0006*c\u000e%Y,\u001c0\u0010\u000e\t8\u0005EUM<\u0003P\u0011`\\-T2$<\u001d\u001a\u001c8\u000f?E,\u00136\u001d\u001aG\u0002\\C'\u0004RcQQ\u0004Z\u0016\u000bG<9\u0018\u001c\u001312\u0013@M\u0012?JFH\u0001\"\u0004S\u0018C M\u0015C\u0002J\u0002CA\u0006,$+\u0004BG\u001f\u0005$37\u0004`0#F\u0011\r+\u0005=\r\t\t9\u0007'\u00170D\u0001\t=M\u0006&\f\u0011\\\u001aR\fV=GM\u0005)\u0002\u0011=L?54\u0006#\u0010\u0015\",`\u0003!JW\\4\u000bUPZ*T9aBbA\u0013a&I\b9\u0016KZ\u000f$\u0017QCTB(7MY(\u000bZ\b_8J\u001c0\u0017\u0003\u0019]E((M-1\u0012_\r\/]B`87K<#_\\`\u0004+3\u0010#\u0007V7+_\u001fE\u001d!7]5\u000f+a`;\r\u00124b W\u0018BU<\u0015Tb[\/\/\u000e;O6X\u0004RJ\u000b@7<\u0006\u001f$\r\u000b6%\"@U#.\"H\u0001I+\u001f4R#\u00183#1b_6\u0019T\u001a\u001b*\u000e\u0016\u001fLA9S\u0011$*I'&J6\u0003\u0007]\u0001]?\"CILFK0^'L\u0001K\u001bYUI\u001dT\u001d)BN\u0014\u00169-0I`_IAM\u0013?2-\u0016SN*;\u00190O\u001eH\u0001\b\u0019\u0017W\u000747\/J#\t>Z\u00015\f C\/Z\u0005b\u0005 #A\u0001@\n\u0013\u00014(\u0003DZE02\u0013!3_G+\/O#B\u001d\u0002\u001eFc3\u0004F\u001a>3\u0013O\u001aT3ZO\u00027\u0005(\u0019B^\u0018\u001e7T7M$\u001b\u000b\u0004 \u000fX6\u0016Q\u000f)O7E@:=P\u0007\n\u0018Z!\u0014\bbEA\u0014\u000bD2=&.\u0013\u0014\b^\u0010K0_^VI,AD\u00076N]\u0016?DH<\/SY\tSHD`V:RC\u0010 ;=',!S;\u0018I\t9\u0007[[\u0010bN\u001f\\W,H\u000e2_D72^R\u001c&bC\")PB;.%M=\u00107J\u0006\u0012\\N\u001b:\u0004\u0011ES`6\u0011C\u0003@Z\u00128U$D&V\f\u0019\u00073.\u001bP1B;\u000f-.PG6\u0004``\u001e \r\u0012U'+\bS\u0006\u000bG#\u001cK\u0019P\u0019>3\u0013-G^YH\t\u0005:\u001b>AU_ C\u000eAKFJ\u001e\\IFH!\u000f7H\u0012+\u0010\u00054\u000f\b=D\u001b>:*\u000b\u0012 #%.J8-BH\u0016\u0002\u0018S\u0006\u0010!;Y!<;FU\u0001\u0013Q`\"S2J\u0003G\t\u00050\u0013; \n\u0016\fPD\"0.\u0011Q\u0019DD\u001c)\f\u0018b3IX$(\u001e\u001cR,=\u000fV4V\b\u0006\u0002QRJN\u0015_\u001e(\u0007&=.\/TG\u000b,\b\u0004\u0014&:U*_2Z\u0018KY\u0006\u0015G\u000bN\u001d\u0002([GW\u0014O8\u0002O] 4\u0014\u0016SYA\u0007T.\u001aTW[44*$\u0004\u0001*\u000f-1B-9@\\\u0014\u001f$#\f!\u0007\u0012\f\u001fL\u000b\u0010T1EY\u001b^\"a2J \u000b\u001a.3E\u0006J\u0004,V,\u0003D:Ja\u001dSP(8 )\u0007&\u0005V\u0003\u001a8Ib)>\u000e\u001ec\u0001\u0014\u0006\u0017\u0001Rc\u0014[#\u0005\u0006H\u000b\u00132\u000bCPV#HGR#R.\\\u0013*;_V>O\u00054M\"Wb\u0013?\f\/9+\u0002E\u0004DT\u0018ZL\/\u0007B,3\u0015\r*D\u000e\u0005H\n\u0006Q\u0006*49\u0011[K#Z#\u0019R\u00135E.%3C \u0016\u000bUL\u001f8\b`\u001c\u001a7O\u001aM\u0004!5254\u0018:,H\n1\u0015cZ\/\u0010\u0001\rSF>)&\u001fZ,\u0011\rV\u0004HHV'`\u00113D\u001e63 =N\u0013\u0006a\u00031\u0012\nc3 )OH^a:^\u0017X\tE6&FY\u001dC8]8\u0004\u001aEK\u001aX\u0015E_\u0014\b.\u00191\u0012X\n^a\u001dD\u0011[\f>]-B\u0012\\V,.YS\tW\u0006\u000fVJb^2;\u001c[\bRB%\u00119=H-\u001c!U($?28\u00168Q46\u0003\u0012B>8\u0002\u0014\\\u001cL.3b7\u0006[4HGL\u0006\r&=^\u00021=\u00143\u0002E\b;)8BK\u001d\u0010\u0005>\u0010Y`K\b+I8D\/\u00166\u0004\u0001\\H8-2Dc7S\u0014\n\t#V^c\u000b>(K+\u0010@\u001cP.450\u0014= _4\u0005-\t'X^\u0013\u001bH\u0018?\u001c\u001b\u0017+5\n+S\n)A\u0004$cIB`?\u001d'P\u0017J5@LX2S\/\u0010B\u0010&\n)c:Q-L\u0013\u001e.`@b\\I1SQ\/\u001e)8$V+%G@A!\u0019\u0011c\u0019X\u0012-V]\u000f8X3;Q\u001b\b\n\fI8= !$>.'$\u000b'\u00168\u0013\nV?V\u0011\u0016%\u0018\u0016QD\tH+-#+28\u0001Z\u0002\u0003NF\"U&\u0013`S\u0006-\u001f+\u0005-B7B\u0014U\u0019PWG8&FI 1\u0002D;\u001c8]b\u0012J<\u0002S\u001aDE[)9\u0001#:c\u0013Q_>+O;\u0011 \u001fT\u001f\u001a\u001e\u00078\u000f,R8\u0003&E9\u0005G\bJ\u0013DD,\u0001`\u0014\f1\u0002\u001aQ#L\u001e\u0018\u00113>%\u0016WSF+SF\u001dJ\u0013\u00195=\u000e[9\u0003\u0003:`[\u0010\u001a\u0011\/(B1\u0002P\rU\n\u0006\u0003:\/\\\u0010@EH[\u0001AX>;\f[=.\f;7\n)%\u0017\"\u0012\u00055F^\u000f2?23JMS\r)\u0019!\u001c@\u0014\"\u0003:\u0007\u001cWC\u000e\r2H+\rGALDL\u0015W1+1\u0005G\u001b:\u0001QGM1+VDA>V[\u0002CaQQOY\fOM\u001bU_(?