What is advisorinstaller.exe?

advisorinstaller.exe is developed by Belarc, Inc. according to the advisorinstaller.exe version information.

advisorinstaller.exe's description is "Belarc Advisor Installer"

advisorinstaller.exe is digitally signed by Belarc, Inc..

advisorinstaller.exe is usually located in the 'c:\users\%USERNAME%\downloads\' folder.

None of the anti-virus scanners at VirusTotal reports anything malicious about advisorinstaller.exe.

If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.

Vendor and version information [?]

The following is the available information on advisorinstaller.exe:

PropertyValue
Company nameBelarc, Inc.
File descriptionBelarc Advisor Installer
Legal copyrightCopyright (c) 2019 Belarc, Inc.
File version9.0.0.0

Here's a screenshot of the file properties when displayed by Windows Explorer:

Company nameBelarc, Inc.
File descriptionBelarc Advisor Installer
Legal copyrightCopyright (c) 2019 Belarc, Inc.
File version9.0.0.0

Digital signatures [?]

advisorinstaller.exe has a valid digital signature.

PropertyValue
Signer nameBelarc, Inc.
Certificate issuer nameSectigo RSA Code Signing CA
Certificate serial number31a5a09d5c225de221b043a233a50e64

VirusTotal report

None of the 68 anti-virus programs at VirusTotal detected the advisorinstaller.exe file.

None of the 68 anti-virus programs detected the advisorinstaller.exe file.

Sandbox Report

The following information was gathered by executing the file inside Cuckoo Sandbox.

Summary

Successfully executed process in sandbox.