\u0017\u0002\u001eUM>\"\u001b\u001c\u001e:%(]$=\u001a\u0002>9\u001dK;\u0005[X4!\u001bQ\u0013F)\u0002\u0003$1\/,L\u0003\u0005X;V\u0004B\/T!;LN\r6I8\u000b\u001f$Gb\u001b$U\u0016aR\u0015aUZG9FF*U1O\f,\f\u000f\u00029\u0007W:KRbaF\u000ea\u0004\u00021\b <\b\t(c\u001f\u0004@A\u001cN\u0015U)\u0015S'W)JR_\u001fP\u0017\u000bS\u001e:\u00040\u00027a;\u0002''@3!M_\t\u0012<'5\u0012*\u0019WL$[>\u0010DS\u00107bQ2#\u0011'.\u00078$'@S;a\u0007\u0017\u0014!_+5\u0004FZA\u00174\"\u0010S;\u0004Qb7J4c\u0013.G\u001a\u0011_\u0002`BG\u0014Q\b,'\u0002=[\u0003\u001aKKKI3?\u0018\u0001\u0013\"E&)1\u0004:!9$\u0005G^,%\u0010\u001f21[C[\u001b\r_CP\t\u0004$\u001f\u0012 <\b5\u0004>\u001a\u000b\u0001\u0014\u000e'#K8.BK\"GN[5\u0015\u001dR\u0006QX&a^O RQ&M`[3$\u001eD-B\f@7'\"\u0015A#Pa\u0017\rB(\u001b&@\u0013\u000f&\\.0\u0017JO\u001d:%TS\u0006\u0010\u000f9NHGRb8\u001264\u0010\":L\u000b `\u0007O\u0007?H\u0016\u0004=\r.\u001e1W\u0010M3J:\u000f\rTBBEXN2M;J\u0006\u0015Z\u0003\u0006OY=_\u000e\u0016XW\u000f1\u001f\u000bJP\n*\u001a\u000f[\u001bcM,`,\"92BF`;\u0019\u001f\\\u0013N=I.>]\b\u0006C\u0003T\u0010-0\u0018 WL>LGP4$$A\r\\\\>Y\"(WPW\u00027\f+\u0012\u0012'\u0012\"S0cQ%\u0018Q3>29`\u001089\u0016'B\u0007\u0004&\u0001\u0019$3\u0015MA8X\u001a(PDO32RT'<\u001b'C\u0004'\fX\u0014\u000108\/2\u001eEV\u001e N\u000bK9\r0c_3HX\u0012(\u000b\u0015AIBD\u0001C&\ba\u000fG5I\u00037 \/-\u0004^C3D6P^\u001d*Q\u0003b:ZC-^PJ\u0018\b_V\u0014c.c\u00126\u001bZ\u001f=+\u000fEP+!)<'\u001e\u000e4\u001d(\u0014&\u001c.$\u001b=G4\"HIV>N\t\u001cV=)\u0012a\u0005]+\u001f>*]\u001eM\b+<`K<`\\I6\n\r!`E9+\u000f\u0013E.\u000f\u0017`\n&c\f@Y\u0007B\u0013]\u000e\u001d\u0010T1N\u0014\\8V\u0018\u0010\")\u0014*\u0010!T#^Na\rD\u0005\fN._\u001d2\/+M+K2K#4F \u001d\u0019UA80X\u0012L2W@\u0016$RW^4(A\"@WR\u001aBUD;\u0005F\"\t3Y\b4\u0017A0F%\u00197T\u000ec\/$\u001a1A\u001c@\u0003*YF\u001a#\u000b4S.1^H9:-T\u0002\u0003\u0015AQH8)\u0006BbJ\u0007M1%^\rUZK2a\u0003M\u0011&FQ26TZ4N\n92MK\u0014\u001b\u0006=\u001bVcI$G\u0007\u0002\u0016 `_ \u0017-A\u0004\u0002\u00129\u001a.B*K\u0005Y5MM>\u001e\u0019^_RB+P=@\u0014H>M\b\u001a%\u001a<\u0014->\u0007-6>\u000304TX3Xb(\rR\tG[4\u0017\u001fa*(SDKLc[\u000b>HG)\u000f-+\u001b\u0006!P#\u0006'\u001cL\u0014Z\u001dFO_U.Z#?Z)-\u0010@\"G@`]T\u0012\u0006Q2_`\"=\u0001)\u001c \u0012\u001fE2IW\u00064+\u0013%\u0005CO\u001fI3^0\/%:_(J\u0013a\u0011,\u0019\ba6\r`V4Y\f6HY\rC QT+\u001dLa\u0011\u0010;\f,&K''=\u0013PQEM\u0014* \/L]61(G\u0017]E\u000b\u001eB\/\u0018\u0016<&\u0018\u0007<\u001c'$\u0014LT\u001a2B%KAOUXP\u000eca\/AVF\u001d]Q\u0003C\tBA+9\\X\t%\u0006\t:\u0017\u001d]\u0019-\u001d$0@3\u0006\u0010+.:O\u001fN<\u001d\\(H<\u0004\u001f+UG\n= S[\u001c\u001b\t aO`0,G$\b.P\u001a'P\u0013V3=7SG;TTEF \"9\u0015SMY+6W$\u00182ZPR\u001c\r#5\u0011M%\u000b\\!,\u0001>>!Y(O\u0007\u0016J\u0015T\u00107N.\u0007;F\u0005^\u0006b6\u0012c]\u000bQ9;\u001b\\ DUHc,,8%\u0019B\u001d\">]< X5DU3+X6!)+,C\u001b(VT\u0016P\u000b1+R: \n\u0007\u001fc\u0018\u0006 1b\u001d4:?(B\t\u000f:Yc\f.R\u0017E\fW\u0012\"\b\u001f\u000bc\u001dZ\rX6S'))+MI1+R\u0005\u001e\r\u001d.BN+bb\u0010E\u000b\u00012R X$\u001c%K&\u001c!'F:+M^>&\"J?\/\u0016ZH.WKUC\u000e@\fD$;>LC\fD\u001a7'\b\u000e\n?\u0017\u000f\u000b\u0010=\u0018\u0017I\u0006\u0015\u00057D\u0010\u000b3BWCCP4\u0011\bDE:Qc\u001f#$S.'M\u00040ST]4=\n\u000e\u0006\u0007b R*7)\u0016N\u001aE;\u0017:\u0007X\rDK9\bX49Z\u001fb`M_.&H,Q\u0010\u0016\u0010V\u0004\u0005!F\u000709E*#\"7`\u001d8\f\u001b$4_1,:P\u0015\tEaJW\u0005JO3!\u0019\u000b\u0018\"\rL]\u0010$J <#9\u0007!\u001573\u001bX##Y;;\n9W#\u000b\u001a4bC\u00192\u0004<\u001c\u0005\\E\u001b^X\t\u00184X\rR\u0019#(\u0010\\$\u001a>W\u001f]\fP2\u0019V2VS\u0010\u0011\nZ\u0003\u0011D\u0016'_%&\u000fE\u0012\u001f\u001aT\u0018\u001f\u0013_$5\u0017%G'Q\u001f7\u0016\u0017\u001fK\u0005\u000fP4\u0004`9\"&R\u0013Yc?$\u0011PR]\u0014\u00177;,bb31\u0018M`5\u00033\u0004=*16\"K\f\u000fL+](%\rJ3\u0005M\"CI\u0002O\u00151A\u0011C\u001b-]H\u0015_TH\u001c'\"\rE\u0012aCIH6\u0016!M\u0018.2)\u0012\\9\b&7\u000ea\u000e^IVI;\b\u0016\u00123[0\u0011D\u001c\u0003^\u0003&\u00072@8[\u000bZ\u0002[C\u0013\u0018\u0018@\b>9\u000e\u0011\u0002\u001167\/\u0012>\u001dVL\u0004P,\n$\u0017,L8\u0013!5N(a',\u001f\u0017\u0006\u000fT:A^_S\/<_\u0005H\u0011\u000bc^U%&\u000f\u0019\u000f\u001fP.4S3_\u0003\u001d4J\n\f]#)R\u0010\\\u001b\u0015\fW:\u0018A`Q@\u0007\u000e\fM'(4( @\u0010(9B\u000f:T?\u001b&\u0003R\u001dZF^*$\\",