Summary

{
    "file_opened": [
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html",
        "C:\\ProgramData",
        "C:\\",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP",
        "C:\\Users\\cuck\\Desktop\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html",
        "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\Desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif",
        "C:\\Windows\\System32\\oleaccrc.dll",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP",
        "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP",
        "C:\\Users\\Public\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP",
        "C:\\Windows\\AppPatch\\sysmain.sdb",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html",
        "C:\\Users\\cuck\\AppData\\Roaming",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_1024.db",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility\\Desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif",
        "C:\\Program Files (x86)",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP",
        "C:\\ProgramData\\Microsoft\\Windows",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_idx.db",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Python 2.7",
        "C:\\Windows\\AppPatch\\pcamain.sdb",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0006.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif",
        "C:\\Users\\Public\\Desktop",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_sr.db",
        "C:\\Program Files (x86)\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP",
        "C:\\Program Files (x86)\\Belarc",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html",
        "C:\\Users\\Public\\Desktop\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html",
        "C:\\Users\\",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP",
        "C:\\Users",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_96.db",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html",
        "C:\\Users\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif",
        "C:\\Users\\cuck",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_256.db",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP",
        "C:\\Users\\cuck\\AppData\\",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Desktop.ini",
        "C:\\Users\\cuck\\AppData",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC\\Desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP",
        "C:\\Users\\cuck\\Desktop",
        "C:\\Users\\cuck\\",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png",
        "C:\\Users\\Public",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html",
        "C:\\ProgramData\\Microsoft",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html",
        "C:\\Program Files (x86)\\",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP",
        "C:\\Windows\\win.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html",
        "C:\\Windows\\System32\\en-US\\wininet.dll.mui",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP",
        "c:\\program files (x86)\\Belarc\\belarcadvisor\\belarcadvisor.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools\\Desktop.ini",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP"
    ],
    "regkey_opened": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\DnsClient",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\BELARC~1.EXE",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D0CBB37A94C46943A90AC5008CF1CC9",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0F4DC93AAA8AD1D448BC4E6A207F4FE0",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\ddeexec",
        "HKEY_CLASSES_ROOT\\CLSID",
        "HKEY_CLASSES_ROOT\\Outlook.Application.12",
        "HKEY_CLASSES_ROOT\\Outlook.Application.11",
        "HKEY_CLASSES_ROOT\\Outlook.Application.10",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0EF52818FCE3E7B488427C1F8266654E",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\11E2BA15171FE704B98E7505E58D7749",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1E82F31DC0D05AA4CB291B7BAA23FC8E",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
        "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F356843B045CC0A4BA0D83C1D85AAAFD",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\LSA\\AccessProviders",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A7E9995902A24964C9C5D461E1C86F19",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4486F7CE8F022FB4EB0154C5226C27A0",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
        "HKEY_CURRENT_USER\\Interface",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E429E5BC27530F4786481EC687D9EC9",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0411990C889EE9B47BB0B5D356564877",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CB2182A03B6B11341A1F09A021991CE1",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Control",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PropertyBag",
        "HKEY_CLASSES_ROOT\\.com",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7BF7ABF4D25C03F4582D4BC3082FB208",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Associations",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CF65AB832507EDB4BB357F9D8E0431BD",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9BA984AD4F03E284382FFBB7A68BEE27",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\Software\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B4BBDDC88CEE4DD439E8BB261CE222A8",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\System\\Setup",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3D197E722531D614AB40C182904D9A31",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A558E619ABC4CE5479C1DA5070EFBF81",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\669C9DC1419C0F240B35B36B99AAB50C",
        "HKEY_CLASSES_ROOT\\VoilaXctl.VoilaXctl.1",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E40FDF839772BEB41AC977860DBB4853",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ThumbnailCache",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_CURRENT_USER\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\863CA21BBA4DFCE489FDF96EAB898616",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\1.0",
        "HKEY_CLASSES_ROOT\\.chm",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler",
        "HKEY_CLASSES_ROOT\\VoilaXctl.VoilaXctl",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\Software\\Belarc\\Advisor",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FBEAAA6C37E8AF24B87AAEA0047433BD",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\BELARC~1_RASMANCS",
        "HKEY_CLASSES_ROOT\\.ade",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\(Default)",
        "HKEY_CLASSES_ROOT\\.adp",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-699399860-4089948139-3198924279-1001\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D725CB8E57307E64EB574E04214D8B5F",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18F5DB38C45303843B06B1B5025E4820",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\Progid",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\VersionIndependentProgID",
        "HKEY_CLASSES_ROOT\\Belarc.Computer.Inventory\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C4040CC509FB0DC4886F590DDF6B6132",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F21868A51A175874BB819DCA5FAA40A3",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F41A458014D57E54E8DBD0B0CBC361A2",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9E40FDB6330EBA242A4BD5F4FDD0B803",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E3DAE67887931944BCD7171908FA775",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\965742E8F65116F4BB2CB01341464FA7",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters",
        "HKEY_CLASSES_ROOT\\Belarc.Computer.Inventory",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\335F6F64CD461D9469519574D34757EB",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\17E23EF6C775D324DB90E0E2B7D1CA72",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95EE473833000D6409127D1B85882AC9",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Network\\Location Awareness",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\HELPDIR",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F05C8358C56DAD54BB81D0A11DD52F41",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\895805CC90C04694887EF6BD140A622D",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B06071FE021ECB04E8B3BF1E39AD5BB3",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8020CF43278B2644190F51544810251E",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\Clsid",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}",
        "HKEY_CLASSES_ROOT\\.cer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D3541DFF9B79C584284E8981624C04CB",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.EXE",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E85E64F0A7FC58E47A87E5AB98A6F2DD",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\belarc",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B1D5EA6004F809D48B117CE563261011",
        "HKEY_CLASSES_ROOT\\.html",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B04950B5EC5C924B8F428B5484A2720",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Logins\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\75B368B60C908BA4E87C31F66B02F3F0",
        "HKEY_CLASSES_ROOT\\Belarc.Computer.Inventory\\DefaultIcon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\ProductOptions",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\DnsCache\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE\\Tracing",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\63B1AF366905AF641BA514CCBAE803C4",
        "HKEY_CLASSES_ROOT\\.cpl",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-699399860-4089948139-3198924279-1001\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\285499F23409ED14FB4A01230F5DFA91",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9F5ED6B416EF0A1448D94799D0FF20BA",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FEB01D34D0F67E4F9CD810B432C1B91",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4514EC211C8947C4B9BA24F353AFFD50",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7814D91294731FF4DBBB840810BEB3BB",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\67C12EF40671B7342A2F990919031A57",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PropertyBag",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B690B72A999998C47B5F93C94A8D43B2",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LanmanWorkstation\\Parameters",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7C0477DE66D1A6749864FCE02A6DCB6C",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32",
        "HKEY_CLASSES_ROOT\\.csh",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\315C767EFC72D8445B1D2D16F72653F0",
        "HKEY_CURRENT_USER\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PropertyBag",
        "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89BBBC8A0D32B014696C4BA3C20CDD34",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9DD74C0626DC33C479C1929714AB5295",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Associations",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\53F08364FFD17F14B8FD7CA7F52FAE76",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\ShellEx\\IconHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A0256FF64030E0746A4AA95D3FFD0BE4",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D04063BE69797D4D8505462827A0D19",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\DropTarget",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\73964AA699D5B5140ADC41ED3F7DB38A",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9753E3A35E3BDFB468DF95B5D19C8A04",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Sharing",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PropertyBag",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StuckRects2",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AD21E12039BB3BC47B1938BC4ABDFEE2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\(Default)",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\034A8F8E06031EF46BCB4C10469098E5",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84BBAC70FB00B6046881B55CB3122F0F",
        "HKEY_CURRENT_USER\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OleAut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\CurVer",
        "HKEY_CLASSES_ROOT\\.bat",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E116C831A95AB5B4787CE3086FE83631",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D5FD8239A83FE564F97379EA15CE8CB6",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING",
        "HKEY_CLASSES_ROOT\\.asp",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_INCLUDE_PORT_IN_SPN_KB908209",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}",
        "HKEY_CLASSES_ROOT\\exefile",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7636A94AA21EDBB48B6AFFB17E5907B8",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\BELARC~1.EXE",
        "HKEY_CLASSES_ROOT\\.html\\OpenWithProgids",
        "HKEY_CLASSES_ROOT\\.cmd",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
        "HKEY_CLASSES_ROOT\\FirefoxHTML-E7CF176E110C211B",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ToolboxBitmap32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\BE0BD5097A638224EB0DAAE870267F03",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B5C8B2FB95B57147954C18085D53ACE",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\040E2A370D6DB2F45AE45A0032BC2179",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\30FAECE2400494D4FB69207288EB5B73",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\FLAGS",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\87C48B95924E3294FBC1766C9225DD0C",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\OpenWithProgids",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\33AB3CD4D27277545B5A93CD4ECB96B4",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus\\1",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FE547D6F0D72534A80F89C4AB727618",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89DF671CDA74E9D4EB10275B10D5CF3F",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9D22CD4619F5DBC499A083AAD70FE7B3",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_CURRENT_USER\\Software\\Belarc",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CE5B971A0DBB8FD4F83AE0DADC348104",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LanmanServer\\DefaultSecurity",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\shell\\open",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\Clsid",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\InprocServer32",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Wpad",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0A191B45599EEB74CA305184EA3C2A94",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\(Default)",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\System\\DNSClient",
        "HKEY_CURRENT_USER\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Programmable",
        "HKEY_CURRENT_USER\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\04C56B5D827A9194FA2CBFD014EAD0DA",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18D84E9490A485948A17A1F02CDAA62A",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D38A6F5FC8262149A9FAAE8C621EE3F",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95E2C34402A93A14FA8CB3420B85375C",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C1EF68F348457B246A0AD0C18B3079AF",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1C1ED53B8F25FD248955C15232E46886",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\(Default)",
        "HKEY_CLASSES_ROOT\\Outlook.Application",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\AppCompat",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F591EF48DE97A00428A5BC1AFFFAA868",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LDAP",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\Memory Management\\PrefetchParameters",
        "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1A0857155A8EF604FA5D1648CF382DC7",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing",
        "HKEY_CLASSES_ROOT\\.app",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.EXE\\OpenWithProgids",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\2.0",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
        "HKEY_LOCAL_MACHINE\\software\\microsoft\\windows\\currentversion\\setup\\PnpLockdownFiles",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLEAUT",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PropertyBag",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\UserChoice",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}",
        "HKEY_CLASSES_ROOT\\.EXE\\OpenWithProgids",
        "HKEY_CURRENT_USER\\TypeLib",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\CurVer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CLSID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\CLSID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\TreatAs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\ShellEx\\IconHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CDBF699A8F2EAC2438564C3D50E9E638",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PropertyBag",
        "HKEY_CLASSES_ROOT\\.bas",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\103857F24A2EDA54A800A41FA570861F",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\958C4A0DE6C8D5C428C6E9D875BC33B6",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\msasn1",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AE5A0040C41ACA642AF6DB16F4D2F638",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\MS Shell Dlg 2",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\2FA90A429E82313489DAA2E2C2F0872C",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\62293D511DB84E5489074C5AFA18E882",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FF9FDEA72CD9DDC47A6DAB85F9F76B81",
        "HKEY_CLASSES_ROOT\\MIME\\Database\\Content Type\\application\/vnd.belarc-bci",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\Insertable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610",
        "HKEY_LOCAL_MACHINE\\Software\\Classes\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8691BCC36FF121849A90B085BFAF5E5E",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ProgID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE19F224928A59468049F045950CB08",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Connections",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84C584688CFC74A4E9D36E5EE2E02FA7",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CurVer",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE462B32EFD81040A184ED17E00452B",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\296744B7EBFEB2741A47781AE6E32269",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\92F9143E715DEF045A539256438E41FB",
        "HKEY_CLASSES_ROOT\\.EXE",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\16AC40BE991DF1643B2800729063B2F9",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Version",
        "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4626147D107665540A84D43A5908E74D",
        "HKEY_CLASSES_ROOT\\.crt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion",
        "HKEY_CLASSES_ROOT\\SystemFileAssociations\\.EXE",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1\\KnownFolders",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
        "HKEY_CURRENT_USER\\software",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8ECC347096FA78C4E8291F449F71E16E",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FE056816E41FD2F4CACD03E7A2CA2E6E",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid",
        "HKEY_CLASSES_ROOT\\.bci",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FFFA6DF7EA9EDFC45A1F02FE6DF8F067",
        "HKEY_CURRENT_USER\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\ProgIDs\\exefile",
        "HKEY_LOCAL_MACHINE\\NOT_FOUND",
        "HKEY_CLASSES_ROOT\\htmlfile",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
        "HKEY_CURRENT_USER\\SOFTWARE\\Belarc\\Advisor\\Settings",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0\\win32",
        "HKEY_CURRENT_USER\\SOFTWARE\\Belarc\\Advisor\\Prompts",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3C68656E520593A45925ADFB41F821B5",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\90860AAA7BD3DE34EB32330DD29CAD62",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\002F6EFFA8A0A40498F3035BD153685A",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PropertyBag",
        "HKEY_CLASSES_ROOT\\PROTOCOLS",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\Logins",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\BELARC~1.EXE",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\717591555BCB1604BA9777E8A55D0E41",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppCompat",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0FD387D006FD9734FA65B249F36DE42A",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\EEF8AA9EB45B5DB4BBE46B8634C910CD",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
    ],
    "fetches_url": [
        "https:\/\/www.belarc.com\/Programs\/defs.xml?dv=2019.11.14.2&av=9.0&df=B&au=1.0.0"
    ],
    "guid": [
        "{fdada2fa-894d-47d8-ae78-adf1fd7f28df}",
        "{00000003-0000-0000-c000-000000000046}",
        "{49f371e1-8c5c-4d9c-9a3b-54a6827f513c}",
        "{a4341687-7593-47aa-9554-4b0ffc8b2214}",
        "{00021401-0000-0000-c000-000000000046}",
        "{688c934d-0c26-40f6-8d29-d56d72c76b48}",
        "{c0a6c367-c264-4385-a704-9088bdc3640e}",
        "{b2952b16-0e07-4e5a-b993-58c52cb94cae}",
        "{660b90c8-73a9-4b58-8cae-355b7f55341b}",
        "{54410b83-6787-4418-9735-5aaaabe83a9a}",
        "{427fd3d4-f30a-4033-84ef-cbb1a955d9f7}",
        "{dcb00c01-570f-4a9b-8d69-199fdba5723b}",
        "{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
        "{42aedc87-2188-41fd-b9a3-0c966feabec1}",
        "{f6166dad-d3be-4ebd-8419-9b5ead8d0ec7}",
        "{00000000-0000-0000-c000-000000000046}",
        "{1c1800c1-3258-44c2-be80-3deadb6c5e39}",
        "{00000146-0000-0000-c000-000000000046}",
        "{cef04fdf-fe72-11d2-87a5-00c04f6837cf}",
        "{d0074ffd-570f-4a9b-8d69-199fdba5723b}",
        "{76765b11-3f95-4af2-ac9d-ea55d8994f1a}",
        "{79eac9ee-baf9-11ce-8c82-00aa004ba90b}",
        "{6746c347-576b-4f73-9012-cdfeea251bc4}",
        "{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}",
        "{2fb499a3-cfce-480f-a5f3-2453db7a2b7a}",
        "{00000323-0000-0000-c000-000000000046}",
        "{6e682784-1eca-4cf2-988d-96b6e89e9a4d}",
        "{75121952-e0d0-43e5-9380-1d80483acf72}",
        "{ab8902b4-09ca-4bb6-b78d-a8f59079a8d5}",
        "{000214ee-0000-0000-c000-000000000046}",
        "{dcb00000-570f-4a9b-8d69-199fdba5723b}",
        "{dc8f8556-efbd-4efa-8b64-bba84b4ecd7f}",
        "{f676c15d-596a-4ce2-8234-33996f445db1}",
        "{a47979d2-c419-11d9-a5b4-001185ad2b89}",
        "{46a6eeff-908e-4dc6-92a6-64be9177b41c}",
        "{50ef4544-ac9f-4a8e-b21b-8a26180db13f}",
        "{edb5f444-cb8d-445a-a523-ec5ab6ea33c7}",
        "{7b8a2d94-0ac9-11d1-896c-00c04fb6bfc4}"
    ],
    "connects_ip": [
        "127.0.0.1"
    ],
    "regkey_written": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\InprocServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\UninstallString",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus\\1\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\Sort",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\Publisher",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Test2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Serial Number",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bci\\Content Type",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupView",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByKey:PID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bci\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayIcon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayVersion",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecision",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Computer ID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\UuidMethod",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CurVer\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\InprocServer32\\ThreadingModel",
        "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts\\License Agreement",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\IconSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\InstallLocation",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\HELPDIR\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Version\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CLSID\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts\\C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\HelpLink",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\LanguageList",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\CLSID\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLUpdateInfo",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\UserStartTime",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StuckRects2\\Settings",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ProgID\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\MaxFileSize",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionTime",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\FLAGS\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Home",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Logins\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\DefaultIcon\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileDirectory",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\GetIpAddress",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadNetworkName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ColInfo",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\ProgramsCache",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByDirection",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\(Default)",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\LastAdvertisement",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\PastIconsStream",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionReason",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\Mode",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\belarc\\CLSID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Downloaded From",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Streams\\Desktop\\TaskbarWinXP",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\belarc\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByKey:FMTID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\FFlags",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableFileTracing",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\IconStreams",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\application\/vnd.belarc-bci\\Extension",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableConsoleTracing",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLInfoAbout",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\ConsoleTracingMask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ToolboxBitmap32\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\ShellBrowser\\ITBar7Layout",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\VersionIndependentProgID\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\LogicalViewMode",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0\\win32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\ShowNtAdminMessage",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileTracingMask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)"
    ],
    "command_line": [
        "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp\" C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll",
        "\"C:\\PROGRA~2\\Belarc\\BELARC~1\\BELARC~1.EXE\" ",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe"
    ],
    "regkey_deleted": [
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupCollapseState",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\2.0",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ItemPos800x600x96(1)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ItemOrder"
    ],
    "mutex": [
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwReaderRefs",
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer",
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer",
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer",
        "Local\\Shell.CMruPidlList",
        "Local\\ZonesLockedCacheCounterMutex",
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer",
        "Local\\ZoneAttributeCacheCounterMutex",
        "IESQMMUTEX_0_208",
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit",
        "Local\\ZonesCacheCounterMutex",
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer",
        "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex"
    ],
    "file_read": [
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\desktop.ini",
        "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif",
        "C:\\Users\\cuck\\Desktop\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\Desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html",
        "C:\\Users\\Public\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp",
        "C:\\Windows\\win.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility\\Desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif",
        "C:\\Program Files (x86)\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html",
        "C:\\Users\\Public\\Desktop\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html",
        "C:\\Users\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC\\Desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools\\Desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll"
    ],
    "regkey_read": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0A191B45599EEB74CA305184EA3C2A94\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\67C12EF40671B7342A2F990919031A57\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\90860AAA7BD3DE34EB32330DD29CAD62\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_PowerButtonAction",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\rhqprqvg.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Erzbgr Qrfxgbc Pbaarpgvba.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InfoTip",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.VagreargRkcybere.Qrsnhyg",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html",
        "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts\\AutoDownloadDefs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Category",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollDelay",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CF65AB832507EDB4BB357F9D8E0431BD\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\safer\\codeidentifiers\\TransparentEnabled",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E85E64F0A7FC58E47A87E5AB98A6F2DD\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Serial Number",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D04063BE69797D4D8505462827A0D19\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Attributes",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\FuncrPbyyrpgbe.yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoProxyDetectType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResource",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Jvaqbjf Sverjnyy jvgu Nqinaprq Frphevgl.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Domain",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableImprovedZoneCheck",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Stream",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Znvagranapr\\Erzbgr Nffvfgnapr.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bat\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zntavsl.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{NN198O3P-PQ8P-7QR1-98Q1-O460S637193O}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\ProfileImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\ProgramFilesDir",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Stream",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\QIQ Znxre\\QIQZnxre.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Qvfx Pyrnahc.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\863CA21BBA4DFCE489FDF96EAB898616\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1E82F31DC0D05AA4CB291B7BAA23FC8E\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B4BBDDC88CEE4DD439E8BB261CE222A8\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClearRecentDocsOnExit",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0411990C889EE9B47BB0B5D356564877\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\Content Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\InProcServer32\\ThreadingModel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResourceType",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\EnableBalloonTips",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D3541DFF9B79C584284E8981624C04CB\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\FavoritesRemovedChanges",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Zngu Vachg Cnary.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InfoTip",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy VFR.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\FavoritesChanges",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Category",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\AppData",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bmp\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\285499F23409ED14FB4A01230F5DFA91\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{53123611-QN37-S8QN-SNP9-03R76QO9Q64Q}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7BF7ABF4D25C03F4582D4BC3082FB208\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\DefaultSecurity\\SrvsvcDefaultShareInfo",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A7E9995902A24964C9C5D461E1C86F19\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8691BCC36FF121849A90B085BFAF5E5E\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy (k86).yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Snk naq Fpna.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B06071FE021ECB04E8B3BF1E39AD5BB3\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\FLAGS\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FE056816E41FD2F4CACD03E7A2CA2E6E\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InitFolderHandler",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.TrggvatFgnegrq",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PreCreate",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\FavccvatGbby.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\Shell Folders\\Common AppData",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_LargeMFUIcons",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Gnfx Fpurqhyre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\Auto Update\\UAS\\UpdateCount",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Category",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\qsethv.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\ArgjbexCebwrpgvba.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\103857F24A2EDA54A800A41FA570861F\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\Public",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{P1P6S8NP-40N3-0S5P-146S-65N9QP70OOO4}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AE5A0040C41ACA642AF6DB16F4D2F638\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\MaxFileSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\freivprf.zfp",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\FavoritesRemovedChanges",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\StartMenu_Balloon_Time",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95E2C34402A93A14FA8CB3420B85375C\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FEB01D34D0F67E4F9CD810B432C1B91\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Personal",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\FolderTypeID",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FF9FDEA72CD9DDC47A6DAB85F9F76B81\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU Size",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Category",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Pnyphyngbe.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalRedirectOnly",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{15067OP1-P5N8-425R-37P6-SN0O891674S9}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\296744B7EBFEB2741A47781AE6E32269\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InitFolderHandler",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.FgvpxlAbgrf",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Downloaded From",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ZrqvnCynlre32",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Jvaqbjf Rkcybere.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\62293D511DB84E5489074C5AFA18E882\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7636A94AA21EDBB48B6AFFB17E5907B8\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\RelativePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Jvaqbjf Rkcybere.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Icon",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8ECC347096FA78C4E8291F449F71E16E\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Icon",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\\JvaqbjfCbjreFuryy\\i1.0\\CbjreFuryy_VFR.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Jvaqbjf CbjreFuryy Zbqhyrf.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\InprocServer32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableFileTracing",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{OQ3S924R-55SO-N1ON-9QR6-O50S9S2460NP}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Favorites",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\MSBulletinVersion",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E429E5BC27530F4786481EC687D9EC9\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9BA984AD4F03E284382FFBB7A68BEE27\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\*",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89DF671CDA74E9D4EB10275B10D5CF3F\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfcnvag.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InitFolderHandler",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\Jvaqbjf Wbheany.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\AlwaysShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\ProfilesDirectory",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParentFolder",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pnyp.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy VFR (k86).yax",