                        "regkey_r": "Cache",
                        "reg_type": 1,
                        "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ett\\Extension\\{223bd3fe-345e-ffae-3c9f-fe62375679e1}\\Cache"
                    },
                    "time": 1587318806.54625,
                    "tid": 2572,
                    "flags": {
                        "reg_type": "REG_SZ"
                    }
                },
                "pid": 1504,
                "type": "call",
                "cid": 977
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegSetValueExA",
                    "return_value": 0,
                    "arguments": {
                        "key_handle": "0x00000160",
                        "value": "6-\n\u001eD\\)\u0004C\u001c!,]\u0013'8& )\u001d_!@\u001f\u001c\u001aQ\u0013TS'A0V\u0004VHQ\u0005@1\u0007Z`,U\u0016\r!\u00193'\u0010+Z\/%\u0014\u001a\u0002\u0012?!>=c?28\u000e\bD\u000e\u001bJ\n9\u0001^.R\u0018]\u0002[H\u0005?\f[\u0005UAa\u0001\u001c\u001fO\u0015ID9\u001f@?+\/Z,[\u001d`!@,\u0001%_2\u000bHU\b0\u0012\u0002\u000f,\/R:+\u000f\u000b4+aMT.)^3,V(\u0010 H_\u0001EZ#@+3M\"1K\u001d\t]@\u0018Y6\u0002\u000fA)>$\/\u0004%\u0010[;=\u0018,00K24]$M2\u001fL\u000b7\u001f\u0007L3\u0006__W\u001fMZO\u0001O&#,\u001e\u0018H\u0005YG\u00187F2\n\r#=\u0002];'!a.W\u0004,\u000e\u0018b3cP3B>XV\r-\r3\u001aJCV\b>\u0006RE,P]<\u0006\t3RE\u001c\r\u00167[\b\u0016B:\u001e4<\u0014\u001c\u0005\u0006J]!!TN[Y\u0001O\u0006\f\u001c #\u0014c\u000eS!-PW4_c@Z<$\u0019\u0018$CH\rVC\\*\u001e'$\u0002\f\u001aI\u001293_X\u000b]&`\"9\u0006\u0001^LW\u0004J23FLZ\fQ\n@\u0003\u00053\r\u0001O*\u00168\u0016^4=T\u0017ZS:O[0H`\u000eZ\u000fU7\t\u001d\b(\u0003bDPM?GJ,[\u0015\u001d\"\r=;\u00051N``6\n\u0018=` ++!D;:Q<_W\u001e\/4XE\u001c)_2$3F\u000e\u0018\f3SSG1\f\u0007)'\u000e\u0019\u0006F&\u001e\u00075Oc:@R\u001c3\u0016!!251\u0019\t\u0001\u0017H\u000785&1S\u001cH\u001c9([\u0003\u001a0\u000f^!\f%?\u0012D\u0014A-\u0001Vb.\u0010\/V\u0002c#\u0011\u0016\u0005\u0019%N\u0011\u001a#%S\u001aM\u0007;:(]\u0004#6)\u0006\u0010:)\u001a.OW\u0005B\u000f:N9\\\u0003868E++]^H\u001dGO7BM\"\u001c_)*1\/$2\\MRJ(\u001d).P\u00060\u0018C\u000e*D9KKN\u001fLFCLMQH\u0018\/MZ);$:6\u00140%828K\u0015\u0014\u0002>6\u0012\u000f65!\u0007#\u0002\u0003 ERO\u0016K\u001c\t`H\u001c^\u0019A\u001dR\u001f\u001c&\b$\u0015\u0018\u001cLP*\nD<#R.`K-bT1K\u001e\u00010DWR_ccW\u001a\u000b\u001f?\u001aJV\u0006\bG_Q0:\u0004\u001cCB\u0014J\/F\u001ba>\u0001\u0011$V\u0004]0\nK[]W@\":'.`$B\"\u0019\fV`66\u0018$00DGIa'?\u0002\u000eRU\u0011a4[U\nE\u0019]>,4G\u001a$\u0017'SR\u001d$M\u001cN\nE$!1\u0010\nEU\u0014\u0010;\u001eM]?b0`\u001f\u0005\u0013b8TV-\u000e-\bV\u001a9=5R\u000fFGM\u0015\u001d-\u0017-[\u000f\u000f\u0002KC b=@QRcA$GZ4\u0011Q\u0015\u0002&LE\u001eE\u0002\u0011\u001d\t?\u0019XK6@+\u001db\u0015\\G6+PQ\f0\u0018:\u000f_?+Q<<[\u0015\u0003KM\u000e]5[\u000b*\u001c\u001aX\u0012\u000f=\u001b\u001dV\u001f\t\u0016'<\/C\u0010\\\u0010>B\u0016J`7\u0015c\u000f!5\u0004\u0002(^\u0015\u000b'@\u00166\u0006\u0004-\u001cB\u0017\u0007O\u0004\u0003\u0017$\u000f\u001e\u0018\u0004(=\u0013+#)\t\u0002\u0013>\u000f@V$^\\\u0006ZSY$\u0013\u0014\u0001?\u0013$*?:\u0005\u001e\"TO\u000e\u001a\f#\u0005\t&\rN]\u000f\u000e\u0003@\u000bZ'[\u0006I;UVF8BH\u0019\u0010%\u0018\u0005F\u001f\u001a]\u001fIB-W(X\u0017+\u001e,\u0013$ 0\u0002#\"LF*B%b$Q%\u0013\t\u00162\bD(-&,\u001a\t\u000bH\u0015\\\u0017.J\u0010\u00147\u0005\u0012F\tY\u001f6A%\u0004\u0005\u0005>\u0018ON(5)*-.=P37;W2\"\u0003cHS1\u0006`JN\u001d%\u0014Ab6\u0010\u0017N$\u001f\u0017\\%6*\u001b+>)\r\u001c\u0017A\u001c(J,5\r%PK9]A]9>\u000e\u0014a\bAG\f27G\u00012B\u0015\u0002(!\t\u0018$\u001f% 9[\u001b@0S(=\u0017\u001d5?\u0002\u000f\u001eEWF\f[\u0011\u001f+aDS\u001d.O\r\u001e\u0019F\u001b`7\u0018;\b\t0\u000eB?LH\u001e\u0018V\u0011\u0003(N\u0013\u0014TW!\u0005\u0012\u00164OQ,HSU\u000bY\baS2#\\)Z\u0002B\u001d\u0001\\!]EL-a,\n$:\u0004^\/\u0011,&,0\u001a^\n\u0019_\u0002?G7bFa\u000e5\nDFD6aK<+B*\/\u0013^>\u000b*\u0012S(:&\n1\f\u0004W\u000f\u001e,Y^_`:\u0017V\u001f\n^EM(*)BQU5\u0018\u0010\u000b\u000e\u001a\u001bY&\u0001BE[N&M\nLF#W0\u001504>\u001a2.1D6\u00036\u0010*<\u0019I\u00015DV\t\u0006X2a\\\u0005@\u001fQ>,\u0012)\u0002\na\f\tI\u000f\u0017S\u0014\u000b$\u000b\"T1;\u0015KEc<]\u0012Q)^Y;SE\u0002^@\u0005\t\u0010\u0015N>9\t\u00119Q:K)A]\u0011\tJ\u0015DCB'KEB\b9\nR'B\u0016@\u0013(N\u0010\u001a+'bPNPW1\u001d\u0010WUQ5\u001b\u001f+-M#LNM\u0016_I\u0014K\u000bV\u000f'.YBX\/PaJ\u0004\u000b\u0013\u0012cTR\u001b\u0006\u0018>\u0011X\u0016a'&\u001f>\u0016\"U\u0010\u0010O\u0013\u001aB\u0005\t94\u000b\u001dE,I\u001dS270W\u0014\/\u0016:\u001e\u0001J.\u000b\u0012\/ \b1b=\u0014^'\u0001I\u00108E6\u001aPQ(O\u001b'`\u0004\/:4`\u0013bQH\u000fW\u0019L\t\u001e\u001dN\u0002K5\u001aJ\u00053*\u0017X\u000fZ\/\u0007\u001b7\u0015\fQG\u000bT5@U7%7\u001c\\>@\u000bO\u0014%9\t]6\u00149c\b\u0015'\u001a,\u0001#?,#P;]\u001fSD!U\u0015P.5\u001d\u001dX2;,\u001c\fJ0.61!0K`M#9K#\u0019`@G_`]^6\u0015DF\r6\u0016G\t\u0014937,V\r\u0010; \u001f\u001ea!`a,\ra@-\u0013\u001aX\u0004\f\u001b\u00064-4),ZP\f\u000b&\u001ec.\u000f\u00016%A\u001e\u0017[\u000e\/\u001e\u001d=*EN\u001bKE05V\rF38)!L$PSTa\u0016&>:\u0001I\u001aL4\u000e\n[a\\[\u0018c\u001dF\n;GW\fL\nb&@Y\u001db9:IT';\u0004)<\u000e+\u0001JWO?4]Y%H\n\u001a 7TL\u0011\u001a4S)+H'::\/NV\u0006\u001b8\u00076(\b\t7:\u000fbY<7P\t\u001e\u001c\u001a\u0018\t\u0011\u0018DQbYFJR$$@V\u0001a_bMOMCX\u00075R.;G\u0004@\u0019Q\u000b)\u0012\n )\u0019\u0019Y`I55T^]\u001d-\"\u001aK\\(D\n\u0015=QY'!b\u001dJ-Y= K#<\u0015\u0001\u0001\u0001\u0017\u001d\u000f@\r?\"(\u001a^[?2\u0002\\\u000e\n+ULE\\ \/K\u0003\f\"=]F\u0010>)J_$\u001750S@\u0001\u0004\u0007\u0014*\u0002\u0018\u0002 H3.0'W1`'\r\u0002I>W&\/SZ] J7%1\u000e3\u001a\u0015\u000f76Zb\u001bK%\n\u0011\u0017]LH\b?8I $5\u001aB0OZ!F\b`\u00157\"\u0017\u0004GF\u0005N\u001e\u000fN\u0004\u00175L\u001e\u0003`X\u0003\u0010\u001e`M8WC=`\u0012@,\u0010%\u000f+\u0014\u0015\f\u001c'T\u0016A_^+\u001c\u0006M(<\u001cT\u0007#\u0018[+Y\u0013<\t,\u0012%8<(\u001d\u0002Y\u0004\u0005BTGR\u0004;;\u0005c\u0006(\u0011XaM\u0007\u0004\u0002\u0018D\u0007*Y\u001fG\fD\"&;\r\u0001\u0017\u0019\u000f.)+1\u0018VJ[\t7\u0016W>G\u0007\u0013R`-\"\u0019MPQRc\u0010P\u0007Z[%\u0018$G G\u001f\u0003C\u0012VD,Q\"\u0004Y\"\u0012[HR)XWY\u0005>=\rH\u0004\u001a\u000b\n\n\u001f\u001bV\u0019B*ZDT0@'?\u0003\u0005S81b\u001b\\JK\u0011\u0004\u0014H\u000e`Y\r+\u001668I\u0011\u0019N\"$\u0016\u001e\u0001\t%C2\u0011VHa\u0016E5\u0010\"4\u0007?>+\u0013\b\u001f\u0003L\u001f$>&c8N\/\u0019\u0001.,\"\r)O\u0014G&,=N\u000f8VY\u001e:\u0005G%(IYY\b[D\u0011C\u001a\"\fZ\u0002b@\u0017\t\u001cM6%\r\u0015EZ2UH\u0016IXE^?Nc\u0019-X\u0006\"F\\PV\u0011F1QN\u001d:38\u0002\u0013\u0019a\u0010]c'\u0017a\u0006\t\u0012\\_\"=\u001c\u0004RK;?c C`.;\u0019\u0019\u001aNM:(=ZCOL'5&+\u0016E\u0004\u0011'Q:\bO@\b^B ]MG>(KZ\u0013U\b@A4\u0016\u0016\u0001\u0019\u0016.\\\u0005G\u001a\u001f<\u0001\u001f)\u0007\u000bW\n7$bI1\u0006\u000eX\u001b;\u000e)D3\u0014B:A>(\u001f\u0006[%\u0006SJ\u001d8\u000fO\u0002.\u001cL\u001e4$\u0006$#SPN\u0003\u000f,\u0006\u0010\u0018a\f:\u0005\f7\u00027J2\/(1,MS&#a*bb%\\_\u0005a0*\u0001S&\u001b R\fQ\u0006QG\u000eP\u0016 UYYIB'[\u001c\u0005\fJ:\u001bIWHRF\u0015\u0006D+\u0018\\I1\u0016\u0019\u0010\u0010-Q\"]\u0001B\t3\u0002\u000b\u0001\u001a=Y0;US\n(\"GQc\u000f5\u0010Q\u0004\u0002.