        "HKEY_CURRENT_USER\\Control Panel\\Desktop\\SmoothScroll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Roamable",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewShadow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResource",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Pictures",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5\\TclTk",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Znvagranapr\\Perngr Erpbirel Qvfp.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\895805CC90C04694887EF6BD140A622D\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfen.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemDrive%\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\\rkcybere.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lnk\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Jvaqbjf Zrqvn Cynlre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89BBBC8A0D32B014696C4BA3C20CDD34\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileTracingMask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Nalgvzr Hctenqr.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4626147D107665540A84D43A5908E74D\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features\\DefaultFeature",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Fvqrone.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_MinMFU",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Category",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Flfgrz Gbbyf\\Cevingr Punenpgre Rqvgbe.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4486F7CE8F022FB4EB0154C5226C27A0\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Vagrearg Rkcybere.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParsingName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\qsethv.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F05C8358C56DAD54BB81D0A11DD52F41\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\WMI Timeout",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\BELARC~1.EXE",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonVideo",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zboflap.rkr",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\SNTSearch.dll,-505",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9D22CD4619F5DBC499A083AAD70FE7B3\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9DD74C0626DC33C479C1929714AB5295\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_TrackProgs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\InProcServer32\\InprocServer32",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\FbhaqErpbeqre.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\ProfileImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\002F6EFFA8A0A40498F3035BD153685A\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bci\\Content Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalRedirectOnly",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{374DE290-123F-4565-9164-39C4925E467B}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\ProgramData",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Icon",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\efgehv.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\zvc.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\717591555BCB1604BA9777E8A55D0E41\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\InProcServer32\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\vFPFV Vavgvngbe.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Computer ID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayVersion",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.cer\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\bqopnq32.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResource",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\displayswitch.exe,-320",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_MinMFU",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.com\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9753E3A35E3BDFB468DF95B5D19C8A04\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\R7PS176R110P211O",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\UuidMethod",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayIcon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{Q4N262QQ-PR44-Q105-S36O-9Q77N8PO65N4}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5\\DefaultFeature",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE462B32EFD81040A184ED17E00452B\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\LastDefsCheck",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\GlobalSession",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\HELPDIR\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3C68656E520593A45925ADFB41F821B5\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Description",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Roamable",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\KCF Ivrjre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Vagrearg Rkcybere.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Name",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Programs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalizedName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Zrqvn Cynlre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PreCreate",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jbeqcnq.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4514EC211C8947C4B9BA24F353AFFD50\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\HelpLink",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\GetIpAddress",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\MachineThrottling",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8020CF43278B2644190F51544810251E\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Music",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalRedirectOnly",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Zrqvn Pragre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\RelativePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Video",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A0256FF64030E0746A4AA95D3FFD0BE4\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C4040CC509FB0DC4886F590DDF6B6132\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\MaxFileSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Sharing\\UsersShareName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonMusic",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParentFolder",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfCbjreFuryy\\i1.0\\cbjrefuryy.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0EF52818FCE3E7B488427C1F8266654E\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7C0477DE66D1A6749864FCE02A6DCB6C\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{35786D3C-B075-49b9-88DD-029876E11C01}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0F4DC93AAA8AD1D448BC4E6A207F4FE0\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Roamable",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\erpqvfp.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParsingName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\P:\\Clguba27\\clguba.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\EnableShareDenyNone",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D725CB8E57307E64EB574E04214D8B5F\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\DisableProcessIsolation",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Paint.Picture\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileDirectory",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Punenpgre Znc.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollInterval",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\*",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CE5B971A0DBB8FD4F83AE0DADC348104\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Hostname",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PreCreate",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Startup",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParsingName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalRedirectOnly",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.VagreargRkcybere.64Ovg",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Rirag Ivrjre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NoStaticDefaultVerb",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InfoTip",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\GnoGvc.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.chm\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\FavoritesRemovedChanges",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Icon",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Sversbk.yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Qngn Fbheprf (BQOP).yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\315C767EFC72D8445B1D2D16F72653F0\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{7SR8Q22N-SO1Q-N8OR-01R3-6P8693961R6R}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3D197E722531D614AB40C182904D9A31\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\FuncrPbyyrpgbe.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Security",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\mstsc.exe,-4000",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\ConsoleTracingMask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\HfdefsUrl",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\958C4A0DE6C8D5C428C6E9D875BC33B6\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84C584688CFC74A4E9D36E5EE2E02FA7\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Description",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\qvfcynlfjvgpu.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\lnkfile\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1A0857155A8EF604FA5D1648CF382DC7\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap\\.exe",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParentFolder",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Sversbk.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalRedirectOnly",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Pbzcbarag Freivprf.yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JS.zfp",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\17E23EF6C775D324DB90E0E2B7D1CA72\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InitFolderHandler",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\GnoGvc.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InitFolderHandler",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\MenuUserExpanded",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\UninstallString",
        "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts\\AutoCheckDefs",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\FXSRESM.dll,-114",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfNalgvzrHctenqrHV.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{56784854-C6CB-462B-8169-88E350ACB882}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_NotifyNewApps",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\DelegateExecute",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlot",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\63B1AF366905AF641BA514CCBAE803C4\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Name",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice\\Progid",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1806",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewAlphaSelect",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\Publisher",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flap Pragre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Test2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84BBAC70FB00B6046881B55CB3122F0F\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\RelativePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Vagrearg Rkcybere (64-ovg).yax",
        "HKEY_CURRENT_USER\\.html\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Stream",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Fgvpxl Abgrf.yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JSF.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\040E2A370D6DB2F45AE45A0032BC2179\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B04950B5EC5C924B8F428B5484A2720\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ProductOptions\\ProductType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Description",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pzq.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E40FDF839772BEB41AC977860DBB4853\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Cnvag.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.crt\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Attributes",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Npprffvovyvgl\\Fcrrpu Erpbtavgvba.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Desktop",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\ArgCebw.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FBEAAA6C37E8AF24B87AAEA0047433BD\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Abgrcnq.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\EnableConsoleTracing",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{8NOQ94SO-R7Q6-84N6-N997-P918RQQR0NR5}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\Clguba (pbzznaq yvar).yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Documents",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugHeapFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollInset",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Cresbeznapr Zbavgbe.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\Flags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\53F08364FFD17F14B8FD7CA7F52FAE76\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\\SortOrderIndex",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\Flags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\cevagznantrzrag.zfp",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Paint.Picture\\CLSID\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ErzbgrQrfxgbc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Home",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Fbhaq Erpbeqre.yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\\Orynep\\OrynepNqivfbe\\OrynepNqivfbe.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Category",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\bfx.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_TrackProgs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 6",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Jvaqbjf Rnfl Genafsre Ercbegf.yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\Flags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bas\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Stream",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_LargeMFUIcons",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9F5ED6B416EF0A1448D94799D0FF20BA\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Flfgrz Pbasvthengvba.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\04C56B5D827A9194FA2CBFD014EAD0DA\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Icon",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\puneznc.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLUpdateInfo",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AlwaysShowMenus",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InitFolderHandler",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\PromotedIconCache",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\RelativePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\abgrcnq.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\qvfcynlfjvgpu.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant\\AllowNetworkPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\034A8F8E06031EF46BCB4C10469098E5\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\BELARC~1.EXE",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\NoOplock",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InitFolderHandler",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Favccvat Gbby.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParsingName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\TurnOffSPIAnimations",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParsingName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{P804OON7-SN5S-POS7-8O55-2096R5S972PO}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zvtjvm\\cbfgzvt.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\MEMORY MANAGEMENT\\PrefetchParameters\\EnablePrefetcher",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Cevag Znantrzrag.yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Flfgrz Erfgber.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragDelay",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.cpl\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F356843B045CC0A4BA0D83C1D85AAAFD\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\System.NamespaceCLSID",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Zntavsl.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C1EF68F348457B246A0AD0C18B3079AF\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lnk\\ShellEx\\{BB2E617C-0920-11D1-9A0B-00C04FC2D6C1}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorUseSystemHeap",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Jvaqbjf Wbheany\\Wbheany.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\RelativePath",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\SnippingTool.exe,-15051",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\FavoritesChanges",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F591EF48DE97A00428A5BC1AFFFAA868\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE19F224928A59468049F045950CB08\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\669C9DC1419C0F240B35B36B99AAB50C\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParsingName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\kcfepuij.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\2FA90A429E82313489DAA2E2C2F0872C\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\TaskbarAnimations",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Pbzznaq Cebzcg.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\AlwaysShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonPictures",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParentFolder",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\aneengbe.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResource",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{8NN47365-O2O3-1961-69RO-S866R376O12S}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\87C48B95924E3294FBC1766C9225DD0C\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\92F9143E715DEF045A539256438E41FB\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResourceType",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\Zbqhyr Qbpf.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NeverShowExt",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ZrqvnPragre",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\FolderTypeID",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Gnfx Fpurqhyre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B1D5EA6004F809D48B117CE563261011\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\335F6F64CD461D9469519574D34757EB\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0\\win32\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\\JvaqbjfCbjreFuryy\\i1.0\\cbjrefuryy.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResourceType",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Cache",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Category",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfvasb32.rkr",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F41A458014D57E54E8DBD0B0CBC361A2\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalizedName",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Description",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\ZqFpurq.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\command",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap\\.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\InstallLocation",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResourceType",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Frphevgl Pbasvthengvba Znantrzrag.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7814D91294731FF4DBBB840810BEB3BB\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\OobeFldr.dll,-33056",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FE547D6F0D72534A80F89C4AB727618\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Description",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{QNN168QR-4306-P8OP-8P11-O596240OQQRQ}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\NoWorkingDirectory",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SharedDir",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\33AB3CD4D27277545B5A93CD4ECB96B4\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\*",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B690B72A999998C47B5F93C94A8D43B2\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.cmd\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN\\*",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_PowerButtonAction",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLInfoAbout",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\InheritConsoleHandles",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D0CBB37A94C46943A90AC5008CF1CC9\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\FileTracingMask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E3DAE67887931944BCD7171908FA775\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D5FD8239A83FE564F97379EA15CE8CB6\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfCbjreFuryy\\i1.0\\CbjreFuryy_VFR.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Aneengbe.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\Segoe UI",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InfoTip",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Jvaqbjf AG\\Npprffbevrf\\jbeqcnq.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\CommonFilesDir",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0FD387D006FD9734FA65B249F36DE42A\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\Flags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{OO044OSQ-25O7-2SNN-22N8-6371N93R0456}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E116C831A95AB5B4787CE3086FE83631\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FFFA6DF7EA9EDFC45A1F02FE6DF8F067\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalRedirectOnly",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D38A6F5FC8262149A9FAAE8C621EE3F\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemDrive%\\PROGRA~2\\Belarc\\BELARC~1\\BELARC~1.EXE",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\Flags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A558E619ABC4CE5479C1DA5070EFBF81\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\FileDirectory",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95EE473833000D6409127D1B85882AC9\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\EnableFileTracing",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features\\TclTk",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PublishExpandedPath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Zbovyvgl Pragre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\965742E8F65116F4BB2CB01341464FA7\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\73964AA699D5B5140ADC41ED3F7DB38A\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalizedName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pyrnazte.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Stream",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\StartMenu_Balloon_Time",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Startup",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InfoTip",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_NotifyNewApps",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalizedName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy.yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\P:\\Hfref\\Choyvp\\Qrfxgbc\\Orynep Nqivfbe.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalRedirectOnly",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Ba-Fperra Xrlobneq.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\FolderTypeID",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\freivprf.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-18\\ProfileImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Stream",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Pbzchgre Znantrzrag.yax",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jrypbzr Pragre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\EEF8AA9EB45B5DB4BBE46B8634C910CD\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Jvaqbjf Rnfl Genafsre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AD21E12039BB3BC47B1938BC4ABDFEE2\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18F5DB38C45303843B06B1B5025E4820\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorSystemHeapIsPrivate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\ThreadingModel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\BE0BD5097A638224EB0DAAE870267F03\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\NeverDefault",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AlwaysShowMenus",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\VQYR (Clguba THV).yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CDBF699A8F2EAC2438564C3D50E9E638\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Security_HKLM_only",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DisallowRun",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.asp\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InfoTip",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Zrzbel Qvntabfgvpf Gbby.yax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Parameters\\RpcCacheTimeout",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\vfpfvpcy.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\SetWorkingDirectoryFromTarget",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9E40FDB6330EBA242A4BD5F4FDD0B803\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Flfgrz Vasbezngvba.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\UseOutOfProcHandlerCache",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1806",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\UseInProcHandlerCache",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\16AC40BE991DF1643B2800729063B2F9\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1C1ED53B8F25FD248955C15232E46886\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zvtjvm\\zvtjvm.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableConsoleTracing",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\30FAECE2400494D4FB69207288EB5B73\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfpbasvt.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Orynep Nqivfbe.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\ConsoleTracingMask",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf QIQ Znxre.yax",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CB2182A03B6B11341A1F09A021991CE1\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F21868A51A175874BB819DCA5FAA40A3\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledProcesses\\7914760B",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\XpsRchVw.exe,-102",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B5C8B2FB95B57147954C18085D53ACE\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragMinDist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\RestrictRun",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18D84E9490A485948A17A1F02CDAA62A\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\11E2BA15171FE704B98E7505E58D7749\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Erfbhepr Zbavgbe.yax",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\ShowNtAdminMessage",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\75B368B60C908BA4E87C31F66B02F3F0\\586A8930D8DF3B6489614C37910BFCF5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\RelativePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pbzrkc.zfp"
    ],
    "file_created": [
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP",
        "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLB63F0.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP",
        "C:\\Windows\\System32\\GLBSINST.%$D"
    ],
    "dll_loaded": [
        "C:\\Windows\\system32\\wininet.dll",
        "C:\\Windows\\system32\\sfc.dll",
        "C:\\Windows\\System32\\mswsock.dll",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
        "API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
        "C:\\Windows\\system32\\advapi32.dll",
        "srvcli.dll",
        "apphelp.dll",
        "CRYPT32.dll",
        "DNSAPI.dll",
        "DHCPCSVC.DLL",
        "kernel32.dll",
        "UxTheme.dll",
        "netutils.dll",
        "C:\\Windows\\system32\\ole32.dll",
        "POWRPROF.DLL",
        "dwmapi.dll",
        "C:\\Windows\\system32\\napinsp.dll",
        "CABINET.DLL",
        "imm32.dll",
        "profapi.dll",
        "ntmarta.dll",
        "schannel",
        "API-MS-WIN-Service-Management-L1-1-0.dll",
        "PROPSYS.dll",
        "C:\\Windows\\syswow64\\MSCTF.dll",
        "WININET.dll",
        "slc.dll",
        "KERNEL32.DLL",
        "OLEAUT32.DLL",
        "RASMAN.DLL",
        "comctl32",
        "ole32.dll",
        "C:\\Windows\\system32\\uxtheme.dll",
        "USER32.dll",
        "Comctl32.dll",
        "MPR.dll",
        "API-MS-Win-Security-SDDL-L1-1-0.dll",
        "API-MS-WIN-Service-winsvc-L1-1-0.dll",
        "wintrust.dll",
        "rtutils.dll",
        "IPHLPAPI.DLL",
        "SETUPAPI.dll",
        "C:\\PROGRA~2\\Belarc\\BELARC~1\\System\\NPBelv32.dll",
        "wininet.dll",
        "SHELL32.DLL",
        "C:\\Windows\\system32\\xmllite.dll",
        "OLEAUT32.dll",
        "C:\\Windows\\system32\\pnrpnsp.dll",
        "SHELL32.dll",
        "RPCRT4.dll",
        "C:\\Windows\\System32\\winrnr.dll",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp",
        "SHLWAPI.dll",
        "C:\\Windows\\system32\\NLAapi.dll",
        "ntshrui.dll",
        "RICHED32.DLL",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
        "DEVRTL.dll",
        "C:\\Windows\\SysWOW64\\oleaut32.dll",
        "ADVAPI32.dll",
        "LINKINFO.dll",
        "OLE32.DLL",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll",
        "WS2_32.dll"
    ],
    "file_moved": [
        [
            "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000",
            "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0006.TMP"
        ]
    ],
    "file_written": [
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP",
        "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP"
    ],
    "file_recreated": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp"
    ],
    "directory_created": [
        "C:\\ProgramData",
        "C:\\Users\\cuck\\AppData",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System",
        "C:\\Users\\cuck\\AppData\\Local\\Temp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks",
        "C:\\Users\\Public",
        "C:\\Users\\cuck\\AppData\\Roaming",
        "C:\\ProgramData\\Microsoft",
        "C:\\Users",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer",
        "C:\\Users\\cuck",
        "C:\\Program Files (x86)",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
        "C:\\ProgramData\\Microsoft\\Windows",
        "C:\\Users\\cuck\\AppData\\Local",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft",
        "C:\\Users\\Public\\Desktop",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer",
        "C:\\Program Files (x86)\\Belarc"
    ],
    "file_failed": [
        "C:\\Windows\\winsxs\\FileMaps\\program_files_x86_belarc_belarcadvisor_system_2911269189da9f55.cdf-ms",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html",
        "C:\\Windows\\BAVoilaX.dll",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif",
        "C:\\Windows\\System32\\BAVoilaX.dll",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html",
        "C:\\Users\\cuck\\Desktop\\Belarc Advisor.lnk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html",
        "C:\\cuckoo_2648.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html",
        "C:\\cuckoo_1504.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif",
        "C:\\cuckoo_1788.ini",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAVoilaX.dll",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif",
        "C:\\Windows\\winsxs\\FileMaps\\progra_2_belarc_belarc_1_8c5c07b07cc16182.cdf-ms",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html",
        "C:\\ProgramData\\Microsoft\\desktop.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll"
    ],
    "resolves_host": [
        "wpad",
        "cuckpc",
        "www.belarc.com"
    ],
    "file_deleted": [
        "",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLB63F0.tmp",
        "C:\\Windows\\System32\\GLBSINST.%$D"
    ],
    "file_exists": [
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Temp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP",
        "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP",
        "C:\\Program Files\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BELARC~1.EXE:Zone.Identifier",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html",
        "C:\\Windows\\System32\\propsys.dll",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif",
        "C:\\Python27\\python.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP",
        "C:\\Windows\\SysWOW64\\propsys.dll",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html",
        "C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif",
        "C:\\Program Files (x86)",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0006.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif",
        "C:\\Users\\Public\\Desktop",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP",
        "C:\\cuckoo_2648.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP",
        "C:\\cuckoo_1788.ini",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html",
        "C:\\Users",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP",
        "C:\\Users\\cuck\\Desktop",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP",
        "C:\\Python27\\pythonw.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png",
        "C:\\Users\\Public",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\ThumbCacheToDelete",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP",
        "C:\\cuckoo_1504.ini",
        "C:\\Users\\cuck",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html",
        "C:\\ProgramData\\Microsoft\\Internet Explorer\\Quick Launch",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP"
    ],
    "directory_enumerated": [
        "",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
        "C:\\Windows\\System32\\ras\\*.pbk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif",
        "C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\*.pbk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\*.*",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor2_startup.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif",
        "C:\\Program Files (x86)",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif",
        "C:\\Windows",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html",
        "C:\\Program Files (x86)\\Belarc",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html",
        "C:\\Users",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif",
        "C:\\Users\\cuck",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html",
        "C:\\Users\\cuck\\AppData\\Local",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif",
        "C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\*.pbk",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html",
        "C:\\Windows\\System32\\rundll32.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif",
        "C:\\Users\\cuck\\AppData",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif",
        "C:\\Windows\\System32",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html",
        "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll"
    ]
}