*!^7\t\u001e7\"_\u0019(=_:\">@)[Y[Y\u0019K3+\u00055;@!QG\u000b\u000f\f\u0015\u0002;-\u001dXC-.C<\u0007 G\u001c\u000e'\u0003\u0016)YR!F#\u0018\u0005\u001a\/\u0017\"O:,S_8>\n\r\u0004\u0015\f*S\u0017O%[+\u00166\fZ\u0019\u001b\u0001J2\u0004\u00139+\tS\u001a\u0015Y\u0019a\u0014\n\u001dY\u0004\u0006]]\bSC\u0007\u0018OPE8UY\u001dG$ZT2\u001d\u0004J\u0006W\u000bX#S?\u0005\u0019<\u0002=F0C:^'6\t<\u0010\u0010\t*>`^6\bN6I(VNI\u0019\\Gc[\u0007\u0017G\u0003]&\u000f1-\/_I>E-!6%\u0016D\\\u001c\u0019S!OcP\u0011U,#7\u0005\u001d5&=*QaZ\na\u0005!\t^UE\u0012V6R\u0005=<1.EM1\u0012+\u0011\u0011-;\u0016\u0007\u0011\u0017A\t\u0013BT\u000e#>\u0011G\u00155_\n\u0005LS\u001eN\r\u000e\u0015\u0006NU\u0007,\u001d\u00057\u0018\tA\/X\u000bP\u001f[V\u0003\u0016^D\n=(\f.\\.+\\J\u0017\u0014\u000f^>\u0013,[\u0006*Aa9!\u0006J(\b\u0007\u0010*KYWOR\u0005\u0015.\u0004GP*)\u00104&=aA\u001c+MLKRHacbN#,b\u0017K\u0011Y@\u001aPSO._\nJ\u00038$5\"1\u0002!\u0012=U7\u001d+X\n15\u0006D3K&P\u0003\u0015P\b\u0016\u00016_<\u0006\u001f\u0001ZRbMK\f. \u0002I$U\f<*,I=7W@\u0014GVV\u0005AA\u00171R@ab\u000b\u0005\u0019 \u0012\n\u000f\r =@\"\u001f\b\u0006\nBJL\u001fQE\u001b*\u001c6L\\F9\u0012^N>;`<`JJ<4\u0003S\u0007J\u0012\u000b\u0017I=6\t\rAIZ,\u0017M1&\u0017Y\u001eF\u0018Y\f \u0011a^\r\u000765\u001f-\/I\u0005]:D*\\\r;\u00057\u0018\u001a62\u001c\u001fK\u0015\"\u001a55M\bW.$:?;\u0017\\ a7PM#G\u000341\u001aN9(+F\u001fF@?cb\u001eE \u0006<\u00183G\u00020H5@0D\u001b\u000b[1E\u000e\u001f^%]>P\n\u0013B& &J\u0013\u001c\u001b\"-\u001a%IX\u001cN\u0011HD\u0014OL#B8\u000f8\u001b7\b#N\u0014&*\u001fN\u0004GTP[\b(\u001c[\b@Q&\u001e\/\u0015a.;\u0002C\u000fT\u0016Y\u0017=\u0014#\u0012!a[\u0011PC\u0003\u0001N\u0001O\u001f_'U5[C8\u001c3MM]H\u00040`TL\u001aS.6\f\u001b'-\u001cINB #\b\u00138\u00051\u00037\u000f6W\u0006!D1\u001bHOR$!\rU;%B\u001d_\u000fC+1UXH\u0010*\u001b;\nTV\"\bc\/\\\u0014\u0012\u000e6aG>\u000eG:TKM?\t\n\u0001\b?.2\u000bM?\u001dW<>B>\/A\u0010?!\u000b9J33W!\n\u001c0FUC\u0001a\u0006OV\u000f\u001b2\u0003=?\tb[\u001d)V\u001d\u0005,H\u000e[\u0018\b*8.\u000eCZ\u0015\u0005\u001cO#,\u0016]\bS\b@\u000bYYM\u0002?_V9c\u0006\"\u001d\u00125\n\u0019\"PO*5#\u0012#\u0006\u001eZ\u000baa)JP\u0016=F\u000b0D?^BN\\$I+OD\u0017\\B\u0017\u0001^\fW.\u0014D\u000b+\\\u0010\n\tN\f-%\b4\\E$0D7\u001e\u0010\f\u0017K\u0018)\t\f\u0003'^U9\u0012\/\u0005\u0013@G\u00065V;\tM2c\b\u0002\u0010US&TU\u001f:6=c;S@b-\"C\u0018H+I\u0018P\u00031%5\u000e\fC3AMH\u000f\u001d:\b\u0017S,\u0018V\u0013#\u001a.-D\u0017\u000fE\u0015b\u001e\u0001=52',FY'A8^H'5!EA](\u0007I\u0014L!J\u0015<\u0019H\u0005>II>1IF.6C_*U\u0006S6F\u000eR\u00041\u0019\u0006S\u001f\u0016\u001a\u0017--\u0011_\f>TW\u0011.HX<\u0006\/Wb\u0007)#\u001e\u0001'\u0001*M?\u0019WPB\n-\u001e2:\u001b\u001b\n\u000f\u0007\u001d\u0018JE&b6R\b\u0007[\u001e^\\KY]8W\u001b\u0010\u00146-2CaS6\u0015C\u001d\u0011\u0004X\u0007,\u0019T4\u0018`\u0018%\u001b\r\u0018\u0007\u000e2U8%3\u0015\u00106M?\u0012*\u001eU0`8\u0006\u0011SP)\t\u0006\u0014\u00176N\b\r^4\u0016.\u0003P\u0005R>b\u00033K\u0006\u001dbUIN\u0019\u0001\u0019.OANN\u001d\nQQ\u0006QU<\u0016\u000fBD-]>!\u0019WZSC_W\u0014\f\u0006)\u0007,\u0007H\u001e0\/0$\r\u0017\u0016>@POK\u0003(\r\u001dGa(O\u0004?\u0003\u0014b!#\u0004&]\u000f\u0005T\u0010S>\u0018^E-\u0010\f\\\u001e\u001b5D\u0013PDV3a9[P\u00108\u001fKC:&\u0006\u001315U\u000e\u0001$QB8F@\u0019Z:H\u0014Q0IV\u000fD\u0001]\u000eY \u0019I\u00106\u0004F\u001d\tR#\u0014\u0010\\5\u001b`#1bE\u0010N\u000fS\"\u0014P%937&\u0016GT:\u0019\u0016\u0018\/V\u000e*,\u001b2Z2L'aR<\u0003\\J4\b\u001aLR^\u0004;\u0013C<\u0006S\u001aQ\u0012B;LZ\u001cHX*\u0003\u0005\u0014B\u0018?P =\u0014\u0005\u00199\u000e\u0014`I\u001a\b'\u0019= Y>3b$S+^!=3+F0@\u0013'\u0006I6\u00046\f\u0001.\u0012\u001dNL\\\u00063\u0014\u0013^\u0006\n\u00076\b\\N\u0001S#KO@1\u0010\u001cQ[8Fa\u001cD4\"\u0003:\t\u0018&? >P\u0015%\u0016D\u001d4,2%(+)\u0006\u001b\u0013\u0011`\u0010b\u0010NI\u001a43\n6^!