Dropped

[
    {
        "yara": [],
        "sha1": "cd1ba54eb4d66a31ee8197fae9b8fef3b8b97a5d",
        "name": "f8ad2043143cd46e_box+.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\box+.gif",
        "type": "GIF image data, version 89a, 11 x 11",
        "sha256": "f8ad2043143cd46e744c6572dd4e474f770547066a250ad1aeca438d0e10faff",
        "urls": [],
        "crc32": "39748FA4",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f8ad2043143cd46e_box+.gif",
        "ssdeep": null,
        "size": 73,
        "sha512": "5743ca1ffd126925963bd6123f582bc5b0443a961fba566c1db3f0ebaa13f26a3b8bec1e68179cab3ce4232f1a14f52a195fb65ff9fc064534ca02168c01b520",
        "pids": [
            2740
        ],
        "md5": "9aefef94b5264d3df673072cf3e301b1"
    },
    {
        "yara": [],
        "sha1": "1316271497a29063d3dfe47f3839acd60f3d1a2b",
        "name": "e9be840931007239_summarynetworkdriveitemlinux.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarynetworkdriveitemlinux.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "e9be8409310072394bc6f17dcbf5b36f440a37ae47c6b2613a8a4f4d60a8686c",
        "urls": [],
        "crc32": "C4471D32",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e9be840931007239_summarynetworkdriveitemlinux.html",
        "ssdeep": null,
        "size": 241,
        "sha512": "ec314ddd24350a59a51952b1cde34874a5a579f7d0fdd4b786bac49c49bd34690c545ea06e30a2741a1667c1260d13cfd62ffabf953ae3982d8b1bacbc008be7",
        "pids": [
            2740
        ],
        "md5": "679b41769d731f1d3b257f2b3f8559dc"
    },
    {
        "yara": [],
        "sha1": "c3abfb4ad66e1f087f1056d8be9bec6ca09322e9",
        "name": "8c3fd32b00b3d870_box-.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\box-.gif",
        "type": "GIF image data, version 89a, 11 x 11",
        "sha256": "8c3fd32b00b3d870ec37a958070219a65df27101f517f793338e4b73f478a74a",
        "urls": [],
        "crc32": "B40E7D60",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/8c3fd32b00b3d870_box-.gif",
        "ssdeep": null,
        "size": 72,
        "sha512": "c8b0ce281b7708bba114559ba486ddcf4187ac83c1546309fae12d6482e26f5bd3ce9cfcafd9640ace7e03825d44b5343b4fb5028e945773181dc2ee90c2e5c4",
        "pids": [
            2740
        ],
        "md5": "79d1430acc8b3aa2bfe72972268b5966"
    },
    {
        "yara": [],
        "sha1": "81450cfe5d97d92e29acd9df03666fd9fc12e60a",
        "name": "bb12b8b91009bc00_summaryvirtualmachinedetails.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryvirtualmachinedetails.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "bb12b8b91009bc00c1d4edfefe7d9e110487ba5de91191ed379fb9c38594b93b",
        "urls": [],
        "crc32": "D5514ECA",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/bb12b8b91009bc00_summaryvirtualmachinedetails.html",
        "ssdeep": null,
        "size": 470,
        "sha512": "a412a16ea1ce149ce290d620187db0bc658a507bd2d92344df99b4c26d5a0ffcde5a03ff8386b299127a9d1a25cef429db9ee47f360a74c759c91cbd485ddfb3",
        "pids": [
            2740
        ],
        "md5": "7de6fca80c782db5ea6701c3da3f5cfa"
    },
    {
        "yara": [],
        "sha1": "ace9f01ebedd2fa7606e4e46c4d0278d0ac6396a",
        "name": "85e9ed831b0c3786_benchmarknodetails.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarknodetails.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "85e9ed831b0c37864c2e30c1ac22ac654253b7c5a09a698d35250af4e057a31f",
        "urls": [],
        "crc32": "F2F0D111",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/85e9ed831b0c3786_benchmarknodetails.html",
        "ssdeep": null,
        "size": 654,
        "sha512": "ab461ce7e1d37322da567bbb2ae4f2465e0d69f0363ec50da2abde0aa9c4f93ac1313cccc5b8561f21a7137ace7a7a60914f05e6d9076b7fba0f091cb4bac910",
        "pids": [
            2740
        ],
        "md5": "c3055656250552fb5481f97bc59d7529"
    },
    {
        "yara": [],
        "sha1": "bad41a989cb33909bdfd200687d14d79278d5da0",
        "name": "328239cc4b7c9da9_advisor.ico",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\advisor.ico",
        "type": "MS Windows icon resource - 2 icons, 32x32",
        "sha256": "328239cc4b7c9da96dbb7cf387d86958e809eb1c758070f3d8e31eadd212235c",
        "urls": [],
        "crc32": "37CE247A",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/328239cc4b7c9da9_advisor.ico",
        "ssdeep": null,
        "size": 3638,
        "sha512": "79e00e864680c55bf342602d1dbcffdb9d36d484124f3ba661cca743354eab38a58a4d7392b73e4fab591f1378a7ed2e06101cbec273a1b5bf05728385f4e6c5",
        "pids": [
            2740
        ],
        "md5": "dbc017ea686a9ccba18f63db48c57ccf"
    },
    {
        "yara": [],
        "sha1": "8109c256172eac6984fead0cdca8d2bd01d2fcf2",
        "name": "2260ad0937278006_sp_ok.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_ok.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "2260ad093727800628b14f039910de0361f9861a9978473469a915d373313d29",
        "urls": [],
        "crc32": "1EE43177",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/2260ad0937278006_sp_ok.gif",
        "ssdeep": null,
        "size": 102,
        "sha512": "720c0e3b01fdf6725e5088e76c1d63fa69d4ea965489cabe0675adb74d54cac511abaf78320dc244360a7664f5c524f9a8976ed12948bb63a8e58667a32daa7f",
        "pids": [
            2740
        ],
        "md5": "ccaf35ea19f29888b2799375379a2287"
    },
    {
        "yara": [],
        "sha1": "ba9e0e136a43e994236420ae86f7de54fe552b57",
        "name": "db6ea267203e047e_privacy.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\privacy.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "db6ea267203e047ec6cc8cfef48a16f952ddcbe9a4fb4bea239ad0dae50c109b",
        "urls": [
            "http:\/\/www.belarc.com\/Advisor2\/legal_notice.html",
            "http:\/\/www.belarc.com\/ba5.html?B",
            "http:\/\/www.belarc.com\/privacy.html",
            "http:\/\/www.belarc.com\/ctadvisor.html?B"
        ],
        "crc32": "17F7E5F9",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/db6ea267203e047e_privacy.html",
        "ssdeep": null,
        "size": 2379,
        "sha512": "b034ec207813d164ffcb00e953a7c882c18ccb05b1d35c47fc4a3f1d877f4452311d2fca2c6689735670825d56046461fd5b4add6db8daa8dda8e46f89aabd70",
        "pids": [
            2740
        ],
        "md5": "29d5eaba883670efab3e5c2c1bce30d0"
    },
    {
        "yara": [],
        "sha1": "cc930b9bcb9b624798331bfa28abfb6e62df5d97",
        "name": "bbf26c273c6ae6b2_lock.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\lock.gif",
        "type": "GIF image data, version 87a, 13 x 10",
        "sha256": "bbf26c273c6ae6b20492f7beff37b6ec4aa91b1292e563005727484428523241",
        "urls": [],
        "crc32": "5E26BC5F",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/bbf26c273c6ae6b2_lock.gif",
        "ssdeep": null,
        "size": 140,
        "sha512": "fed6c25a14ea3f114ed0fa63074bd78a298e010bb049b724b56447f5ca5cbac30ded7cccc4c1bfc584b777edc024756c91fe9519290ca43dd3dedfb63b093487",
        "pids": [
            2740
        ],
        "md5": "4aede16b3cec0a29066cdd7e1daeeb91"
    },
    {
        "yara": [],
        "sha1": "0cdf49082ef4cdc15f8bcd6ec787cc1b08257edd",
        "name": "408366548e6ca13b_osautoupdateformats.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\osautoupdateformats.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "408366548e6ca13b7db2cbcf8be8ba291bb773e0887f0aa21e168f727c6eba4e",
        "urls": [],
        "crc32": "F0E800A9",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/408366548e6ca13b_osautoupdateformats.html",
        "ssdeep": null,
        "size": 658,
        "sha512": "ad9c65f611753cb0ff9f3191f3cfc2225ac03c89deb3ec6a3160872f6c86bb38b731588ab79e16851a8133d8cae34f2ea28e15ad1f6d9fa48dd1f436512adb27",
        "pids": [
            2740
        ],
        "md5": "9d49bd8f5b2083381efe60b739212c01"
    },
    {
        "yara": [],
        "sha1": "35b69ee49c8d3643f370ca5335d45e4a36d1f1b1",
        "name": "912df781f305ffb9_corner_bl.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\corner_bl.gif",
        "type": "GIF image data, version 89a, 16 x 16",
        "sha256": "912df781f305ffb9367967b941de7cb5ab79cf8011193080fbc6bc36c0855cf8",
        "urls": [],
        "crc32": "47EEBA1F",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/912df781f305ffb9_corner_bl.gif",
        "ssdeep": null,
        "size": 71,
        "sha512": "03f72e344f964649432d27288a8a11943de367671b6d4890fb6fba37dfc3a64c9fc0f757bcde5ca1d38666de0a043f1400881e9e2ea2a2406832fcf27ad61f92",
        "pids": [
            2740
        ],
        "md5": "ed3f3adb2fcb8730320b1a9cbfe3ef7c"
    },
    {
        "yara": [],
        "sha1": "bf76ecbcd819faf9196734ac9244749d00aa6b3b",
        "name": "316b646a9adc7939_securitypanelsu_alert.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelsu_alert.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "316b646a9adc793953786d826394ceac1b8ba1bbfb660c84467858609de0a3f4",
        "urls": [],
        "crc32": "5F8869F4",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/316b646a9adc7939_securitypanelsu_alert.html",
        "ssdeep": null,
        "size": 411,
        "sha512": "46cc26499129e15b756a51bb00f4aa347f98678e93805a181e3300cd3678636bac3514eb1ed1606915408a25ea8f6a74c9f108cf1024684cae33c1456f557cad",
        "pids": [
            2740
        ],
        "md5": "d40804fb0c796dcf2f8b95d759a21d02"
    },
    {
        "yara": [],
        "sha1": "7aed252dc4e235e6f596ed4de19006cc804f40b6",
        "name": "7b536b3e7de1ca42_summaryusbstorage.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryusbstorage.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "7b536b3e7de1ca42bf825c26af98f2ca36ce616690085e949419a907b0579770",
        "urls": [],
        "crc32": "800DED95",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/7b536b3e7de1ca42_summaryusbstorage.html",
        "ssdeep": null,
        "size": 257,
        "sha512": "99d7ce6189702887ea33e057a24cf04ea4784da100acf0a5bb5c8c40900ec529bc142c64b2de4b3591416773ce872cf83929af13a6ce74fe34500d0ac8aa2120",
        "pids": [
            2740
        ],
        "md5": "3914f20325a3a7defc661d0bbbd394e6"
    },
    {
        "yara": [],
        "sha1": "bb82145e86516859dae6d4b3bffb08c727b13c65",
        "name": "49833d2820afb1d7_GLJ5837.tmp",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp",
        "type": "PE32 executable (GUI) Intel 80386, for MS Windows",
        "sha256": "49833d2820afb1d7409dfbd916480f2cdf5787d2e2d94166725beb9064922d5d",
        "urls": [],
        "crc32": "858B906D",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/49833d2820afb1d7_GLJ5837.tmp",
        "ssdeep": null,
        "size": 2560,
        "sha512": "c14b7ec747357c232f9d958b44760e3a018df628291e87de52b8174ccc4ada546eba90a0e70172d1db54feca01b40cd3aeaa61b8a2b6f22d414baad1f62e8e54",
        "pids": [
            2740
        ],
        "md5": "6f608d264503796bebd7cd66b687be92"
    },
    {
        "yara": [],
        "sha1": "4637bff23431d165bdd9ac29a9fba205e3ab807e",
        "name": "ff515c4555dd28d0_summarylogins.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylogins.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "ff515c4555dd28d0628902c3fd4e61bf25b53a25feadda694797387678deffd2",
        "urls": [],
        "crc32": "D19DBB9F",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ff515c4555dd28d0_summarylogins.html",
        "ssdeep": null,
        "size": 71,
        "sha512": "8d816616620663751a639a17041382983309d0a87c1183e22a0abf657ba68538d2f6957c129dec8cd4c7824bdf7c78d4c219febc428a039bcaf2eaf40f0c6414",
        "pids": [
            2740
        ],
        "md5": "e65919ca4ec8330229824c4e52e4a4dd"
    },
    {
        "yara": [],
        "sha1": "8e15bebbdf5faddf7f1c3aaebd0b00a59f4f0550",
        "name": "80323601c0b978a1_shfs2.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\shfs2.gif",
        "type": "GIF image data, version 89a, 13 x 10",
        "sha256": "80323601c0b978a19a87cf755a23d8988398ea3d535b6c439b35f18c9c7114e2",
        "urls": [],
        "crc32": "C5C704FC",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/80323601c0b978a1_shfs2.gif",
        "ssdeep": null,
        "size": 72,
        "sha512": "50c4d4830d5c2a92c281822997028f81d33555f46a02b6be54413e92c303559873252b025b81ca6b5b1ec34150f6f9a12496d15b57c3b23dddc00d2bef8119c3",
        "pids": [
            2740
        ],
        "md5": "3e59f73ddfe472eb2591769e9fac3879"
    },
    {
        "yara": [],
        "sha1": "b106dcca002a19cd84ad795e5d3dd3cc7e62178d",
        "name": "fedde999e79b8451_advisor.bcx",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\security\\advisor.bcx",
        "type": "data",
        "sha256": "fedde999e79b8451cd405a1e395e36e53ad2b3d6144928d7857a03188a8811d4",
        "urls": [],
        "crc32": "7F42744F",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/fedde999e79b8451_advisor.bcx",
        "ssdeep": null,
        "size": 459,
        "sha512": "f051afd51ef47073e01477e3d59f8c684b3a28ab02ae697bfe73c1c7ced82002abed10f9aa783f3d9f2533c2cdbaaa151c32a5bfd06b23be2f0e9567c011ccf7",
        "pids": [
            2740
        ],
        "md5": "5016766a9d608ab1c6d53d454f2a9409"
    },
    {
        "yara": [],
        "sha1": "098bcc45c7e32ba8dd0870c37bb6953a676ff937",
        "name": "d18c054f455f8a2e_securitypanelsu_ok.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelsu_ok.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "d18c054f455f8a2e2b9f01e6614619d442af20f69efd11db62cc2514902672a9",
        "urls": [],
        "crc32": "55EFD95D",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d18c054f455f8a2e_securitypanelsu_ok.html",
        "ssdeep": null,
        "size": 396,
        "sha512": "14f4dccb920dc5ea9fc16645b7bdf59fcacd087159b92b1c821aebedf127f31bc68584bf9c89cbaf0e13b987e9235840e131edfeb6b16e1d3225427dea5cbc37",
        "pids": [
            2740
        ],
        "md5": "4482f0d4dd328d06dbace17e8620ecee"
    },
    {
        "yara": [],
        "sha1": "040c8efec94061ff735d00a4be7a839fb08cfb0c",
        "name": "b1fc0b4b0dbfa982_shfs0.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\shfs0.gif",
        "type": "GIF image data, version 89a, 13 x 10",
        "sha256": "b1fc0b4b0dbfa982a9166dc54c6c55cff01c6eddef42bf58738c03ab3fe8775a",
        "urls": [],
        "crc32": "DC292604",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/b1fc0b4b0dbfa982_shfs0.gif",
        "ssdeep": null,
        "size": 43,
        "sha512": "a12886009b0c48e27acc4fd122f7d4c6abfb235cfbf8eb10fc73fd50e59e8ee37bfc7cc23967506c10569281eb8548bf0990e20574ad14959bf21cd28a630b37",
        "pids": [
            2740
        ],
        "md5": "c2d263df831635d0a9e00505b38d4e59"
    },
    {
        "yara": [],
        "sha1": "84c00e4cd196a2edcbf30a25ecc9283c3e4985e1",
        "name": "746fb2936e6c2f30_corner_br.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\corner_br.gif",
        "type": "GIF image data, version 89a, 16 x 16",
        "sha256": "746fb2936e6c2f30f820742c73c8b890e5cd507e8927189585d72f35f610bad5",
        "urls": [],
        "crc32": "01820616",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/746fb2936e6c2f30_corner_br.gif",
        "ssdeep": null,
        "size": 71,
        "sha512": "e0d7fefb08b8f3cfe851e0bc24a6d2ca295ee498963daee77b93e1381a59d7ca4a63895aa97d05cc9cb1ef6b45c826f9db4a1fb256f584fd59d8a3bebb6bd297",
        "pids": [
            2740
        ],
        "md5": "5d1ac1c75cce09f6a18b7140d90addc0"
    },
    {
        "yara": [],
        "sha1": "0fa0d3f6692f31fdabefb719b0f7a28cbf5d5415",
        "name": "1c574eab5e83ccfe_GLC5826.tmp",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp",
        "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
        "sha256": "1c574eab5e83ccfe5a0bb7b59e028cc5fa2f4e77868051e305d83c709711ff77",
        "urls": [],
        "crc32": "D88E1477",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/1c574eab5e83ccfe_GLC5826.tmp",
        "ssdeep": null,
        "size": 164864,
        "sha512": "d73e3832777341a4176dbd9988002ec94a32f162492e869a8c03d9bb10f1833821f99e15710e9fc103a2820c862cf14a0b990d7c7c09150bb14618a7c93ca5fd",
        "pids": [
            2740
        ],
        "md5": "09e59d00df5d2effd8dd9b30385cb9d2"
    },
    {
        "yara": [],
        "sha1": "37d116f82c927b2a13f788f63df215c8e71ab65a",
        "name": "a286513b56f2766d_sp_s4.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s4.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "a286513b56f2766d304491b869538c8b22c5c10b8b2a9a560d7055f93c4ba814",
        "urls": [],
        "crc32": "D7BD2E79",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/a286513b56f2766d_sp_s4.gif",
        "ssdeep": null,
        "size": 1170,
        "sha512": "a2608ade2ea76899032e644459521cfc232143cff9e010ad16aea5dacfe48d85d11c49754a37d92f4a6b53ccb286a46b7fbc0450436785cccbe01fbe7016b3a5",
        "pids": [
            2740
        ],
        "md5": "b83528fb0d08d33269f23f0c2f83fa2f"
    },
    {
        "yara": [],
        "sha1": "9f027f2b0d3e67a31ee7ea73c7229e277cfb89f1",
        "name": "f87eeefa46d506fe_benchmarksummary.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarksummary.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "f87eeefa46d506fe3cbb2763d30550da630ea6e0b63e1b80bec9fd6f7f43a675",
        "urls": [
            "http:\/\/www.belarc.com\/ctsecurity.html?B"
        ],
        "crc32": "CDBCD5B4",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f87eeefa46d506fe_benchmarksummary.html",
        "ssdeep": null,
        "size": 4607,
        "sha512": "1d8f9ea57b34ca9f47d615cb5a2b0e4a887a2ae664fde0fd607f476c7441e4c05588ba07f7c201f59d8a5b7209c2fc9171ab5065584e4a3a8395ed5b2aa89847",
        "pids": [
            2740
        ],
        "md5": "f4a268e7dff0a093c7bda4cc6612686c"
    },
    {
        "yara": [],
        "sha1": "ac991ffd54ea192d32eff9ed0a4c9c56d305835d",
        "name": "6d69ec3e21200294_securitypanelsu_unknown.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelsu_unknown.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "6d69ec3e21200294efd146354e9d3185772d698d83aa56db235752b33647433d",
        "urls": [],
        "crc32": "7E8437A3",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/6d69ec3e21200294_securitypanelsu_unknown.html",
        "ssdeep": null,
        "size": 416,
        "sha512": "9d1b2ca3a1c91701803679dc9b0bb352d506141b3f7e74edcf46ec3232b06b842157528222778ca019356806af2f66a574aeb66f068b38df87c78f7dd7a727dd",
        "pids": [
            2740
        ],
        "md5": "e18ea5e71e8be06727eefcb038f7c906"
    },
    {
        "yara": [],
        "sha1": "9d29601802ee7bc83518c09fbca94a6ed7a98f03",
        "name": "eae26c02bd9e19bf_sp_s14.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s14.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "eae26c02bd9e19bff8bcbc43396424ec71add32714c47cab8b66a1beaf92997b",
        "urls": [],
        "crc32": "0C85E829",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/eae26c02bd9e19bf_sp_s14.gif",
        "ssdeep": null,
        "size": 1205,
        "sha512": "d9658d97e27581efb34783e181cf6767fe95ceb5b2143d787a75b67d208e286dfeac51f54a51b703950f1f4048cb2f1d3ac02778057d6525d10f930abf683aa5",
        "pids": [
            2740
        ],
        "md5": "3d6085ecb305e83d7965834e1cd9447c"
    },
    {
        "yara": [],
        "sha1": "53a9c158aa76a30b35cb058093478bbf1f5115f7",
        "name": "b62288fb14044b41_antivirusitems.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\antivirusitems.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "b62288fb14044b419c9ec726ea8608f9594aceb895f0db483d5f27bca0e77a13",
        "urls": [],
        "crc32": "5BAB4F2C",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/b62288fb14044b41_antivirusitems.html",
        "ssdeep": null,
        "size": 702,
        "sha512": "a588c45e94bd80384d08d4afd60dd5201ef5649f633fde337c196e6afbbef555eedfa5d89c3380da37f5754901f211a3be56f9b2c2a7e202a0a18864d604c621",
        "pids": [
            2740
        ],
        "md5": "2aeffcc254dd6ca230725d8803fef704"
    },
    {
        "yara": [],
        "sha1": "32fd9f89230e68c0769b9925060646366c182aaa",
        "name": "7281b20fad0368d3_brandlinks.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\brandlinks.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "7281b20fad0368d3abeafaf8a1649f08474f23631978c962663112478dd67b2f",
        "urls": [
            "http:\/\/www.belarc.com\/ba5.html?B",
            "http:\/\/www.belarc.com\/ctadvisor.html?B-saas",
            "http:\/\/www.belarc.com\/ctadvisor.html?B"
        ],
        "crc32": "0022EA1B",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/7281b20fad0368d3_brandlinks.html",
        "ssdeep": null,
        "size": 446,
        "sha512": "104e45430deb19d88fcf8595352531c72c4bce99150dafebfdf39907eea268112b4eb1b900d6cd54dbfbcee782c28532bd038408cfa0e8349f102a2aa50c3e07",
        "pids": [
            2740
        ],
        "md5": "94db17d2ced4c5927f88b2e9744c5c67"
    },
    {
        "yara": [],
        "sha1": "524bdb79fbeaaf1507ebd40869c950037bea2919",
        "name": "2c627929b971a7b6_summaryusbstoragefootnotes.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryusbstoragefootnotes.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "2c627929b971a7b6476a7349b9903625ef51322bf41baf5f0998aa045109fad8",
        "urls": [],
        "crc32": "F91B2225",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/2c627929b971a7b6_summaryusbstoragefootnotes.html",
        "ssdeep": null,
        "size": 171,
        "sha512": "e2b77df82cc62d63736ec334c7d6e9d3dc12bde32a782f67e46cf05d2257c64079df3f826c1ec46bcb2a38a0bca6ee1a2bdc1785643899fa17fed03cd2ad7095",
        "pids": [
            2740
        ],
        "md5": "2198e4dae600fa4d7976b72f37e712e0"
    },
    {
        "yara": [],
        "sha1": "8b3c0c8633f1bb48a55f86874f0217bae7f8b01a",
        "name": "9887a5e64da2a094_sp_s11.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s11.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "9887a5e64da2a094a67bd6a052a7586f9653f1e89d6db413669abf4b6fa55ed8",
        "urls": [],
        "crc32": "A480B424",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/9887a5e64da2a094_sp_s11.gif",
        "ssdeep": null,
        "size": 1195,
        "sha512": "00b9485a45669d42885c287b0626ff199537909dd8e850cb44adffc380965535d12717dedb80bd1cde296d7f042fe1a6d5c6abf1d769592093e4fb605d8ac0bd",
        "pids": [
            2740
        ],
        "md5": "772bd8800d5d137daf717917bec3d62f"
    },
    {
        "yara": [],
        "sha1": "3c9c28fd352015b0e3c2374dd6b3088a9718dad4",
        "name": "e6b90dc03f8c7516_summaryusbstorageitem.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryusbstorageitem.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "e6b90dc03f8c751628a0e6dbe2e0741f094eb106aed32fe99814a7b23b3167ca",
        "urls": [],
        "crc32": "DCE4608A",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e6b90dc03f8c7516_summaryusbstorageitem.html",
        "ssdeep": null,
        "size": 169,
        "sha512": "c024faabba67e1633a97bb621f6b1f2aff3de8be47b2a17eb074abedff5cb761ba3cd7f2170a8e857e221c86d0ccdeebdd18c0d398505690d47d052eec8b2df7",
        "pids": [
            2740
        ],
        "md5": "98d1929d1d65d9945adce328091a86ed"
    },
    {
        "yara": [],
        "sha1": "24c450f0ee635f783e8002ba943c0de7791491d3",
        "name": "d355cec4dcf65568_securitypanelav_ok.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelav_ok.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "d355cec4dcf65568e82c77d555a4b38bf9d466a6b37368cbc244742c52841bb4",
        "urls": [],
        "crc32": "1650227C",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d355cec4dcf65568_securitypanelav_ok.html",
        "ssdeep": null,
        "size": 397,
        "sha512": "3c69be7c06aeefbf9287ce3e211d26451b2d2403605647e851b568fe6ba7527d5d9156e3191017778b498668ff007089d94627e60a18e7fc7afde5911812aa64",
        "pids": [
            2740
        ],
        "md5": "393b4b0eaf81fd669b7bb7f41e39d298"
    },
    {
        "yara": [],
        "sha1": "17e73f95269b712e43279f84af56bac7fd05adda",
        "name": "96b70ccb73625f9b_summarylocaldrives.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylocaldrives.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "96b70ccb73625f9bf1c122cf00ea72ac4a767fa7888e4c6356b378c044609624",
        "urls": [],
        "crc32": "D613EAA2",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/96b70ccb73625f9b_summarylocaldrives.html",
        "ssdeep": null,
        "size": 267,
        "sha512": "d935e7422780494d694b53ec355add1e52add0e012ee21c918a1290a00dafb096e3d0a6e9528055bf3d68f6e8c51db336162635783eb12848ad544fcb3accf08",
        "pids": [
            2740
        ],
        "md5": "3098ea6db32de3fbcaa4fcd58d2a870b"
    },
    {
        "yara": [],
        "sha1": "e9d08afb387c74c5805d02d4b8b9302688ce599b",
        "name": "6e7ecd76b22fd066_sp_s13.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s13.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "6e7ecd76b22fd066329a11e2e1e23f6a6f9e589046456a684b52f54898e3d91a",
        "urls": [],
        "crc32": "F65DDB4A",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/6e7ecd76b22fd066_sp_s13.gif",
        "ssdeep": null,
        "size": 1199,
        "sha512": "a545d6e03c7dc0d3943e79ee14a7326c5754af695ea4ffedff553306da9bfb00cfa0cf2e1cdd8f00e553125cdfb30d1a77575720c7c5e590770728e08a213afa",
        "pids": [
            2740
        ],
        "md5": "a67fce4bc2e6483a6b5d30aa5472a641"
    },
    {
        "yara": [],
        "sha1": "93c094896df3c2af556ec4bb4a3fda6c96dc458c",
        "name": "8b0882bb863686b2_belarcadvisor.exe",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\belarcadvisor.exe",
        "type": "PE32 executable (GUI) Intel 80386, for MS Windows",
        "sha256": "8b0882bb863686b28c0fbc1b982371f632243043055cf0d62dc56cbe72326dc6",
        "urls": [
            "http:\/\/www.usertrust.com1",
            "http:\/\/ocsp.comodoca.com0",
            "http:\/\/crl.usertrust.com\/UTN-USERFirst-Object.crl05",
            "http:\/\/crl.comodoca.com\/COMODORSACertificationAuthority.crl0q",
            "http:\/\/crl.comodoca.com\/COMODORSACodeSigningCA.crl0t",
            "https:\/\/secure.comodo.net\/CPS0C",
            "http:\/\/ocsp.usertrust.com0",
            "http:\/\/crt.comodoca.com\/COMODORSACodeSigningCA.crt0",
            "http:\/\/crt.comodoca.com\/COMODORSAAddTrustCA.crt0"
        ],
        "crc32": "4D26B1EE",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/8b0882bb863686b2_belarcadvisor.exe",
        "ssdeep": null,
        "size": 134824,
        "sha512": "0f2cd2dee6623a57177060f48faca2bc78757aee9150764f4d73172906e668b7e487a12de64a7065b4e948e17438a83c887fa5846b529d00a0e6a96ea9430344",
        "pids": [
            2740
        ],
        "md5": "7b32f61c6410664877fccaac4c810350"
    },
    {
        "yara": [],
        "sha1": "c844e4f897668adf219b6d048ba769a689cfc83f",
        "name": "ba5e9c26700b7ba6_summarylocaldrivesfootnotes.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylocaldrivesfootnotes.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "ba5e9c26700b7ba66c4e0f7aa4a3c76d89ab49a5c9cc5d47d418ac206c52ff40",
        "urls": [],
        "crc32": "D4F1BF5E",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ba5e9c26700b7ba6_summarylocaldrivesfootnotes.html",
        "ssdeep": null,
        "size": 385,
        "sha512": "06a5050658e90a0ac2fbc4cbd6c4cbdbdd89db9806e7b069ea5ff6383d62ad2bbe7a0c925294da86c937a35eaf1bf9fe196ecdf27ded64adebe37ba0d162e4c9",
        "pids": [
            2740
        ],
        "md5": "cd5931793ff7ff983581270bacfadef3"
    },
    {
        "yara": [],
        "sha1": "092e0f5a68ce3b7f0589688ca12db729dfa1bbf2",
        "name": "98faa1c7f95e1b93_no.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\no.gif",
        "type": "GIF image data, version 89a, 10 x 10",
        "sha256": "98faa1c7f95e1b93781263af7552f48652298fe47115cbc64236d2694c16ca51",
        "urls": [],
        "crc32": "F2AB791D",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/98faa1c7f95e1b93_no.gif",
        "ssdeep": null,
        "size": 61,
        "sha512": "e10cd6b09f756f0acf59ac1a94e54347c6b411bbe00c4030e89802b9081726b0e9cc1b16a0139b1b6f4e0648a0bf888a2aa9b1fcc899f055cae47a9294371493",
        "pids": [
            2740
        ],
        "md5": "951b6ed803d9dd6615a064b9c510375d"
    },
    {
        "yara": [],
        "sha1": "044741717d24d750a882ed25d8fa5755d8483dc1",
        "name": "284682a9fd7d1f22_sp_alert.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_alert.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "284682a9fd7d1f2281b850b842de0bdaa3e3238ec0f19827c05b5c0d0f1ced9c",
        "urls": [],
        "crc32": "E17BA28C",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/284682a9fd7d1f22_sp_alert.gif",
        "ssdeep": null,
        "size": 148,
        "sha512": "036ab222b571e338c89b7180831aa68cfe895759970b18ff6ee70109309f1699a600bf1708dd83d93c18bc7bbd1494a0d95df179bc1953a21e15989e701dc1db",
        "pids": [
            2740
        ],
        "md5": "2edb6cff76a0fc1eaaa7500674c67fa8"
    },
    {
        "yara": [],
        "sha1": "25032bcc7e8e9a10060bdcb2ca95a8b4ebeb7554",
        "name": "2307d540f9986c74_summaryusername.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryusername.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "2307d540f9986c740c8e45e61f814e74ddd2f892d56e664acd726f0e68b860a6",
        "urls": [],
        "crc32": "389AB10C",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/2307d540f9986c74_summaryusername.html",
        "ssdeep": null,
        "size": 95,
        "sha512": "b4bf7411adfc649bb2f05adc4fdb61bca12d2527a0f0e91f34ba160a34c26285952e927fd9d5d4b9caafdcce1965ff13a39810097ec978e6c82a1302a61c3fcb",
        "pids": [
            2740
        ],
        "md5": "9d077d7a70da7306bf8353f6af124ea1"
    },
    {
        "yara": [],
        "sha1": "d087235cc220ee1b61ffae9fc336472e36a8e229",
        "name": "729c401d41ea4503_sp_s6.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s6.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "729c401d41ea45039fa04bcd62a87eb31e2b52f120439aaa90271f91a56c7c81",
        "urls": [],
        "crc32": "5AC0AEC0",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/729c401d41ea4503_sp_s6.gif",
        "ssdeep": null,
        "size": 1200,
        "sha512": "5c77f69d8819514d876c76935cc422120e2997dc9f5b7ec31255dd84e9c7cffcda14ca752b66e2e84c22a73809bf45788375497af33ece2ad92832298cf7b122",
        "pids": [
            2740
        ],
        "md5": "f77da2ce3870489f09a93fa9d2f73df2"
    },
    {
        "yara": [],
        "sha1": "dde7e6429029513fc8a2a6f3d213f610592969be",
        "name": "e474dd417221a1e5_sp_s3.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s3.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "e474dd417221a1e56948047fa28711454342231812836726bb34630b5be6bff4",
        "urls": [],
        "crc32": "654A3083",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e474dd417221a1e5_sp_s3.gif",
        "ssdeep": null,
        "size": 1181,
        "sha512": "ef19bfd137a3e898bdb7c1fcc8cc20ed7d5a3eb14eab4e0c514c8d75a2b4060a3d9c5dbdc60ee34603161b2d55b5a59a25fbcb68146c6d1f8c83d06eb7e66142",
        "pids": [
            2740
        ],
        "md5": "f64e613f8f3c9341cb8ec5109e8f71f3"
    },
    {
        "yara": [],
        "sha1": "08acbdd75f69b69bd4bf0b0dd39e8eafce3c3492",
        "name": "762cf68db65598ae_summarydnssuffix.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarydnssuffix.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "762cf68db65598aebcdc2d6e2adcd8bfed122f788d2ef894775dd77f39a91348",
        "urls": [],
        "crc32": "6B58264F",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/762cf68db65598ae_summarydnssuffix.html",
        "ssdeep": null,
        "size": 94,
        "sha512": "e2c26e7fabb81c6c2bddec561f3039195d63d8f4c901e9a837ddc475d7da38a9767cf1542e74bbab6f936ee06146565eb0fd00ff3f61a380582bbd9f667db830",
        "pids": [
            2740
        ],
        "md5": "fe6837c27e02f34810c51a50a7f30d98"
    },
    {
        "yara": [],
        "sha1": "1f0df1bd53a30e8bef5b05189c6ef734d83e90b2",
        "name": "aff420b165422950_summarynetitems.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarynetitems.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "aff420b1654229508f062c71eb3ce479145e2fa16cb4fe9a605b51f283e6d9ca",
        "urls": [],
        "crc32": "C869A5BC",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/aff420b165422950_summarynetitems.html",
        "ssdeep": null,
        "size": 1509,
        "sha512": "ad38a85368b7f604ffbfc6b9173e6687d201e13d180e042af5f5fc2f388310514d640c47660411d8dec4943a0d5e21ebff0e468776e8665bdbf946908f99d0eb",
        "pids": [
            2740
        ],
        "md5": "d944eae9fc656490ba838835c93bd99b"
    },
    {
        "yara": [],
        "sha1": "5dbdd67015cc2f77743f3261330863ab54c77aaf",
        "name": "d177e4729385bcd1_corner_tr.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\corner_tr.gif",
        "type": "GIF image data, version 89a, 16 x 16",
        "sha256": "d177e4729385bcd1027679b704342517ea37fc55b94b61e16a022cbb9f9fbcbd",
        "urls": [],
        "crc32": "FC4720FD",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d177e4729385bcd1_corner_tr.gif",
        "ssdeep": null,
        "size": 72,
        "sha512": "faa94d0a5248b4d910c6cc6c42e8ac2ec0864e33ca69e5a082ce80e4c469393c7b42f0d6abd3227d38367f376f666037228ac048b3d45c87f40ff0b6e6e8bedd",
        "pids": [
            2740
        ],
        "md5": "a3b7431e4ec6e09e23d2fe00558a6137"
    },
    {
        "yara": [],
        "sha1": "ff7692f3fac23efc1ab7b94ca1cba97f92941198",
        "name": "4088f0981eabd7de_scoring.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarks\\scoring.html",
        "type": "exported SGML document, ISO-8859 text, with CRLF line terminators",
        "sha256": "4088f0981eabd7de01d824b75937a2e4174dc00a0fb67dfa860c3257f628518a",
        "urls": [],
        "crc32": "4F634158",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/4088f0981eabd7de_scoring.html",
        "ssdeep": null,
        "size": 774,
        "sha512": "c4be2f7d25c250694cb9bb7c4fe4f44d976e7e4a5c05ff65686a1e842a15eb6a9e4e628cdabc69e4f8f13b4dc525f14289f30876d3eb5306e23d947a90888892",
        "pids": [
            2740
        ],
        "md5": "f2d5840384273ba3da4c45fa9567f07c"
    },
    {
        "yara": [],
        "sha1": "1e04b813edb07aa8c526ceafba3d21f9990aac07",
        "name": "093b69eea436d692_softwarelinkformats.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\softwarelinkformats.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "093b69eea436d6925fea2c32f850376c674f10b8ff49e3451fed7179d4aa14d3",
        "urls": [],
        "crc32": "7A94EB33",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/093b69eea436d692_softwarelinkformats.html",
        "ssdeep": null,
        "size": 2550,
        "sha512": "96f1d09d7ce776b11956b15e23938209f5c80c49790c25111a28c90c8d660455880627e94d99d31a80e88e8a5fc0445242687c64c9707a33f0676875483a2b98",
        "pids": [
            2740
        ],
        "md5": "cd6cb649dce3c8f601410abc1dbd4bc7"
    },
    {
        "yara": [],
        "sha1": "185855351c1ac14c30d3b2bdf5416a011335e58c",
        "name": "92d5ab5230b0d3bb_sp_unknown.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_unknown.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "92d5ab5230b0d3bbc62e5d87e4c182c296aca9812a4856f83dfc512b6838d3a0",
        "urls": [],
        "crc32": "3DD7A90B",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/92d5ab5230b0d3bb_sp_unknown.gif",
        "ssdeep": null,
        "size": 97,
        "sha512": "a240a284be05d662fd16a0239e4d14b3bda5bfad28c6cc065128138b5dffb4f9009cda56f5eaebdb83bb5985bc45255f1ea7693219e10d5b2b2de931e3e12671",
        "pids": [
            2740
        ],
        "md5": "dbef34749a1fd7fa508a1dfffdc13d2e"
    },
    {
        "yara": [],
        "sha1": "c276cd256737c1a40bb73ba5de2807c999edf8b5",
        "name": "ca912049688490a0_advisorbrand.css",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\advisorbrand.css",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "ca912049688490a06ee95dc126cc0838f5583f6797f674de41ed1c16f518ebcf",
        "urls": [],
        "crc32": "06A43EBC",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ca912049688490a0_advisorbrand.css",
        "ssdeep": null,
        "size": 52,
        "sha512": "a5f83e0c232928cd6e8ff339796b67392b79bae82fee480bcd6e1eadbfbc97ac507532c77abb4ba157452d024f11b628b0d980ddf6219c7079cb5ee59ec4ff92",
        "pids": [
            2740
        ],
        "md5": "01e511983547ab24e450d80853c31e5f"
    },
    {
        "yara": [],
        "sha1": "720e5f3b8380b8a5d04e7a99e4f743e44d738314",
        "name": "d697b0de3cbb1133_belarc-logo-small.png",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\belarc-logo-small.png",
        "type": "PNG image data, 114 x 54, 8-bit\/color RGBA, non-interlaced",
        "sha256": "d697b0de3cbb1133a0899a8facab39e787e5b8dfb3227fe62ac8807e3b2d3c96",
        "urls": [],
        "crc32": "A704D14B",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d697b0de3cbb1133_belarc-logo-small.png",
        "ssdeep": null,
        "size": 1777,
        "sha512": "5d613babef21e0dcf81c9aee419841e9cb67d505d75840dc6162b566269878a1927c9f176f726c53747e203f7afca542b2f4e67947603f55d4590b9941bc7d09",
        "pids": [
            2740
        ],
        "md5": "63ca5f180525e8348a56d2adc85781c4"
    },
    {
        "yara": [],
        "sha1": "fd448d4a9165bc848a1e6c579010a3ec21b4137e",
        "name": "7128574752f0a7da_uninstall.exe",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\uninstall.exe",
        "type": "PE32 executable (GUI) Intel 80386, for MS Windows",
        "sha256": "7128574752f0a7da1284d589c195aafe25c29f825d7028cebdb21a7ecc44dc00",
        "urls": [],
        "crc32": "ACD7A536",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/7128574752f0a7da_uninstall.exe",
        "ssdeep": null,
        "size": 164864,
        "sha512": "310ac39dd9f13d18d87320e1a10167ba206f01819c384dbda341ee8c63d57c6c6cd366f74fa26db94e90904ff5b98388e62905866ee761344f93d532e8f0b2dd",
        "pids": [
            2740
        ],
        "md5": "2b85fe26ca828485bff6a454b881a295"
    },
    {
        "yara": [],
        "sha1": "c9a1026dfc6659ce02c39677cc599bdb61daa721",
        "name": "d8c9fb8a647762f8_securitypaneltextitems.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypaneltextitems.html",
        "type": "HTML document, ASCII text, with very long lines, with CRLF line terminators",
        "sha256": "d8c9fb8a647762f8ce3473cdfa282b74e78240e3cfe934089fae6d4ff8828d67",
        "urls": [
            "http:\/\/www.belarc.com\/cgi-bin\/SecurityAdvisorUpdate?version="
        ],
        "crc32": "7057A418",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d8c9fb8a647762f8_securitypaneltextitems.html",
        "ssdeep": null,
        "size": 1825,
        "sha512": "eab89fbd9c6fbcb9ee1eec4574055fcfcff4eebd4b0e129b5761fce7cfc018794a7942d0fc3456423e298ecb1e82f74bf894348dd95b6d520e7693f81029a8ae",
        "pids": [
            2740
        ],
        "md5": "37b433dcf2a1e78bc682e85a250178d6"
    },
    {
        "yara": [],
        "sha1": "ce24feb23df0099986c9aded8b8e70c328646e70",
        "name": "6053e9ee6544414f_sp_s2.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s2.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "6053e9ee6544414fc717ed4b70f0220244a0dd3603b7dcae3dc75848f5fce0f3",
        "urls": [],
        "crc32": "D64371F1",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/6053e9ee6544414f_sp_s2.gif",
        "ssdeep": null,
        "size": 1187,
        "sha512": "905d8e0976b5d222b23e51709fdc407d47b8fd502a2c186fdeeb36a36916715e65c2f292b148d3cdc31bd1049884947d3766e5a4e7f6f2bd22dee88963034d6c",
        "pids": [
            2740
        ],
        "md5": "1458db0aa0132f367b0cb92c58637378"
    },
    {
        "yara": [],
        "sha1": "cd403f6875d91475c253ba65013e497a62081737",
        "name": "9823f8eb44898548_summarypageheader.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarypageheader.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "9823f8eb448985484dc49885e11fc69ac8c5892c08745b72ada9d9a8fa83d136",
        "urls": [
            "http:\/\/www.belarc.com\/ba5.html?B"
        ],
        "crc32": "2F304AF1",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/9823f8eb44898548_summarypageheader.html",
        "ssdeep": null,
        "size": 973,
        "sha512": "0e46780e23c66958b704a494aede6dad73b45e92d3c1f9f062f0d26c33a448d37a5f3d455fb859f87ffba0ab652a039d504ae1410d64f725f59d60ca0ab7b2a4",
        "pids": [
            2740
        ],
        "md5": "79033c1c5940538689b5769bcbe044c0"
    },
    {
        "yara": [],
        "sha1": "b654dfafb535137fefca03fc979e3ab9c84ea008",
        "name": "3bbee86c84910d5e_summaryusernamenotes.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryusernamenotes.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "3bbee86c84910d5efc8f3583324edd9657a353450ac1e7cbead6847096ec1f5e",
        "urls": [],
        "crc32": "F2E8CCFE",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/3bbee86c84910d5e_summaryusernamenotes.html",
        "ssdeep": null,
        "size": 107,
        "sha512": "9a62c513290fd08588b690b968134f506f5c524b8f191656bc83711b73f53c8749fd03eda46c9a7e9e4bf25a781a17d1f98e69686ed175983ba7c8e4a9d5ebb4",
        "pids": [
            2740
        ],
        "md5": "a9ced68b1a856cb57e616b9ab41acbbd"
    },
    {
        "yara": [],
        "sha1": "b3ad9f69a90c03b79edebb250295f9eadb7eb490",
        "name": "8f344606d9572f54_sp_s5.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s5.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "8f344606d9572f54f7e5d89655da5a1c1b206efca9c9360f047cfb929f5dfb78",
        "urls": [],
        "crc32": "4C97EBA8",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/8f344606d9572f54_sp_s5.gif",
        "ssdeep": null,
        "size": 1194,
        "sha512": "4efdde985151c49b8726828e3215b8b5a4261bfa60e8310f10edfd3493d89798159fd146622b328e8c64cb5d524dea8c732a92b7b148b2f1f102e97a9c13ec72",
        "pids": [
            2740
        ],
        "md5": "16d000897c503d6c231c8cbf6c11f47a"
    },
    {
        "yara": [],
        "sha1": "b9cf0ebf06cd4239b14f2a8cf7cc59ec0e02e021",
        "name": "fcdc88c9c4384c93_summaryuserentry.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryuserentry.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "fcdc88c9c4384c931030ac4abd49f3346033e02806c829158426fc79250ea5ed",
        "urls": [],
        "crc32": "5E731402",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/fcdc88c9c4384c93_summaryuserentry.html",
        "ssdeep": null,
        "size": 74,
        "sha512": "51f0c96587823b0191554982ee399deb302cb02d79c74efecb0b16a61acb89ed52cb2761a4d173191aa9aef3aaefbf5f26ff9309bb6ef329db7918ab4267d622",
        "pids": [
            2740
        ],
        "md5": "044f3b834cc18e3682d0d1fe018d54eb"
    },
    {
        "yara": [],
        "sha1": "048e9ac4d7224682ca0e7649d995b801527c9b2a",
        "name": "67bee1c01b3ac6c2_sp_s15.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s15.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "67bee1c01b3ac6c2b6e7e27294fc00951b970d0e855ede5dd70eb5ccf66dd66b",
        "urls": [],
        "crc32": "474E8B73",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/67bee1c01b3ac6c2_sp_s15.gif",
        "ssdeep": null,
        "size": 1191,
        "sha512": "4f611a55d4d3dc9f97673d5b4477c986f0b6e98ad9022001b8c609781ad53d9c80b5e6d0c60d6985bbfabb247eae32ee5509cc26d7cad80c62965d3041e9ee75",
        "pids": [
            2740
        ],
        "md5": "1f1c7cac45519f1855a73200c9ca9355"
    },
    {
        "yara": [],
        "sha1": "b589b993fb4c3923ed6643c8ce0b2f2212eec4e4",
        "name": "51dd0a9bfe326cc3_yes.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\yes.gif",
        "type": "GIF image data, version 89a, 10 x 10",
        "sha256": "51dd0a9bfe326cc392544251171de4e58eeaaa0da89828732d64dec1e06b4a28",
        "urls": [],
        "crc32": "145644C6",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/51dd0a9bfe326cc3_yes.gif",
        "ssdeep": null,
        "size": 58,
        "sha512": "faa7f43ed89ac814ffa30767a9b063b514e64f31af483027cbd28dad8e868fdf6373ed7d7344dfe08ffe0c86af05ccd63cf311192a403bcfdb70953605c55b24",
        "pids": [
            2740
        ],
        "md5": "79853686b6e0beae68d52bb36488f1f1"
    },
    {
        "yara": [],
        "sha1": "124a6ef34de29890a0e59b9ef55f99b10ea12957",
        "name": "0246c4ca3bdc4bf6_summarygrouppolicyitem.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarygrouppolicyitem.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "0246c4ca3bdc4bf621f1e8f3919882cc2cecadc2c5fbd548e64bef71ae5863a1",
        "urls": [],
        "crc32": "B40186FD",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/0246c4ca3bdc4bf6_summarygrouppolicyitem.html",
        "ssdeep": null,
        "size": 137,
        "sha512": "1719e28ab0fe8aa81e7d2e9b11ef30ab23e63a2b9f468504a7a780c80d4fe8e1819ba0d5c70ca919951508dff9a148b253d3138228eeb6d74ddfc1e76bca39c9",
        "pids": [
            2740
        ],
        "md5": "c23106622d948817e975db68387b5d6e"
    },
    {
        "yara": [],
        "sha1": "b1b56d3fd7df0671e736ccafbef7650621c3ae68",
        "name": "d9a58bc9eb807c5c_cux.bcx",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\security\\cux.bcx",
        "type": "data",
        "sha256": "d9a58bc9eb807c5c12fe389c9dd42ade00f66774969df5f90ce925581c28ca5c",
        "urls": [],
        "crc32": "69908211",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d9a58bc9eb807c5c_cux.bcx",
        "ssdeep": null,
        "size": 4738,
        "sha512": "84e6e0498bce39166a486b390b34d640c457bff6131af52b5e092ab53a57f88e5a7cc205048dec208e72cd1a063ee2399c92861cb795eaf91e77fa924c87b93e",
        "pids": [
            2740
        ],
        "md5": "342df05af89710c91e6f2a4f55949966"
    },
    {
        "yara": [],
        "sha1": "c82845e58e36b63ed83f1a8fff0ece7895f06f0b",
        "name": "f9cfe20ababff595_summaryprinteritem.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryprinteritem.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "f9cfe20ababff595d9042277140dc444a50605f2d495e994c87328fee4c1b2b5",
        "urls": [],
        "crc32": "56036489",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f9cfe20ababff595_summaryprinteritem.html",
        "ssdeep": null,
        "size": 84,
        "sha512": "d8126e42a3a66270aec6b33958b594aa31406e16d0fb2f9ade557f6143776614d904854d07da9b6a4caab5ddc19a89c06cfb59c071d1a5bcbe793bc882d9dcc6",
        "pids": [
            2740
        ],
        "md5": "5458494c416ed46fd0565a1dd2d157cb"
    },
    {
        "yara": [],
        "sha1": "6b33b9f9a4f6961e93b53bc209719961dca7746e",
        "name": "adb3069d8514d497_securitypanelcis_unknown.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelcis_unknown.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "adb3069d8514d497fe9c97175c37de70187ae83ac19ec7630ec2e9ba7c5cce16",
        "urls": [],
        "crc32": "1F02A952",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/adb3069d8514d497_securitypanelcis_unknown.html",
        "ssdeep": null,
        "size": 342,
        "sha512": "48b3f0bd1d22720481f13335a097af1a66ac9375cc41a2408f06a4f796fae3c4cd3f9e9a71d6bc102a7c7d300aa13a4289a2329d7a52d47f2a701c6da7f02355",
        "pids": [
            2740
        ],
        "md5": "a2e4519be3c00b1e7c73b3fc247f5dc5"
    },
    {
        "yara": [],
        "sha1": "f73298d750363a4df36a50a19ee890d6d223e566",
        "name": "89b673f93af29a27_summarynetworkdriveitem.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarynetworkdriveitem.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "89b673f93af29a27119a8192502bb4c2c092024a771b17ad66ba52ed39859968",
        "urls": [],
        "crc32": "70C43FCE",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/89b673f93af29a27_summarynetworkdriveitem.html",
        "ssdeep": null,
        "size": 187,
        "sha512": "18a0ab247bee00996ddf6a938cd171032c8caa379b0780f350fbe2278fb5f6f124fb0e27b116bb084b49f9b91adb8d18ee2d5ec8196c76d7a05c4ba77f265439",
        "pids": [
            2740
        ],
        "md5": "8f2a3197390742ef9b04b7e7116e98f5"
    },
    {
        "yara": [],
        "sha1": "ff14c6e48e6867d902563870572a3fbb149340c7",
        "name": "e4e27fc41da08d2e_summarylicenseitem.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylicenseitem.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "e4e27fc41da08d2e43bc2eec56efadcf2e08d0aca4d9015d3a23e986be1a62a7",
        "urls": [],
        "crc32": "5970D81B",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e4e27fc41da08d2e_summarylicenseitem.html",
        "ssdeep": null,
        "size": 90,
        "sha512": "9f4509476a583cbdc2258e92a3bced199fb9bef5ca57a47767a093f356fefeb6ca40e8ee4aa8cfa79b085d015a7103ee3e5fa0f0596c5e8d35f371410b445e6e",
        "pids": [
            2740
        ],
        "md5": "59690b46a3e4844bb78da25967b09bd5"
    },
    {
        "yara": [],
        "sha1": "84462cc58a9520d29ec2724380f65c0b104ea46b",
        "name": "0c9c1cada7c04163_summaryqfemissingempty.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfemissingempty.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "0c9c1cada7c041635a49c39d0dbd085407d575c8723833ed151b1b1bdbffdca6",
        "urls": [],
        "crc32": "CACB028C",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/0c9c1cada7c04163_summaryqfemissingempty.html",
        "ssdeep": null,
        "size": 297,
        "sha512": "e20d23483f69fd3fd59c61576374ca213eedfb69e3bf8ffedc069a1995aa516b5b3bf4d9743f13b9eca3f82002a48a9dc7c606909ac7a596b9e743481fb5bc6e",
        "pids": [
            2740
        ],
        "md5": "2a73f405b734e8d3125fb907c5a82632"
    },
    {
        "yara": [],
        "sha1": "65e91d2ac8580927ec57856372402399ec9d98b8",
        "name": "297d4166c7b76e1c_advisor.css",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\advisor.css",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "297d4166c7b76e1c9e4b6c08d9650de019d545c768ffc26e36f649c1b311c9fd",
        "urls": [
            "https:\/\/fonts.googleapis.com\/css?family=Roboto:500",
            "https:\/\/fonts.googleapis.com\/css?family=Roboto:700",
            "https:\/\/fonts.googleapis.com\/css?family=Roboto"
        ],
        "crc32": "03BB69FF",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/297d4166c7b76e1c_advisor.css",
        "ssdeep": null,
        "size": 12696,
        "sha512": "9ce26370302559023e157f703e638813338a9f22f936f478c9e5a7eb2329856e59bc11f9173f9764dc58af619948dc657091593211407858ac8f5e8e283cab9e",
        "pids": [
            2740
        ],
        "md5": "e07295dbc51aa07a0a5ff43d2f91da09"
    },
    {
        "yara": [],
        "sha1": "51b9e573e509cb7cc8b4f275572d79898a5d597a",
        "name": "63ce5d09bae0776d_benchmarkscorewarning.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarkscorewarning.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "63ce5d09bae0776d41caa666150c5ba1c791b4328138bddc4766dbdcaa55a88b",
        "urls": [
            "http:\/\/www.belarc.com\/cgi-bin\/SecurityAdvisorUpdate?version="
        ],
        "crc32": "997DDAB9",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/63ce5d09bae0776d_benchmarkscorewarning.html",
        "ssdeep": null,
        "size": 399,
        "sha512": "140cc27d654db97c0b4cc62153a60ff6878e053976a20d1efca005a8ac9a4e50640835eb34b4dbfb4bd112caf9e5c2b33e67423199bc56d41de949077eee9846",
        "pids": [
            2740
        ],
        "md5": "fc273f432d9bd605869eee133244457b"
    },
    {
        "yara": [],
        "sha1": "775de7cad437fd3f7225fa9efbb1b02f59c25028",
        "name": "564c221fdad409dd_securitypanelcis_alert.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelcis_alert.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "564c221fdad409ddbcf4619c77959a946b58da4eda00ead4c313df05953996a7",
        "urls": [],
        "crc32": "92484A66",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/564c221fdad409dd_securitypanelcis_alert.html",
        "ssdeep": null,
        "size": 322,
        "sha512": "d87524f2074b6eb8fcbba7467523b08db96ba44d03cf694939d114c270ecb2b7563ae3829d8518860af7a37f2361f8a5228d770184d4c8a66a9a5d058b15842f",
        "pids": [
            2740
        ],
        "md5": "5057512bb34f7947c917aa1cbc6d9dda"
    },
    {
        "yara": [],
        "sha1": "7bc6a62341cbe78f1bf6d6517f08f9a3a67bcf3f",
        "name": "d6f895223c63e9e5_summaryvirtualmachineitem.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryvirtualmachineitem.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "d6f895223c63e9e52cfd5fbbc75f5b0ae0078decd70f89ad84b4b906caacf0c3",
        "urls": [],
        "crc32": "076DF11A",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d6f895223c63e9e5_summaryvirtualmachineitem.html",
        "ssdeep": null,
        "size": 154,
        "sha512": "4ba30d9d53a73e994a500290ade977a5fc70d3f1f3119e191f3ca4ea7e5139200922ff8456c78813fd8748d74b50408919f9854a0278fdd8cd140c30a6b631bd",
        "pids": [
            2740
        ],
        "md5": "a9d65e9b85baa3c42a4d5d6ba00d7311"
    },
    {
        "yara": [],
        "sha1": "6d95615e1c9c572f9d6fc1884fc8262635815f12",
        "name": "0cfa75537347b687_sp_s0.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s0.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "0cfa75537347b6878f57fed73a7548d291d317e82ee9767219e33d3dfce583d8",
        "urls": [],
        "crc32": "6B1BB39A",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/0cfa75537347b687_sp_s0.gif",
        "ssdeep": null,
        "size": 1146,
        "sha512": "c8a218530757c5cf880f95955ea30561ac6f6c3698c57994913742022eafd5d8af49aa809946634136af189da8b490d1e58d48038038953edcd6ff3ec4414968",
        "pids": [
            2740
        ],
        "md5": "abbc9e59b73537b7af1a5804f371fcb0"
    },
    {
        "yara": [],
        "sha1": "dcc855a43cbc73d806824941cf75e6c4bf5645f5",
        "name": "ef7cfd00f31e0bed_bar1.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\bar1.gif",
        "type": "GIF image data, version 89a, 1 x 5",
        "sha256": "ef7cfd00f31e0bedf0989e89083331c361394c1b370b2d4f8dbebca451ab0474",
        "urls": [],
        "crc32": "1BD19F7A",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ef7cfd00f31e0bed_bar1.gif",
        "ssdeep": null,
        "size": 42,
        "sha512": "739d31ecbd65a70b25257ed6ba83af6cfcb470a5ef610571e362f0aa539b074da59097b04141ddb498aa99bfc7ed39a2d3c2abd8b6db1154e6eb62904267b507",
        "pids": [
            2740
        ],
        "md5": "45084103841150c88d02ab55bb76f63c"
    },
    {
        "yara": [],
        "sha1": "b5acea29f94a351bad838e77fdf29893d2055e29",
        "name": "d48787ae16db0039_summaryloginsitems.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryloginsitems.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "d48787ae16db003995b52455f743bc6bfa21ad4407790c0167f88635c5e6f758",
        "urls": [],
        "crc32": "9B6DA2D6",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d48787ae16db0039_summaryloginsitems.html",
        "ssdeep": null,
        "size": 1566,
        "sha512": "f734cea73ec4756825b7dc191b75f8136cdc70422d7b34c9e255f488b65b6e9714e8e5c7155f09cee5e3c01d4dd6002f6765ae57072a081a7ef21babc1898c6b",
        "pids": [
            2740
        ],
        "md5": "2d59021641a2358d181c08a407926dfd"
    },
    {
        "yara": [],
        "sha1": "60641c600c69d9c15f23b4350f2cda55afa49520",
        "name": "8a831ef1dcf91927_summary.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summary.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "8a831ef1dcf919279aa1670d2ba51969fa74873ce8f86843e8b3c88a64e22c49",
        "urls": [
            "http:\/\/www.belarc.com\/ctadvisor.html?B-versions",
            "http:\/\/www.belarc.com\/msproductkeys.html",
            "http:\/\/www.belarc.com\/ctadvisor.html?B-hotfixes",
            "http:\/\/www.belarc.com\/ctadvisor.html?B-net",
            "http:\/\/www.belarc.com\/ctadvisor.html?B-licenses",
            "http:\/\/www.belarc.com\/ctadvisor.html?B-missing",
            "http:\/\/www.belarc.com\/ctadvisor.html?B-top"
        ],
        "crc32": "B4A22A20",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/8a831ef1dcf91927_summary.html",
        "ssdeep": null,
        "size": 10670,
        "sha512": "052477903873c57a2decc772fdb1b4ca83acfe42e22465659c40a8d190e78da4f3c701bc083844a0534866dce30172008b075c880655bcd6bd46f169b6354cec",
        "pids": [
            2740
        ],
        "md5": "302ba424f79a5447318884f71abdaab2"
    },
    {
        "yara": [],
        "sha1": "7b55247dacd15768000caf3607277f0cde5df081",
        "name": "764148dc26d30b97_fdcc - windows vista,v1.2.1.0.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarks\\fdcc - windows vista,v1.2.1.0.html",
        "type": "HTML document, ISO-8859 text, with very long lines, with CRLF line terminators",
        "sha256": "764148dc26d30b97871b08bffc33232e24a43c4d5f1d1b86dec57501f3c3ec2e",
        "urls": [
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5018",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3082",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2525",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2521",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3033",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4869",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4863",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4861",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3076",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4867",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4866",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5089",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3888",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3929",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2359",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2457",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4568",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4569",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4564",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3426",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4215",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3421",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3429",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4597",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4047",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4046",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4040",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4043",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5061",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4048",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5067",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4694",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2854",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3518",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4184",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3696",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2858",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4627",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3452",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3450",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4962",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4963",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3454",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3459",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4969",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3214",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3217",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3216",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4916",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4915",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3199",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4919",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2679",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4139",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3351",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3601",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3996",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2719",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3855",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3853",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5084",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3998",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4988",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3283",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3287",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3285",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3288",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4828",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3072",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3075",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3041",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2557",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4152",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4001",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4150",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3976",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5020",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5023",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2398",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5028",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4793",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4792",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3271",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4797",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4796",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3270",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3553",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2785",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3417",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4704",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3414",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4703",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4317",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4098",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4099",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3875",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4161",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4093",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4382",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3486",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3482",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2953",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2825",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2821",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2820",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3251",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4673",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3252",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3255",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4891",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3259",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4956",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4955",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4898",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4774",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3325",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4763",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3323",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3023",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2697",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3024",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3744",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4872",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4877",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3933",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2519",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4201",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2467",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5181",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4053",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4050",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5114",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4581",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4583",