&\u0001%\u0004\bO4\u0003@]:_ c$\u0004-DGDZ\u0006S\u0001GN._\"\u001f..6Z\"!c,\tb\u0002\u0007\u001c1\"\u001d3\u0016Da\u001f\fN\u000fOZ4AK3=; 6\u0002J\u000b\u0016%+\u0018\u0018b3DH>\u0019>\u001eZ>\"7^\u0004_\u0006\u0007\u000e\u0002R\t\u0007>\bQ:F*^A\u00058N,\bb[\u0005\u0012\u0012*_\nYT 7\u0002X6'\u0005\u0002!\u0007_GXc\/;E0@(;3\/)\u001fA[:a\u001e\u0005Z3CcJ>\u0017` \\3?\u0004\u000eP[\u0015\u000f)TD4\u0016\u0016XU)\nb\u0014'KSM\u001b]\u0002VB\u0007`[\u001e\u0017\u0015N`\u0013+E6,9\f\u0016a$$\u0019\u0013E,\u001fW9\u001cVA)UM'c\u000b+\u0001A6L\f,R\/\f(\t \u0017b;!\u001f\u000e;`\u0017;\r\u00134OIN\u0001O\/0-B% P<\u0011\n\u0019\"\b\u0003\u0016%\u0006\u0001\u0011<>V%>* 01+\\Z7\u0001S+\u001a\u001bH.\"`NHF!\u0007\u001cI)L\u0006\u0006L \u00190\u0018PL(L&Nc0R\u0018\u0007:\u0006)@S\u0010?VY\u000e_C\f`\u000bT\u00050'!]'5\u0018\nN..6\u0003F\u0010\t\u001c\u00013= 7\/H\u001d\u001d\u0005Q6EK^&4$\u000e55(M\nI5`4I3V\u0010 !KN\u0012\u0018Y\u0004\u0003\u0013\f\u0011(X\u0002.6\u0002+2\u0010\u001c]Y@$'N-\u0004\u000fV$9%4\u001b0b\u000f\u0011RRP\u0013:2!\u001a2,\u001a\u0012\/\u001eQ'\u0019!a\u00022OJF\u000fD\r\u001b,:6R\u0005\nMKNX\u0005DMb%\u0007\u0011\u0019%\u00051\u0005Ya)%#5B[R\u001d$N\u001c\u0003L\u001c^\u0013?\/\u0018P\u001eOMY\u001b\u0013[C*G\u0005\u0011\u000f\\\u000e`@^\u0014`AZP6\u001e\u000fL35\u0003Z)\t\u0001\u000bUV-L)\u0005Y\u000b3&?bAI\u0011\u0007?NOW\u0016-\u0003Z\u001c=)NB&.\u0016P3S\u0015M>\r`P1\u00124+OR\u00035\u0010#D.\u001cFE+D\r\u001a\u0007BNAb\u0014\u0011\u00168\u0001>__U+_0\u0001\u0019X\u001c,U\fY41HN\u0003T+OR3Z\u0004\u0003\b;!O[\u0011^:@\u0001<-@Z\u001a\u001c!CZ9Y)?\u0019*O\u001a\n=\u0002\u001e5F\u0014\u0018\u0015b\u0006\u000b4\u001c\u001a-LY*b8SIX4\u0018%#*b\u001f&\u0017NW\u0002)2\u000b3\u0012?MTI\u0016\u0002\"D!\u0012$9\u0016ZZ\u001d$\u0019\u0017\"]NK_CI&Z;5)UW\u0001)X&%\u0013\u0019\u001fA\u0014N<>H\";\bUC\u0015\u001eTT\n&0G\u0011bR\u0015\u001f\u0003I>:\u000f-@\u0014?\u000eO&P\u0012'P\u000b@\u000f2\u001c 4\u0005\u0007(`\u000f-K.\u0001\u000f(][R8\r\r(c$Mc$*.\\D\fS\u0011I+:S\u0013a;6*K716K\"F0,\u0005\u0001%O\\;03L:2\"\u0016UC\u001e\f>LR\r\u0004'F\u0015>-&J[\u001f_ $K6GM,YK;\u001b\u0006_!7\u001c:>0`\u0006[=]-\u0016\u001bX\u0002N6\u001fOG53@_\u001f\u0001\u001b\u001b_\u0004\u0005H\u0005\u0015\u000f\u0015NE\u0018K4`8$;1\u0015\u0002*<\\`_PY\u0001=b6\u001f]D\u0005\u001d[!\u00118?V\u000b64U>\r[9\u0013\u0006\u001b\u0016\r\rWM@(\u0004*HKU5]K [()P9\b,L6\u0002\u0015\u0011\u0011Z\u0004F\t7\u0004\u0016\u001c9\u001f#*\f\u000e6*L\u0001P\u00153\u0013\u0017b?\u00014.-Q\u001f&(\u0001\u001f\u0001J\u0018X][ #\u0004\fI\u0017\u0004!\u0014\u001b\u001b\n\u0006\u0007X4A>)[&:WS*\u001d6F)K(\"\u0002\nKQI\u0012X%1\f8]\u001b\u0019&\u001dW? 1:82\u0005\b2a\u000f^J>&JS\n\u0016aPbV7N[9?*P62\u00102\"\u001a>\u0007#Q_ZbOb:J\"4\u001b\u0014\\\u001c=\u0001 '(;.D\u00104,\u0012GU\u0019\u000f5>\u001a\u001eO?\u0003\u0010\u001fI\u0004$IP\r9' \u001fK^\u000bA#X\u0018I& OQ\u001fV4O]\u0018\"cM\b\u0018\u0014Z=\u00152B#*GX(?95;G\u0016:\u0001\tB\u0019:\u00077\tS\/C?BK]\u0002-=\t:&S\u0005P^=<=\u0019\r.\"\u0019Z7'\u001a0\u0012\u0017I+5\\3\u0003\nD\u00030QJbD`7\u001d\u000e\bG\u0003\u000e\u000e?@0,&6\n@\u0013[\rYA$NTBX1Lc8S\u000fM\u0016]\f@\u0012O\u00194\u0001VP,,\u00140Q9Z+@@Y\u0007?\u0012`\u001aH6>PB%\"\u000fB<\u000e\bC$\\D\u001b\u0014\u0004R(\n>\u0012\u001dM@G\u000b?\u0010Z\u000bM\u0005A\u0017MA\u000fObW\n=\u0014'LJ)B,(F3YD 4D\u0012\u0003c\rF\u0010\u0014H\u0003\u001e,^F3\u000f\b5X\u0014\t\u0004cMcc)AU`J.\u0015\u001fbXW >V\u0016!I;\u0013J\"J8\u0005\u000fD&\u000b(\u000f\f\u0003GV\u0019\u0002\u000bX\/ \u001c\nbO\u0017c\u0003&@\bL5$P\u0003M?\u000eN\u0016\u0013\u0013^c\u0011K\u0017\u0010\u0012\bXZ9\u0011\\\rV\u000bW;H\u0012\n\u0007\u0010=ac\u0010G>PAD[_R\u001aA!N\"@URP.V\u0002\tbJ\u0014H)O`S\u0012D<\u001faN:\u00072\u001bYK'<2'1\b3U\u0018_\b [\u0019c4F\u001fX9bbcb.VG\u0018\u0017F\u0016,\u001d\"\u0019#\u000f\u0004*QQS\u001e-\u001b\u00010^ICG4!.\u00079(L\u001bbY\u0013=\u0016S\u0012>\tM\"S Sb!U\u001e\u0005F)?K(\t]\u000f1\r E\u0017\u0012J$\u0004\u0004D\u0005\u0005KH\u0015EU\u000e\u000f8\fYM\/BD\u000f\u001b]\u00063X2(3\":a-%\u0002\u001e\/\u0017$)U$0\/\f&8X*2<\u0002]*[\u000b`5\u0005J4\u0018a%\u00033;\u001e[cMDQ\u001dG\u0011\u001b\u000b\u0013#c\u0005.D1V\rMA\\C\u001f$\"+Q_9@\u00181\u0015';<=6\b?92\/\f\bG\u0004<4\b@\n6*\u0002K7\f O\u001db2H!\u0001SE0]D&>L+7V\u00124:K\u0005@Y'\u0010SZ>\u0003V\u001dU0=_\f\\UQ\/%PB1I\u0002H:(\rTT^^\u000e@!YA\u0011Y_6Ob(`8].\u001b?Vb>T!)2561\\PMZK\u000bO]\u000b&5\u0002CY\u0012\u0005\u001a\u0006\t\fF\u001fbEc5\u0010^[\u0019\u0007\f\u001eMC%\f:\u0015S)\u0011=\r\u0007'\u0005QRa\u0004\u0003\/B8\u0002\u0012a\u000e\u0006$)\\A!98+\u000e\u0006,K =0\u0016J\u000f?01;\u000b\u0016\u0011\u0007WP\t\u000f Cc\n\u0005)_\"%PF\u0013PQ\u0005?\u0002F6%\u001a\u0005NT\u0006N`]Qc(\u0013\r!TQ\n&$\u001dc=(\u0005c\u0019\u001d+K\u001e\u0017aN\u0018E\u0004TV\u0012`T\u0012\t\u000149?\u001c\"\u001d\u001b%@\r]\u000f\u0011O5Q?a\b\u00101\u000b\u0015.(4!J499\u000f5':HR]N@?]@\u001f@\u0011>H\u0004]\u000b\bX\u001b\u000bV)>\u000b1'G@(\n\b,D\u0010b\u000e?1\"9\u0002@\/1@_V\u0005\nHZ\u0018\u00029?\"\u0014!HI94<1VI\r[YI:@bc\/\u0006\t\u0006)\u0017:3(>9;\u001f\u0002\/+;0D\u0006EF+W\u001c\u0006L\u0005aFF\"EW6.\u0014$\u001b^VB^9\u0016=Y]WO\u0013>P\u000f=8\u001eG2;.%\u001a\u0015\u000f@0\u0015\u0017_$\u00019\u001f\u0016R]>\\!\u0003W\u000b\u000b\\b^72\u001dK\u001dU\u0014`*,0\u0015L\u0007L^\u0003`\u001c\u001e!\u0012Z\u001f\f\t'(\u0012.]P-\u000585UEQ;J5,W-\u001f\u001f\f\/\u0016#RK-4@\u0017P\u00173%\u001e+C\u0013W\u0010Y$\f!0W\fO\u0014\r1`\u001c\u0006\u0007\u0005\u000b\u000b-`9#\"S\u000e\/\u001a5c,\u00154H\u001fV7?><\b\u0013B\u0011R\u001f7\u0010)G[\u0011\u0002[#2\u001d;J\b\\7DV\u000eP.J\u001b\u0013JZ\n\f1 \\\u0001WD' \u0003>[\u001eXDG\u0016'\tWN\u0012?)$9b\n_\u0002\u0015VKZa+\u000e>L\u0019\rS\u0017^JZS,\u0014.\u0001+,\u0013<)T\u001fVG)\u001f>JDI\u0015]\/+H\u0011.;\u0011W\u0014,S,\u0013[\u001f\u000b`\u0007)\u000e\u00106+^$\rLA@\"\u00184J@3\u001eO&CZ^X.D28SL.\u0018\u0015$\u001c\rH\u0018HX\u000f\u0011<\u001dD$;>I\fY&\u0004\u001a`%?\u001f\u0016CD[,\\5$NO+\u0011DN-$=\u0001#\u0006%\f\u0010Y`\"H*-WRY<%P-H+\u001b4T\"Z[<1B*c\u000f_\u0016&B\u0019+_BR$SJc$$*VNL\u0006Y\u0005\n\tJ6\u0012b2E7\u000f :J\u000b\u001c0N6#b>J\u00142Ja7\u001a\u0002@\raG-!\u000e(L\"'`;\b\r`<,\u0001\u0014\u001bJVA\u0010L^6^\t:C9#\r\u0005ZVOC\\13P%A:619+6\u0011[\u00175\u0018@'\u0003B+,:3V\u0016F?=5J-3XM\u0015\u0017\u001bFI\u000b \u001cV\u001c2)'\/+\u0011A1ADZ&K<\u001f)G\u001c=444LWEPO*R\u0016H;\u0014\u00041Y\b\u001a`I\u000e\u0014C;TS\u000f\r\bY^Z1R\"&OO`\u001fDJIC?HKY[R\u001f\u0011\u0003\fAD,)\n'\"\u001f:b\u0004B4L?&\u0016EAV7\u0004\u000f\u001e8\u0013c\rR+>#=\\\u001dU\u0016\u0011\u00053\u00198%D\u001b![L1\u000b#^$6OV\u001ccB2F1;\n\u001b-9H\u00055MD<<\u0013>E%a*\u001e\u0018<\f'!G3a\u0006\u0005Z^\u0004\r]6I!\u0016)\t_ZV\u000b\u0019!\u0010Z(\bb\t\u0015:\u0016)V!8;\u0016)C'\u0015_\u0005*2S#?\u0004\u001a=\f\u0010B\u000ea< &S$+=)TK($74b1B\u001cKLJ5!\u0010\u0018AQ \fPaY*6>F!\u000b^GbC4RK6\r\u0019`\u0015`N 4\t\u0005OD,JU[9=;3;\u0005.\/\b[\u0017\f=T'\u0006R87\u000e]\u001a\u00023.aQJ7&\u0006\u000b1\u0002G-\u001c2\u001b\u001aC\fD%\u0018OS(\u0003M\"Y,\u000fA\/\u0012\"^<9NXR ,J3LP\u0018\u001d\u000b;+2<\u0015*\u0017\u00166#[WI;_OZYS1@Q\u001f\u001d\"\u0018\u001b\u000f\u001c)$\u0013,H$R\u0002\u0002\u0018D70T\u001aM\rF\u0001O\t\/76+bM]IF\/1\u001f.08-O9'A;\f\u0019\\c\u0017\u001d'\"\u0017c]WV\u001cXO0\u0018\tT\u0019_<\u0011\u001e\u001e\u0013\u0003\u000e\/2\u001fc\u0017\u0012&Ac>A\"Y\/L\u000f \u0007U\u0019K0\u0001$\u000f\u000eWD*R@BX!0\u0011,'>\u000f8@\u0015BN;\u0005\u0004'\u0015\u001d\"\u000b@\r\u0010[QJ\u0011[9\\DANTWY+\u000f?\/3U]\u0016Q)\u000bN\u0007[JL\u000f[\"I\u000f\":@0VR,\\K^!=\u000f\u001dIAa\n\u000f\u0019B2\u001b\u000f0*\u001c\u0014F:4\u0005\n6#%#\u0005\u001b