            "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/WinVista-FDCC-V1.2.1.0.htm",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3164",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2999",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2998",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4639",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3564",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3115",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4902",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3160",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4904",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3166",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3165",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4907",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3168",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2868",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3378",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2641",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3361",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3360",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3364",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3367",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4643",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3201",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3207",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3204",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3706",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3338",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4594",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4833",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2746",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4110",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3015",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3963",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3380",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3385",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4016",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4017",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4013",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4011",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3945",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3941",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4018",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5016",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2380",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4122",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2339",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4781",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4264",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4267",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4300",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3400",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3403",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4062",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4066",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4068",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5163",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5008",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3891",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2724",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4166",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4175",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2838",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4162",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4163",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4160",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4174",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3246",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3244",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4948",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3240",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4761",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3125",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4947",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4940",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4941",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3248",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3120",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3233",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3232",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3230",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3623",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3584",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3239",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4285",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4629",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4119",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4118",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2755",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2754",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3330",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3331",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3336",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3337",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4115",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3054",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3050",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3751",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3754",
            "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/WinVista-FDCC-Firewall-V1.2.1.0.htm",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4845",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4841",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2471",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2477",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3909",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4213",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3457",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4507",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3905",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4501",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3456",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5128",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4342",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4026",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4020",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3469",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5047",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5048",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2376",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2977",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2975",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3576",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3570",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4488",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4722",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4334",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3173",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3177",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3212",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4938",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2650",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2715",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2714",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3376",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4153",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3373",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3279",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3278",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4651",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4652",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3272",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4656",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3379",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3303",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3302",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3307",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2781",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4991",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3093",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3902",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2533",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3993",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3001",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3398",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3906",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3394",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3395",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3953",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3954",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5007",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5004",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5000",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3894",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2322",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2323",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4479",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3432",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3436",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3439",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4372",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4278",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5172",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4071",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5170",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5177",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4077",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4078",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4079",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4158",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4687",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4192",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4196",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4194",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2924",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4970",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4616",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4200",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3138",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4206",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4612",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4976",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4757",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4618",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3220",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3590",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3225",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3181",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2778",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5011",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4132",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3619",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4109",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3349",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3348",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4101",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4104",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3341",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4107",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3045",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3046",
            "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/IE7-FDCC-V1.2.1.0.htm",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4998",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3299",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4854",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4992",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3297",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4996",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3292",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4922",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4827",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4149",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4535",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3914",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4925",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4405",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3969",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4038",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4034",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5132",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5131",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5036",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5034",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2363",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5038",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4202",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4973",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4207",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3500",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3468",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2967",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2962",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3460",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4714",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3464",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4089",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4088",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4083",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4084",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4086",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3143",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3142",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2883",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4147",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4143",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4889",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4921",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3260",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3261",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3263",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3866",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3311",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3314",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3316",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4813"
        ],
        "crc32": "E7EE0EAC",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/764148dc26d30b97_fdcc - windows vista,v1.2.1.0.html",
        "ssdeep": null,
        "size": 233322,
        "sha512": "5616dd3e4fb3920f0f5c8ce25a30bc74ab5eb91673111d88df50700d153fd88de3aca107a1aa6a9fae2b4c545ef6d40dd9da62d899f3fb190b961a4ac37f6ddd",
        "pids": [
            2740
        ],
        "md5": "b653e79754eae5dba2f0b9eec447de7a"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "Contains an embedded Mach-O file",
                    "author": "nex"
                },
                "name": "embedded_macho",
                "offsets": {
                    "magic1": [
                        [
                            889012,
                            0
                        ]
                    ]
                },
                "strings": [
                    "yv66vg=="
                ]
            },
            {
                "meta": {
                    "description": "Possibly employs anti-virtualization techniques",
                    "author": "nex"
                },
                "name": "vmdetect",
                "offsets": {
                    "vmware24": [
                        [
                            1851766,
                            0
                        ],
                        [
                            1860628,
                            0
                        ],
                        [
                            1875480,
                            1
                        ],
                        [
                            1888301,
                            0
                        ],
                        [
                            1903628,
                            0
                        ],
                        [
                            1903644,
                            0
                        ],
                        [
                            1903660,
                            0
                        ],
                        [
                            1903676,
                            0
                        ],
                        [
                            1903692,
                            0
                        ],
                        [
                            1903708,
                            0
                        ],
                        [
                            1903724,
                            0
                        ],
                        [
                            1903740,
                            0
                        ],
                        [
                            1903756,
                            0
                        ],
                        [
                            1903772,
                            0
                        ],
                        [
                            1903788,
                            0
                        ],
                        [
                            1903804,
                            0
                        ],
                        [
                            1903820,
                            0
                        ],
                        [
                            1903836,
                            0
                        ],
                        [
                            1903852,
                            0
                        ],
                        [
                            1903868,
                            0
                        ],
                        [
                            1952650,
                            1
                        ],
                        [
                            1952664,
                            0
                        ],
                        [
                            1952818,
                            0
                        ],
                        [
                            1952862,
                            0
                        ],
                        [
                            1960096,
                            1
                        ],
                        [
                            1960108,
                            1
                        ],
                        [
                            1960316,
                            0
                        ]
                    ]
                },
                "strings": [
                    "Vk13YXJl",
                    "dm13YXJl"
                ]
            }
        ],
        "sha1": "61e6ed9b208bdd8543e554abb9efef88a74802b1",
        "name": "6c4d70243ae78f4d_npbelv32.dll",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\npbelv32.dll",
        "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
        "sha256": "6c4d70243ae78f4d2707cda714f79397ebcb6ca04e515a03f8dc63bedb76f84e",
        "urls": [
            "http:\/\/www.usertrust.com1",
            "http:\/\/ocsp.comodoca.com0",
            "http:\/\/crl.usertrust.com\/UTN-USERFirst-Object.crl05",
            "http:\/\/crl.comodoca.com\/COMODORSACertificationAuthority.crl0q",
            "http:\/\/crl.comodoca.com\/COMODORSACodeSigningCA.crl0t",
            "https:\/\/secure.comodo.net\/CPS0C",
            "http:\/\/www.belarc.com\/BelNotify\/Master.bcf",
            "http:\/\/ocsp.usertrust.com0",
            "http:\/\/www.belarc.com\/cgi-bin\/baerror?%s",
            "http:\/\/crt.comodoca.com\/COMODORSACodeSigningCA.crt0",
            "http:\/\/www.belarc.com\/cgi-bin\/dellrefer?%s",
            "http:\/\/crt.comodoca.com\/COMODORSAAddTrustCA.crt0"
        ],
        "crc32": "75F836A2",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/6c4d70243ae78f4d_npbelv32.dll",
        "ssdeep": null,
        "size": 2625544,
        "sha512": "ee6a4bdd39deb73e57a0f1bd64acff211d94518848f71685164dc63d20d70521b573096dab347c5b41de504e669d4374a919c42d89680451c8d224130db0924b",
        "pids": [
            2740
        ],
        "md5": "d2dbe09125727bc00051ccb3ff69d9ba"
    },
    {
        "yara": [],
        "sha1": "19604a259d224c6dd39106b78b8aa2ddcc402a50",
        "name": "f99f3cf558d94ad3_sp_s12.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s12.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "f99f3cf558d94ad32d0bbd3594104f34f59291bebe6ef2ed6fda9761b70441fe",
        "urls": [],
        "crc32": "901E0B68",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f99f3cf558d94ad3_sp_s12.gif",
        "ssdeep": null,
        "size": 1184,
        "sha512": "937cd7a9c00e4a53b9c5f06850bd92f77bae5ac9d78beea4835213cfd9de84d783dea9c194955b68676a51f6728e43c261b469835ecf92a0df785622f1e532d4",
        "pids": [
            2740
        ],
        "md5": "c266d7d0586dde2d1bec595f41b729a5"
    },
    {
        "yara": [],
        "sha1": "38eff05f2887bdc91b4bc90c4ec1d114dac04477",
        "name": "3b09702902dcbffe_summaryqfemissing.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfemissing.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "3b09702902dcbffe93b5b243b477596e262e7d7f05c8ec17a8692e70afe92443",
        "urls": [],
        "crc32": "9E93E378",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/3b09702902dcbffe_summaryqfemissing.html",
        "ssdeep": null,
        "size": 697,
        "sha512": "85cd8e2361754608ae52f0b0863ade7440af75520541d6641956200c456edb818146657872a94b952bc4d72fed6e0f800e84a458667075a4fcd022810266a182",
        "pids": [
            2740
        ],
        "md5": "1abe5f514054896d4d220ed26fb13f44"
    },
    {
        "yara": [],
        "sha1": "76049db00744cc2b0be068b22621615644b55a13",
        "name": "bdaf1446ad030e88_benchmarks.cax",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\security\\benchmarks.cax",
        "type": "data",
        "sha256": "bdaf1446ad030e88014af648f53333c07c862401cd5644625b556e7b5d25a557",
        "urls": [],
        "crc32": "2C1CEAD1",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/bdaf1446ad030e88_benchmarks.cax",
        "ssdeep": null,
        "size": 30627,
        "sha512": "e880ce4a79649754e463b7231ffaf87b909a4b6f3b11422963e5cf0a4236b670f984c9efa197c3056cec6ec5ec8356b0d08acbe2c7fdd29d0aaed4fbe0fe49ed",
        "pids": [
            2740
        ],
        "md5": "1e79b03365a1f664effbf2e5422a78ef"
    },
    {
        "yara": [],
        "sha1": "922e4b209084ac95a48d35b38305dc904ce6da7e",
        "name": "c7e923e8acf0d788_summaryqfefootnotes.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfefootnotes.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "c7e923e8acf0d788edbb7c5959a153689a290981cb5c10491c0fbfadcf2e38b8",
        "urls": [],
        "crc32": "EA32090B",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/c7e923e8acf0d788_summaryqfefootnotes.html",
        "ssdeep": null,
        "size": 581,
        "sha512": "ee4688e4566faf8f00ebb0f525dc9d3acf41c7f392d11ae2ee4f691fca9c91142059221e6ad1674dffee1f2abeac0c0f5fa4a5f8d324bf676f770d3b24fe9547",
        "pids": [
            2740
        ],
        "md5": "a28d3794d9278a9eb3d215cb1cfd18d8"
    },
    {
        "yara": [],
        "sha1": "2329f1cd91a11b755633884b62eb6785a032d8eb",
        "name": "1db60562d8704a50_summaryqfeempty.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfeempty.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "1db60562d8704a507ad3d169aa0482d2a14ebb6dbd30081616be1f4f3cb84efd",
        "urls": [],
        "crc32": "B537D52A",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/1db60562d8704a50_summaryqfeempty.html",
        "ssdeep": null,
        "size": 109,
        "sha512": "f0358e1c7961e6584cbdbfabaebba149bb6c9d41067a0ef09460d2e5a1d2e00319d29beed11ecd263d5dc8c83db618d2580b3fa91ecb214cbc5b95f0af1ce248",
        "pids": [
            2740
        ],
        "md5": "788d02bb6e2737c3a3163a877e32cc70"
    },
    {
        "yara": [],
        "sha1": "7b9e39df4c9328349e880704975eff66f2d99126",
        "name": "3094f46c4ad9449a_sp_s1.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s1.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "3094f46c4ad9449a67283e69145974b510a009d0b303a4a070ff074ad99d6c3f",
        "urls": [],
        "crc32": "7E7D757F",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/3094f46c4ad9449a_sp_s1.gif",
        "ssdeep": null,
        "size": 1171,
        "sha512": "616b1fe22184e1601427ba8ad3d8b55dcd0079c84164cd434eb4f543b0021be4f51d6c7562e08868500a43474ca64501fe0ad9fdf5a4a643039184238f0173b5",
        "pids": [
            2740
        ],
        "md5": "98ecc0041d56d628337afbe9223b8146"
    },
    {
        "yara": [],
        "sha1": "33a2d0a99115eefd1c63e19f130dc4560e07b524",
        "name": "cf84452e352ef976_summaryvirtualmachines.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryvirtualmachines.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "cf84452e352ef976b8ba052c30f5bffdbe2c839b0b7daf853cebb6f12d66fc35",
        "urls": [],
        "crc32": "CB67C562",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/cf84452e352ef976_summaryvirtualmachines.html",
        "ssdeep": null,
        "size": 288,
        "sha512": "d15e9c1c3e8034121083e7f12067fb81f4e016eb0a67da1ee0f52965418cbf6e7433a5ab278ccc0e326b4452810de9628fabc980bdd06a10f06f8f8e1367c3b6",
        "pids": [
            2740
        ],
        "md5": "0e7df45173c11a35be4c5ab7e2eb09fd"
    },
    {
        "yara": [],
        "sha1": "ff58693ad665566ba06ddf355fe7dd31e7d00429",
        "name": "aacd4d8756618d25_summaryqfeexternal.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfeexternal.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "aacd4d8756618d25a3adf43b54786396401ff25466d0fb458df4a75d5429a397",
        "urls": [
            "http:\/\/www.belarc.com\/ctadvisor.html?B-hotfixes"
        ],
        "crc32": "E8BD1917",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/aacd4d8756618d25_summaryqfeexternal.html",
        "ssdeep": null,
        "size": 1998,
        "sha512": "fb6319e75a681a57ed579175b8150c8005aa83043f6f04b20535fbf31f62eac26bbff257ce4a8b85b63453a5f4df651e4181babb4de866eac4722d63c1487b25",
        "pids": [
            2740
        ],
        "md5": "127aa876a8d50a0884672217bb4b76e8"
    },
    {
        "yara": [],
        "sha1": "dd230da2e31589ae6b8a079f995e206f3230e742",
        "name": "a12c0b3645750255_summaryprinters.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryprinters.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "a12c0b3645750255458f991a3d5bf6c7e3d771f1e7b541ecb8915d28714c7e0f",
        "urls": [],
        "crc32": "ADD23AD5",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/a12c0b3645750255_summaryprinters.html",
        "ssdeep": null,
        "size": 95,
        "sha512": "c97304c12380ef310bc2c4673bdbcd733216445bb9a970b6c101f054ca30b2cf4bb5d39c2b4b538bb5181cc4fd77e251a1f73c67d0a9caa73b5a9354a331f3db",
        "pids": [
            2740
        ],
        "md5": "eeb2f06dbaff750ddf3205588a4da9ab"
    },
    {
        "yara": [],
        "sha1": "2aba6e50f74eb9016991a2a8413a74f9a7f6b1f7",
        "name": "a5003419390bcfe8_summarylanitem.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylanitem.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "a5003419390bcfe814aa4be870a8e2ba8ea3dd45955ce3e8d0ecb591a9dd30d2",
        "urls": [],
        "crc32": "91B79F86",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/a5003419390bcfe8_summarylanitem.html",
        "ssdeep": null,
        "size": 192,
        "sha512": "c6b417ae56d1e4db4618f75b0b31bfe2c0ccf36d3744dbf5bcc28e53549a7fdd57ed49c8964bbd56e23c2fc93ca5335805a1c65d81e532be87b1a73013829e01",
        "pids": [
            2740
        ],
        "md5": "b3f58d240f044794edde275ec3c7022e"
    },
    {
        "yara": [],
        "sha1": "5101cb278dae86183e024db02af72b68802845ca",
        "name": "7863796bde8134f7_usgcb - windows 7,v2.0.5.1.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarks\\usgcb - windows 7,v2.0.5.1.html",
        "type": "HTML document, ISO-8859 text, with very long lines, with CRLF line terminators",
        "sha256": "7863796bde8134f7b799e5432fbb1fef798491333b07a33196d56df15cffa538",
        "urls": [
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10403",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10011",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9620",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9301",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9657",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9304",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9307",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9309",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9308",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10083",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9960",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10539",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9496",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9712",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9498",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10535",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8974",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8973",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9406",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9407",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9156",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10277",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9150",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9403",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9400",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9014",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9396",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9395",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10405",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8870",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9274",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8484",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8487",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10623",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10622",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8414",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10620",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10625",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9829",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9945",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9821",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9823",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10744",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10059",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10052",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10055",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10699",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10696",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8460",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10692",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10759",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9753",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9750",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10574",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10472",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9616",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10470",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10578",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10475",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9358",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10275",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10276",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10178",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9357",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9686",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10882",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9683",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8937",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8936",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10373",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8804",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8807",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8806",
            "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/IE8-USGCB-V1.0.1.0.htm",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9534",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9532",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9531",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9124",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9121",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9432",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8560",
            "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/Win7-USGCB-V1.0.1.0.htm",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9439",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8513",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9982",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9985",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9864",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9865",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9866",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9863",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9868",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?11252",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9222",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9223",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9226",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9509",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9542",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9540",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8740",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10714",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9918",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9919",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10650",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10651",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8423",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10654",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10655",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9910",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8583",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9914",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9917",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8562",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10486",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9123",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10438",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10434",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10433",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10431",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10002",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8732",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10265",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9317",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9643",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10137",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10293",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10138",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9319",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9669",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10235",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10566",
            "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/Win7-USGCB-Firewall-V1.0.1.0.htm",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9487",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10509",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9768",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10502",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10500",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9764",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9763",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9760",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10342",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10344",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10347",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9007",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9667",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9361",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10200",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9266",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9265",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9260",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9506",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9503",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9501",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9461",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9464",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9465",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8999",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9189",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10611",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9185",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9819",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9953",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9736",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9814",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9817",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9959",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8789",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9212",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9217",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9215",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9704",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9707",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10763",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10764",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10769",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10685",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8475",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9336",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9330",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10543",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10466",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10461",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9603",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10266",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9329",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9737",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9327",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9326",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10140",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10268",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9048",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9320",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10824",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10828",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10386",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10387",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10380",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10389",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9229",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10319",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8958",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9136",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10311",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9135",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9426",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9786",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9781",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9783",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9858",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8503",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9850",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9857",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8818",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8813",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8811",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8817",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9559",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9254",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9253",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9251",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10725",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10649",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10645",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10646",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10641",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10642",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8431",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9925",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9926",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9289",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10581",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10586",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10420",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10425",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10033",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10037",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9674",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9670",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9673",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9672",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9440",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10522",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10515",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9779",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9774",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10107",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9776",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10105",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9770",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10103",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9773",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10219",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10359",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10215",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9370",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9375",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10811",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8856",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9588",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8912",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9792",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9295",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9793",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9107",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9458",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10547",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9456",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9199",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10603",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10602",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10604",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10607",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10606",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10609",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10608",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9193",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9195",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9967",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9801",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10110",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10074",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?14986",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10778",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10676",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10672",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10782",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10787",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10553",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10554",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?14854",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8612",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10154",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10157",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10156",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10150",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10094",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10095",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10096",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10090",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9021",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9739",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10850",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10856",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10394",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10393",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9040",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10525",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10527",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10250",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9419",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9418",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8945",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9149",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9417",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9389",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9388",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9790",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9026",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9387",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9386",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9098",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9096",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9842",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9898",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10130",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9244",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9249",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9562",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10638",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10730",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10630",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10635",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9832",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9938",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8467",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10182",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10183",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10181",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10021",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10022",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8654",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8655",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8714",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8825",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10664",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10595",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10594",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10597",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10591",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10590",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10561",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9742",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9747",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9749",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9663",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9660",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8591",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10441",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10205",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9068",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9069",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10165",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9067",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10160",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9345",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9344",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9694",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9692",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9342",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9348",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10360",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9593",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9528",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9520",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9522",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9888",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9882",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9449",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9885",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9976",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9973",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9876",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9875",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9874",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9870",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9879",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9878",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9239",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9191",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8884",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10061",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10709",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9908",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10661",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9901",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9907",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9905",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10795",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10496"
        ],
        "crc32": "7C23BEFF",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/7863796bde8134f7_usgcb - windows 7,v2.0.5.1.html",
        "ssdeep": null,
        "size": 237067,
        "sha512": "91aa891771297857b4ebfc059548b42685eedf25a3ec0f8b7676034456342cd6bc0ea28a80da1639837873269305736338f61ce74a2cdc4ce49a1f9910a6d297",
        "pids": [
            2740
        ],
        "md5": "c588e0afef29185c57fb3c0a1aa5fe40"
    },
    {
        "yara": [],
        "sha1": "f12464a0fd32f14e30fb5af3d10571a94faccad4",
        "name": "ce27e9975ca4a86e_shfs3.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\shfs3.gif",
        "type": "GIF image data, version 89a, 13 x 10",
        "sha256": "ce27e9975ca4a86e29330bf40c11493a90b17a6f976599e23b7e905282601b3a",
        "urls": [],
        "crc32": "CCA14F0B",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ce27e9975ca4a86e_shfs3.gif",
        "ssdeep": null,
        "size": 68,
        "sha512": "51e6348a2ede2be4879a578af2b34b4598f765df8d79221777ba454486d8874b335676cd42858682045013e2a3a8c3ab1f1dd78392720d7f4134d585babd2c56",
        "pids": [
            2740
        ],
        "md5": "4dd78e7118f10ce9131759a4231f65c6"
    },
    {
        "yara": [],
        "sha1": "da39a3ee5e6b4b0d3255bfef95601890afd80709",
        "name": "e3b0c44298fc1c14_GLB63F0.tmp",
        "type": "empty",
        "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
        "urls": [],
        "crc32": "00000000",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e3b0c44298fc1c14_GLB63F0.tmp",
        "ssdeep": null,
        "size": 0,
        "sha512": "cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e",
        "md5": "d41d8cd98f00b204e9800998ecf8427e"
    },
    {
        "yara": [],
        "sha1": "0cdedfcb1f0b1b6f29276b8d7edbea2843c53064",
        "name": "e97459d6a5f9b968_summarynetworkdrives.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarynetworkdrives.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "e97459d6a5f9b968a7f157d3115abf5e988dfb026a8eced4a0fc18ebd08ea2ff",
        "urls": [],
        "crc32": "A07128B2",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e97459d6a5f9b968_summarynetworkdrives.html",
        "ssdeep": null,
        "size": 251,
        "sha512": "a260e61c8e120d384a8cc06c07d5d5d4b8a7d4ae3e16c3fae100565ad60dfca7e3088c85c4c4e79af353adfb873f524fa4779fa0c8009c6a77b1a554605d25c4",
        "pids": [
            2740
        ],
        "md5": "e9d10fe5ed34071e60ba60be851a6ea5"
    },
    {
        "yara": [],
        "sha1": "ffce22d4447e0c40793b2bcdb808571cc5051011",
        "name": "049cfd0bc645c517_securitypanelcis_ok.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelcis_ok.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "049cfd0bc645c5172cd5326ed6df5bff2194dca543c34914e6a9943c9c9521d9",
        "urls": [],
        "crc32": "11ECD742",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/049cfd0bc645c517_securitypanelcis_ok.html",
        "ssdeep": null,
        "size": 569,
        "sha512": "46ea60a6c75542718883edbf45fcc4ef7c74d1afd632bf9927836cad9324f6a4ee2d3b74d956dcf0f5328966ae9c914052781f54ae91c0d15839aec81eecb2af",
        "pids": [
            2740
        ],
        "md5": "1e72a2eeb0ebaed4633f79da948abd3e"
    },
    {
        "yara": [],
        "sha1": "3955fa0d27094e16624c791e5faf6cb5e5283172",
        "name": "467390e9116ac881_corner_tl.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\corner_tl.gif",
        "type": "GIF image data, version 89a, 16 x 16",
        "sha256": "467390e9116ac8811f2d39f6cf6b1f23a1f2cc4e3da2dd384ab552b517f82057",
        "urls": [],
        "crc32": "7D123EC8",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/467390e9116ac881_corner_tl.gif",
        "ssdeep": null,
        "size": 71,
        "sha512": "156b99915f5148f036b116804ba81b33c1a3acc19244085f59828fdc22f87aadf42f4d2908d0b2b8736d82413fb5f48d0b3f2097bad329b6e7e5bf472fbeb542",
        "pids": [
            2740
        ],
        "md5": "5e6fdb130dff77279ae6815e8e9ecdd3"
    },
    {
        "yara": [],
        "sha1": "0e7b303a729cbbe77f3bc6d0ddf2c674637fab0e",
        "name": "3213501caffe4cb5_hotfixdefs.cax",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\security\\hotfixdefs.cax",
        "type": "data",
        "sha256": "3213501caffe4cb5d34aeaf19f80865b307e10bd687027ffc5165fbcdcaa58eb",
        "urls": [],
        "crc32": "3BA5A3EF",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/3213501caffe4cb5_hotfixdefs.cax",
        "ssdeep": null,
        "size": 1624315,
        "sha512": "b7e440f67c8c745a694a2791c5b2d1a060609b9bb2121f8e58e691cea9f78cf3a8889f3480bde832ddbe12bc97f264f68e117022fb26911cc428e20c890e0195",
        "pids": [
            2740
        ],
        "md5": "9d13bbd02ca3356110e78d36929fd54b"
    },
    {
        "yara": [],
        "sha1": "f620eacfe3429b4ac848e88216d5e08947e0722c",
        "name": "098a0093519a12a8_bar2.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\bar2.gif",
        "type": "GIF image data, version 89a, 1 x 5",
        "sha256": "098a0093519a12a8f2fe1b76c5d6502a9f48fae8acd49567bbdb47acb47adc72",
        "urls": [],
        "crc32": "31EA3A62",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/098a0093519a12a8_bar2.gif",
        "ssdeep": null,
        "size": 42,
        "sha512": "a546ea1f8a2fa95597b9caad5d7e9aca4b9cc91775e916122025f2d0b0cbb924865b7abe278fc145e8d4f564daf148dd6d2f2b1e5d61942e572279b6f784e2e1",
        "pids": [
            2740
        ],
        "md5": "207067dd6124bdaea177c297bc957ed4"
    },
    {
        "yara": [],
        "sha1": "686ff8e30b82ffca4f991b71bf0fcce1000bf546",
        "name": "8df4016e049186b3_summaryqferecentempty.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqferecentempty.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "8df4016e049186b3d143323859af93e98ec5c203f4f7c1a4c71c543df9aec096",
        "urls": [],
        "crc32": "B0AAD27C",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/8df4016e049186b3_summaryqferecentempty.html",
        "ssdeep": null,
        "size": 128,
        "sha512": "a52799a1cd441e476460893ae81d93f5a85dac0ac3a4738d1fd529959a1154cf981d9acf0223d2707f20d1955d09ea9c88b0de42fac45a54f5ed0713aef5e98f",
        "pids": [
            2740
        ],
        "md5": "bdfba144c276f0ff0ed5afccbed94606"
    },
    {
        "yara": [],
        "sha1": "78754ab513dbe6f9d0aaacc81868f014dca30271",
        "name": "dd8010f75fb363f9_shfs1.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\shfs1.gif",
        "type": "GIF image data, version 89a, 13 x 10",
        "sha256": "dd8010f75fb363f9363c2ca5245d4b20d54ca1619bb7aac22f8f1a3234a6360a",
        "urls": [],
        "crc32": "64D56731",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/dd8010f75fb363f9_shfs1.gif",
        "ssdeep": null,
        "size": 65,
        "sha512": "d77c99f154c88554cac531340804bfeb8cb6ca3a81becb55e54d0af896bcf9e8ec4d3b550893af66c3430336f91d68ac33b2ef8ff7d4e8633d6b47c6f0735b25",
        "pids": [
            2740
        ],
        "md5": "15ed20954fa67d8d5f7e6ee4d4045795"
    },
    {
        "yara": [],
        "sha1": "71d4180327373c4898726a1bfa83ae86f8737641",
        "name": "098306ec0d3d991e_summarylocaldriveitemlinux.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylocaldriveitemlinux.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "098306ec0d3d991e9c29908187293c38418dbe91268cc175bae187042d341b86",
        "urls": [],
        "crc32": "CD466710",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/098306ec0d3d991e_summarylocaldriveitemlinux.html",
        "ssdeep": null,
        "size": 228,
        "sha512": "b573a5b098e108ec16e5474f739a02b5b582fc6a869d7000c6241fef1872e64163e4d8d1c161327f75556c6bc913cf53d59ac7b1733976f1d79eb43d4a8ba059",
        "pids": [
            2740
        ],
        "md5": "b1bef50ac4a7291d62f842cedecbd142"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "4ed4b4ab15e42381f562d095f550662803dc1f33",
        "name": "2a2ae1e30de432c0_belarc advisor.lnk",
        "filepath": "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Sat Nov 23 19:53:15 2019, mtime=Sat Nov 23 19:53:15 2019, atime=Sat Jan 26 02:04:36 2019, length=134824, window=hide",
        "sha256": "2a2ae1e30de432c00167fad9313803ff66db4592d523d8349ff50869d4b8dee4",
        "urls": [],
        "crc32": "82296D0C",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/2a2ae1e30de432c0_belarc advisor.lnk",
        "ssdeep": null,
        "size": 2120,
        "sha512": "3599d1867c13ccaa950b2bdd824400cbface6b9dd8eefcf9ca3ae2e0ca9fdf35476bea64aa1774ba93597f8a05ba0e162d0e60ed15a0eeec1456c9a08abec5a7",
        "pids": [
            2740
        ],
        "md5": "6d6513d2c2213147752ec69b63429152"
    },
    {
        "yara": [],
        "sha1": "597aa7508e98d33b1b6d50d723adb2bd331ac22c",
        "name": "03c50e238bd50683_securitypanelav_alert.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelav_alert.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "03c50e238bd5068366375a065f1802721df6f7584cd994c680741c23f806a554",
        "urls": [],
        "crc32": "F27B3BAB",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/03c50e238bd50683_securitypanelav_alert.html",
        "ssdeep": null,
        "size": 405,
        "sha512": "d03e2f464e008b0833e67a9a72c5d51649e48e52e8bb72fe56c2813ca85b47f84c904a6447568cb2e4b15367a2bdf0e0e892fc8c5efbc96132a4d85ef2d58ac1",
        "pids": [
            2740
        ],
        "md5": "edb9507c8e42b8dc0a145f55ebb4525b"
    },
    {
        "yara": [],
        "sha1": "7231268c5c15823b7b8dc3e8183201f47eeb12c4",
        "name": "5b73822f2281e665_sp_s10.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s10.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "5b73822f2281e6654911cc2d801e4c9decfb3f7c6deef3d2150e486fddc9732b",
        "urls": [],
        "crc32": "CEEDF483",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/5b73822f2281e665_sp_s10.gif",
        "ssdeep": null,
        "size": 1197,
        "sha512": "81096d032d498e6774dfc93d6e5787462e80c779148e1fa2c6d15372d65a5012a324f3499fd76001ca7b50635b1ed5baabce8b3b6bc9642e400e82f6bd71cbb8",
        "pids": [
            2740
        ],
        "md5": "36f62ab24c67539041e5e537cb762590"
    },
    {
        "yara": [],
        "sha1": "2daeaa8b5f19f0bc209d976c02bd6acb51b00b0a",
        "name": "b1442e85b03bdcaf_trans.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\trans.gif",
        "type": "GIF image data, version 89a, 1 x 1",
        "sha256": "b1442e85b03bdcaf66dc58c7abb98745dd2687d86350be9a298a1d9382ac849b",
        "urls": [],
        "crc32": "9ACCEAB1",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/b1442e85b03bdcaf_trans.gif",
        "ssdeep": null,
        "size": 43,
        "sha512": "717ea0ff7f3f624c268eccb244e24ec1305ab21557abb3d6f1a7e183ff68a2d28f13d1d2af926c9ef6d1fb16dd8cbe34cd98cacf79091dddc7874dcee21ecfdc",
        "pids": [
            2740
        ],
        "md5": "325472601571f31e1bf00674c368d335"
    },
    {
        "yara": [],
        "sha1": "92035556c43da7f4428c824f7602063a722ededf",
        "name": "319ddac0f4933181_summarygrouppolicy.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarygrouppolicy.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "319ddac0f49331815ea38cb95a78c76d2c6e2eb1e54e49a5b105a8a9051063c1",
        "urls": [],
        "crc32": "78649D4E",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/319ddac0f4933181_summarygrouppolicy.html",
        "ssdeep": null,
        "size": 382,
        "sha512": "04213771d22a74df70d75315f176b2fa9b1806a19ccab193b003bf382a2cbe6858343daf328d7046926e3a177dc3945815b7c489bd5ab2b772c5e04480e99fda",
        "pids": [
            2740
        ],
        "md5": "489442fb0cac204ca954386d6f211ac6"
    },
    {
        "yara": [],
        "sha1": "0419cb772116d54accd4d27f428ceb13da2d5142",
        "name": "f10019cf9c392c09_~GLH0005.TMP",
        "filepath": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP",
        "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
        "sha256": "f10019cf9c392c093f4d65e82da323285c1ca14aef6ea80054ab93af65a5d661",
        "urls": [
            "http:\/\/www.usertrust.com1",
            "http:\/\/ocsp.comodoca.com0",
            "http:\/\/crl.usertrust.com\/UTN-USERFirst-Object.crl05",
            "http:\/\/crl.comodoca.com\/COMODORSACertificationAuthority.crl0q",
            "http:\/\/crl.comodoca.com\/COMODORSACodeSigningCA.crl0t",
            "https:\/\/secure.comodo.net\/CPS0C",
            "http:\/\/ocsp.usertrust.com0",
            "http:\/\/crt.comodoca.com\/COMODORSACodeSigningCA.crt0",
            "http:\/\/crt.comodoca.com\/COMODORSAAddTrustCA.crt0"
        ],
        "crc32": "E0884AEE",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f10019cf9c392c09_~GLH0005.TMP",
        "ssdeep": null,
        "size": 129720,
        "sha512": "7a4862ac704072336e188882f7d139f01095e27c71a9229ccf7ced0668d768767d5979d152ec12076634411abe80b1d1292c7485389de39d079581fc557ea126",
        "pids": [
            2740
        ],
        "md5": "4d11999a3fd88be4728727606a233950"
    },
    {
        "yara": [],
        "sha1": "3a36aef3671bc1fcd812c121522680ed6d689e94",
        "name": "b8347d509eafa5a6_sp_s7.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s7.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "b8347d509eafa5a627e90510d3ddcf2bbd1b33294d2017d39ea7ae3f34cf3fdf",
        "urls": [],
        "crc32": "F86010D2",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/b8347d509eafa5a6_sp_s7.gif",
        "ssdeep": null,
        "size": 1195,
        "sha512": "31e7b0b2f1b6b91e419db304924e30a5bbcbf50037ac1b9d97755701fe364e655752dccbc97534265ebf0dbaccd4e5635af8609c8db5c37cabdf1eb519d0cb48",
        "pids": [
            2740
        ],
        "md5": "a6c4055a9bf36f69055f49c12325de38"
    },
    {
        "yara": [],
        "sha1": "02ca3280439853b4c5f871f17d2863d9b41b69a9",
        "name": "f3dbd3415d10df60_securitypanelav_unknown.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelav_unknown.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "f3dbd3415d10df60e78a7128f8d2a935642fa9da9503875af8718d5a549a46fd",
        "urls": [],
        "crc32": "5333768C",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f3dbd3415d10df60_securitypanelav_unknown.html",
        "ssdeep": null,
        "size": 373,
        "sha512": "d53f71d171c77d6dc310264473e5f4b7d60f8686c3dae4b6a2a07b8d2883870bc48e163f3fec648ac5e1c9b8c04025f73308ff059f75ca63363d66941c11a6d6",
        "pids": [
            2740
        ],
        "md5": "f4814f41b14ed480a7c5c91cba4fb7c9"
    },
    {
        "yara": [],
        "sha1": "bd2c2c82175e24c73735144de4be3d312dec2f47",
        "name": "0e4e080bfead99c6_summarylicenses.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylicenses.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "0e4e080bfead99c6f54eb065b695d0b0e9aa20dc8f30b59c7dc447c9547ece3f",
        "urls": [],
        "crc32": "5EF02942",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/0e4e080bfead99c6_summarylicenses.html",
        "ssdeep": null,
        "size": 178,
        "sha512": "aa45c6aaa49346b29d1a58461eea26a4414fe0f583dc9564b07247580db23f997706fbe31fbb6f3e31110dfda8f106e81e47e4f5f63758ec59e7765400e488d9",
        "pids": [
            2740
        ],
        "md5": "02b4908c863167a7a0585caec236d6af"
    },
    {
        "yara": [],
        "sha1": "d2223598861d59e06b053723207c806f96671bf4",
        "name": "7997c13bb6f36f5f_summarylicenseformats.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylicenseformats.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "7997c13bb6f36f5f03e1ffe0af7133958d0e0a71e2a45d30060ea7e516819254",
        "urls": [],
        "crc32": "29C344D1",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/7997c13bb6f36f5f_summarylicenseformats.html",
        "ssdeep": null,
        "size": 256,
        "sha512": "4390411fc86f0121c7135f442041ffc33892fe42279c84f98feadf0329ec0111b5a285618e1342e3aae84fd47cae29aa1d5e630c1afacc474e43597619b3bac7",
        "pids": [
            2740
        ],
        "md5": "15bf16411783351c833a138afac93eb1"
    },
    {
        "yara": [],
        "sha1": "4e4095ea14e1a29728f909164c25b9e1aa96b57a",
        "name": "864e419cc10c3198_summaryoupath.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryoupath.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "864e419cc10c3198851fc5afb914830e609420646d5e69ceb9381b73d850700a",
        "urls": [],
        "crc32": "ACA3EEA8",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/864e419cc10c3198_summaryoupath.html",
        "ssdeep": null,
        "size": 97,
        "sha512": "df7b8786b9e4a737b446053c8515606947644db40540438ee8baa8b3255932cc6971468c0583a2b80651222797668fc902ba4451c95f0cdc29cb2b460cf4f41f",
        "pids": [
            2740
        ],
        "md5": "dd9aed1fc65764dfe1a7e0fc5f8a50ca"
    },
    {
        "yara": [],
        "sha1": "43a33ae14d760042f9429ca2eb97dff02aed0de3",
        "name": "049cb66277802812_GLG63F1.tmp",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp",