Yara

The Yara rules did not detect anything in the file.

Network

{
    "tls": [],
    "udp": [
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 546,
            "time": 3.0778450965881348,
            "dport": 137,
            "sport": 137
        },
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 5226,
            "time": 9.125520944595337,
            "dport": 138,
            "sport": 138
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7070,
            "time": 3.026732921600342,
            "dport": 5355,
            "sport": 51001
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7398,
            "time": 1.0761919021606445,
            "dport": 5355,
            "sport": 53595
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7726,
            "time": 3.0359930992126465,
            "dport": 5355,
            "sport": 53848
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8054,
            "time": 1.697288990020752,
            "dport": 5355,
            "sport": 54255
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8382,
            "time": -0.08486509323120117,
            "dport": 5355,
            "sport": 55314
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 8710,
            "time": 1.6569950580596924,
            "dport": 1900,
            "sport": 1900
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 28120,
            "time": 1.0969159603118896,
            "dport": 3702,
            "sport": 49152
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 36504,
            "time": 3.12549090385437,
            "dport": 1900,
            "sport": 53598
        }
    ],
    "dns_servers": [],
    "http": [],
    "icmp": [],
    "smtp": [],
    "tcp": [],
    "smtp_ex": [],
    "mitm": [],
    "hosts": [],
    "pcap_sha256": "3c66b46abf50f3632af27fb1af0af3bfbaae601bc5680ca65740ae72cbef5c08",
    "dns": [],
    "http_ex": [],
    "domains": [],
    "dead_hosts": [],
    "sorted_pcap_sha256": "0f99e64f8ee1acff2b5f1f429af93c2c7f1637aedd16ff8520f3ffafd4750d61",
    "irc": [],
    "https_ex": []
}

Screenshots

Screenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandbox

Trojan_Guarder.exe removal instructions

The instructions below shows how to remove Trojan_Guarder.exe with help from the FreeFixer removal tool. Basically, you install FreeFixer, scan your computer, check the Trojan_Guarder.exe file for removal, restart your computer and scan it again to verify that Trojan_Guarder.exe has been successfully removed. Here are the removal instructions in more detail:

  1. Start FreeFixer and press the Start Scan button. The scan will finish in approximately five minutes.
    Screenshot of Start Scan button
  2. When the scan is finished, locate Trojan_Guarder.exe in the scan result and tick the checkbox next to the Trojan_Guarder.exe file. Do not check any other file for removal unless you are 100% sure you want to delete it. Tip: Press CTRL-F to open up FreeFixer's search dialog to quickly locate Trojan_Guarder.exe in the scan result.
    Red arrow point on the unwanted file
    c:\downloads\Trojan_Guarder.exe
  3. Scroll down to the bottom of the scan result and press the Fix button. FreeFixer will now delete the Trojan_Guarder.exe file.
    Screenshot of Fix button
  4. Restart your computer.
  5. Start FreeFixer and scan your computer again. If Trojan_Guarder.exe still remains in the scan result, proceed with the next step. If Trojan_Guarder.exe is gone from the scan result you're done.
  6. If Trojan_Guarder.exe still remains in the scan result, check its checkbox again in the scan result and click Fix.
  7. Restart your computer.
  8. Start FreeFixer and scan your computer again. Verify that Trojan_Guarder.exe no longer appear in the scan result.
Please select the option that best describe your thoughts on the removal instructions given above








Hashes [?]

PropertyValue
MD5a80fd05ecc8820f3069a747f3cce5bba
SHA256b0fdc934c7f8c994633e99b9dcee1ccc70e222ee36e38082ad16d23b982a5b47

Error Messages

These are some of the error messages that can appear related to trojan_guarder.exe:

trojan_guarder.exe has encountered a problem and needs to close. We are sorry for the inconvenience.

trojan_guarder.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.

trojan_guarder.exe has stopped working.

End Program - trojan_guarder.exe. This program is not responding.

trojan_guarder.exe is not a valid Win32 application.

trojan_guarder.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.

What will you do with the file?

To help other users, please let us know what you will do with the file:



Comments

Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.

I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.

No comments posted yet.

Leave a reply