        "type": "diff output, ASCII text, with CRLF line terminators",
        "sha256": "049cb662778028121282078130a4a1efe2a1b19cc88613062114cba69f2093e1",
        "urls": [
            "http:\/\/www.belarc.com",
            "http:\/\/www.belarc.com\/download.html"
        ],
        "crc32": "6512FF82",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/049cb66277802812_GLG63F1.tmp",
        "ssdeep": null,
        "size": 22542,
        "sha512": "d0b7321d5efeac6226028cc6882194fa089f31234813b12f9d0eb88cbbb6391f5edd9d40cefbd4d187735784d35b5427bf405ca14be7da4ece8120550cf1ecbf",
        "pids": [
            2740
        ],
        "md5": "915e24ce22b13d439f217a0f67a6808c"
    },
    {
        "yara": [],
        "sha1": "afb7b81da96f372a22428d679b4314e345f9ae02",
        "name": "47f389de70e6277c_fdcc - windows xp,v1.2.1.0.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarks\\fdcc - windows xp,v1.2.1.0.html",
        "type": "HTML document, ISO-8859 text, with very long lines, with CRLF line terminators",
        "sha256": "47f389de70e6277c590c95a0402cc5cae5b66e606b9f60cf0acdbc9c76e11382",
        "urls": [
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2147",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2145",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3084",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3085",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3088",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2220",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2688",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3035",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3034",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3036",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2683",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3888",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3929",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3081",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2455",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4564",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?1937",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4047",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4040",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4043",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2855",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3518",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2851",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3696",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2915",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2916",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2910",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2913",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3100",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3103",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4215",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3107",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3106",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3038",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3216",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3213",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2259",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2684",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2674",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2675",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2672",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2777",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2776",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4139",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3601",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3996",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3993",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3855",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3853",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3998",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3284",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5200",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2807",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?1978",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2178",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2176",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2175",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2710",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2173",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2559",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4001",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3976",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5025",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5022",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4791",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4793",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3553",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4707",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4160",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4098",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4099",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?1909",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4997",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2958",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2894",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2896",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2898",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2950",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2955",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2954",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2957",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2956",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2731",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2735",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2828",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2737",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2824",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2826",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4175",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4174",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2791",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3258",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3150",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3151",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3156",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3157",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3154",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3155",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3124",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2239",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2609",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2692",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2693",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3026",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3027",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3025",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2699",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3744",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3933",
            "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/WinXP-FDCC-V1.2.1.0.htm",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2344",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2466",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2198",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4513",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4053",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4050",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4581",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5055",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5054",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5053",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2994",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2996",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2991",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2993",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2906",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2904",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3564",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3116",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4224",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4732",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3110",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3111",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3118",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3162",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2860",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2864",
            "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/WinXP-FDCC-Firewall-V1.2.1.0.htm",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2767",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4122",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4643",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4641",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3201",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3207",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3204",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2797",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3706",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2247",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2792",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4079",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3058",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2799",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?1969",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3338",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2494",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2167",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3061",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3018",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2546",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2547",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2891",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3012",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3014",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5136",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4017",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4013",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3945",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3941",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5014",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4018",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2899",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2335",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2336",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3751",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4262",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3400",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4062",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4066",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?1916",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2829",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4068",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5160",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2948",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2944",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2942",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2726",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2833",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2830",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2933",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2930",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4162",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4163",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2935",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4161",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3247",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3128",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4763",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3122",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3236",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3235",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3623",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3584",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4119",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4118",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4110",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3337",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3053",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2299",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4953",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3754",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4952",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4849",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4845",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2052",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2472",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2476",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2573",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3909",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2184",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5194",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3902",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3905",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3906",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5121",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4026",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2379",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2989",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2983",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2980",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2981",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2986",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2987",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2974",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2973",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2972",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2971",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3576",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3570",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3172",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3198",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3176",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3179",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2878",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2873",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2657",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2652",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2718",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2802",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2713",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2806",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2804",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4153",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4150",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4652",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3273",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3378",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4158",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2784",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2786",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3875",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3304",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2788",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2789",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3090",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3097",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3094",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2021",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3000",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3004",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3005",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3006",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3007",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5099",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3891",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3894",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2439",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2436",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2326",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2446",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4270",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5072",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2928",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2846",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4196",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2841",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2920",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2923",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2926",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4202",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3139",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3134",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3135",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3131",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3132",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3133",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3590",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3183",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4132",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2700",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2661",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3619",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4109",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2213",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4101",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4104",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3040",
            "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/IE7-FDCC-V1.2.1.0.htm",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3043",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3048",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3049",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3291",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2847",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4192",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2100",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2842",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3914",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3963",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2849",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2366",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2313",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2312",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2965",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2960",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2961",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4242",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4084",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3141",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2882",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2880",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2886",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2889",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2888",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2818",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2810",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2814",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2701",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2816",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4147",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4887",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4143",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3265",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4149",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3262",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3866",
            "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3867"
        ],
        "crc32": "93F24FC5",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/47f389de70e6277c_fdcc - windows xp,v1.2.1.0.html",
        "ssdeep": null,
        "size": 202571,
        "sha512": "ed0973460ef305d4093d8cdbfab0d04883ab7a45d1d71113818e46026bae880c52ac026e5a73b054a87ceb2018196da65a5b8360387d4f5b190eb413b88a3064",
        "pids": [
            2740
        ],
        "md5": "4f2ef98fb1d70a188de381c48a04896f"
    },
    {
        "yara": [],
        "sha1": "c0125e31480a303f3f0b53e6f576d0141ded6cff",
        "name": "11fd457a46f566fd_benchmarkhelp.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarkhelp.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "11fd457a46f566fdbde209fc4cb3f257e3e424bba72a2e15503c770a44b30c94",
        "urls": [
            "http:\/\/usgcb.nist.gov",
            "https:\/\/www.csiac.org\/journal\/security-benchmarks-gold-standard",
            "http:\/\/fdcc.nist.gov",
            "http:\/\/www.belarc.com\/whitepapers.html"
        ],
        "crc32": "60BED9F7",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/11fd457a46f566fd_benchmarkhelp.html",
        "ssdeep": null,
        "size": 3521,
        "sha512": "3acd441db002a937e57027e6a5d9617cf54a56284cd3538d8545f7b6d390d43276f648d5478645b8121ed1fc89fca683232b9a75849f475ee42bbac88d065295",
        "pids": [
            2740
        ],
        "md5": "360733cbe3db7d8ab08aa98f270a3137"
    },
    {
        "yara": [],
        "sha1": "9aaa6ed98726e657252a098f2bf06066a8604d27",
        "name": "e362a9815527869e_GLF63F2.tmp",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
        "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
        "sha256": "e362a9815527869e0f71fdf766a1c3648e307145defda7a5279914e522bcb57c",
        "urls": [],
        "crc32": "5460133E",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e362a9815527869e_GLF63F2.tmp",
        "ssdeep": null,
        "size": 10752,
        "sha512": "f8b4129dc4ab30e009cb4db8a80f06b16306c1a90a49e534befb925d6ce4d5713b98553a2107b40efa8b5abd025ff0556976cf46c3642ce8e372c34d105e36cb",
        "pids": [
            2740
        ],
        "md5": "9da8f742593d4bbca708b90725282ae2"
    },
    {
        "yara": [],
        "sha1": "45655d80806e4cff3b438f5b9ef792b25bda8aed",
        "name": "ff09243c8f562219_summaryloginsfooter.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryloginsfooter.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "ff09243c8f562219e55eea7a12e94851c6ee05e1720079f7dbe48112e23bdd2c",
        "urls": [],
        "crc32": "E2B5EB7B",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ff09243c8f562219_summaryloginsfooter.html",
        "ssdeep": null,
        "size": 309,
        "sha512": "69dfb0b6b657646bec9554c241835448004e4f1bf7ffb4e2ec61f041eb07d10f410437b716bb2c0da88de62774657a49dab6a99f3b4c6fd860979fd22a1deb9b",
        "pids": [
            2740
        ],
        "md5": "57be666b8d03cda7a5cdba7ba8d3545c"
    },
    {
        "yara": [],
        "sha1": "b6b948aeaa726d238e5a294143777145a4b55720",
        "name": "2c55145e4c2382cd_sp_s16.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s16.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "2c55145e4c2382cdaff56fe35207988b34eafcd5c01b209d099b61fee22c95eb",
        "urls": [],
        "crc32": "7897EFE1",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/2c55145e4c2382cd_sp_s16.gif",
        "ssdeep": null,
        "size": 1131,
        "sha512": "fb518cb04dd7bed969d08c2a5b105ff7c481006d8ed39bae3af3db00ccd68f9b4c96d322e75bc6cb27954b6ecaf25e6f931d77756699b6cd379d7b528b09deca",
        "pids": [
            2740
        ],
        "md5": "3e060efed86cd4c9db67badcf21f769d"
    },
    {
        "yara": [],
        "sha1": "99170bbcf46d8561027f199b2385c5f14458f033",
        "name": "2b53a98c0c179125_sitedefaultsummary.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\sitedefaultsummary.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "2b53a98c0c179125f43d9b9c8758b5506ef3c0bf848ea73d6ef8eca23caf8ddb",
        "urls": [],
        "crc32": "115BFB3E",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/2b53a98c0c179125_sitedefaultsummary.html",
        "ssdeep": null,
        "size": 1394,
        "sha512": "daee136393f9f21bd4be436021114f695c0712f36ddb765866a03f739e8998c22e1fd77310543cd38b08ada964afa3356633400a26408f6aee2416806bca7e1b",
        "pids": [
            2740
        ],
        "md5": "cf1284372fb8bcfbac599340da5fb339"
    },
    {
        "yara": [],
        "sha1": "2bc5e975796de5d0df3db69aa3c95491eac4349f",
        "name": "d111a95011c775ea_sp_s8.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s8.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "d111a95011c775eab620f4d49fd01726986cad8839a917103818d8454f9c0ead",
        "urls": [],
        "crc32": "A03271DD",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d111a95011c775ea_sp_s8.gif",
        "ssdeep": null,
        "size": 1162,
        "sha512": "fb3bfb4e7fa19d5bb704a5da4c9c9ac581528ebfd58ad566f7206fb8d89dc2e9c2244551cc4217c520cf95e2af3e8099e6a8d96cf533c23066ec8c798b319a09",
        "pids": [
            2740
        ],
        "md5": "37729a73d97c3d2aa97b18cf76b6271a"
    },
    {
        "yara": [],
        "sha1": "8c70a89b480fac71d554ac790cef9b133a783850",
        "name": "ce76f733876eb633_summarycopyright.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarycopyright.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "ce76f733876eb633ac352b90e3cb85da877c31dcb6887220850a31779166de2f",
        "urls": [
            "http:\/\/www.belarc.com\/Advisor2\/legal_notice.html"
        ],
        "crc32": "118BFA7F",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ce76f733876eb633_summarycopyright.html",
        "ssdeep": null,
        "size": 297,
        "sha512": "fd1a3dfa1eb9e36d7b807af9bf9a7f34c9b68be16a436f00b006a05d9d2617568d4d0ebf68a3c56b1b534f3d8968a10465a1db3fe07466f72c92dab5db1429a7",
        "pids": [
            2740
        ],
        "md5": "a8cb97667d146f8c394d195a248d3898"
    },
    {
        "yara": [],
        "sha1": "abd3e9908da42748876a0f0ccec2e4d3a5a0d150",
        "name": "cb3621f7599cbbe7_brandname.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\brandname.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "cb3621f7599cbbe7f5ee57b26319fe911cb584c5adcb9e728ce8a38686926b6b",
        "urls": [],
        "crc32": "F0CD7E37",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/cb3621f7599cbbe7_brandname.html",
        "ssdeep": null,
        "size": 102,
        "sha512": "efcbfd0e7da441c5a1f4226e4a905c7e67e7dd3b713815d25a0eccfac335c264371d8378fad929e487cd5088eb73e9a56bc45b7a27548e2e03ade105a9b47a1c",
        "pids": [
            2740
        ],
        "md5": "5c3d0f639b7e125c187f9b0cf9d29ef6"
    },
    {
        "yara": [],
        "sha1": "204840f2d86c8f5b3121fea7e5e06b0363cfbee7",
        "name": "4c218056669668a0_summaryqfemissingitems.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfemissingitems.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "4c218056669668a01f33abb59bd1208c77f01de5fede27b0983e8d67811e0acb",
        "urls": [
            "http:\/\/www.belarc.com\/cgi-bin\/qferefer?%1"
        ],
        "crc32": "3F21A964",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/4c218056669668a0_summaryqfemissingitems.html",
        "ssdeep": null,
        "size": 1058,
        "sha512": "0a87cb4c9e687e52978628ae6f1d61142acca5a435803404ea4689f8d11f537a9f20da9d8bc83b0e6818dc8e06ed2f8bdaff0631ac81e00ef96995ebc287514d",
        "pids": [
            2740
        ],
        "md5": "2c064be20d323bf99f6c6146fc01d63a"
    },
    {
        "yara": [],
        "sha1": "f4f7db1397a3eea8d09d5350a2cb7ccf2a310ccb",
        "name": "d08d9a1438bbe5fb_securitypanel.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanel.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "d08d9a1438bbe5fb9f8b3a444bb9b922d280f11bfce2080ccbaa104fdead574b",
        "urls": [],
        "crc32": "22042120",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d08d9a1438bbe5fb_securitypanel.html",
        "ssdeep": null,
        "size": 940,
        "sha512": "a979170dcd556269a62be40247cb9dce045aa599bc913dfb561509da03b56fae16d612381ceed488f1ee9b3702022f1449f4293efb85e14c2b63d438e351e7e8",
        "pids": [
            2740
        ],
        "md5": "4add6701e4bcd7bd139e16258edd4ceb"
    },
    {
        "yara": [],
        "sha1": "5da963ffede5619ff8e20e6fc3947b66396609ba",
        "name": "e7686cf33ecf77a3_summarylan.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylan.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "e7686cf33ecf77a395b929c4664dad41a07602f1f7d172b382ba725bc8d0afa2",
        "urls": [],
        "crc32": "FDCD8645",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e7686cf33ecf77a3_summarylan.html",
        "ssdeep": null,
        "size": 255,
        "sha512": "f2d2054f88fd603d2e730edca739221686e4c60ba1918c54589da82ae73cf655b0d5475cb8bae46d488caa0b966d38a71696a4f2548bd85826031004d9d96bab",
        "pids": [
            2740
        ],
        "md5": "6c5480c777f7d1c66d7c7fd2fd3b92ed"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "f41e92e183bcb4a3a00497f30975778fa4c7a142",
        "name": "22ebcb8de89a0d00_belarc advisor.lnk",
        "filepath": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Sat Nov 23 19:53:15 2019, mtime=Sat Nov 23 19:53:15 2019, atime=Sat Jan 26 02:04:36 2019, length=134824, window=hide",
        "sha256": "22ebcb8de89a0d00863bc22f3140fcbcbe2d8b02dfed16018e2b2c03d4b72088",
        "urls": [],
        "crc32": "D54B0125",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/22ebcb8de89a0d00_belarc advisor.lnk",
        "ssdeep": null,
        "size": 2132,
        "sha512": "8ce361e11aa591be2769ae0bde4f98c7cf329f1b799385467223d30156cb89d17cec233b064bf0599c50f29729a7195913462e3bf260475f7175ece4957c79a5",
        "pids": [
            2740
        ],
        "md5": "3949cd4c5c9c9d720417a4e8ca6b4578"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "eca9d479f7eeb179ae68694f8558bb2a21a7a2a6",
        "name": "61d77930ad503687_belarc advisor.lnk",
        "filepath": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Sat Nov 23 19:53:15 2019, mtime=Sat Nov 23 19:53:15 2019, atime=Sat Jan 26 02:04:36 2019, length=134824, window=hide",
        "sha256": "61d77930ad503687f7fa66e5ded7dea006cbbd76c8e2abf023692bcc063eb059",
        "urls": [],
        "crc32": "25A55DA1",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/61d77930ad503687_belarc advisor.lnk",
        "ssdeep": null,
        "size": 2144,
        "sha512": "47ff14adb623269ff33eef32bc6876f6e179621be1786c91f0f1f424c1c7a136f3948205a25d0e15d0aac2cffd8c2a9a801fa8b9a595d2de774b6d38ecb2f292",
        "pids": [
            2740
        ],
        "md5": "d22b5342721c0339615618e77a598221"
    },
    {
        "yara": [],
        "sha1": "26124f69a47aa7efcce20c498be302ccdd7ec365",
        "name": "3b9c326820af42b7_summaryqferecent.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqferecent.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "3b9c326820af42b77dad54efd89bf6e53c2972c477962623f100f0dd3ab84f94",
        "urls": [],
        "crc32": "7ED0ABD9",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/3b9c326820af42b7_summaryqferecent.html",
        "ssdeep": null,
        "size": 386,
        "sha512": "b2e70b509cf62165be9d549df1846146ead9cdd8276060996faa021d6fca9d4529837529b553b94c382c429096627fdc15ae3526c34e73fc57ce4beed85ddab0",
        "pids": [
            2740
        ],
        "md5": "1a06d6483beebb76b5db5d5f1b0d2444"
    },
    {
        "yara": [],
        "sha1": "88e365bc395f6cf7cea65cdd937d35391432ddae",
        "name": "ab44800765487575_black.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\black.gif",
        "type": "GIF image data, version 87a, 1 x 1",
        "sha256": "ab44800765487575508351c488398646a5c7b5d01e121cfbd70b37bfeba93a0d",
        "urls": [],
        "crc32": "62EEB30C",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ab44800765487575_black.gif",
        "ssdeep": null,
        "size": 35,
        "sha512": "328e58854ab8a1a30230f711fca584f7ff6ecf23b77627e3f5e4da27be573def6da42e2047781aea47132c6d83d95cd28456e82a837145d6173720d4e9cbf746",
        "pids": [
            2740
        ],
        "md5": "54bcf265c60042adbbc35215aaf86bf6"
    },
    {
        "yara": [],
        "sha1": "1638721af45e01d3506bfb77ff00ce2f6638c090",
        "name": "d7101488ce0dfaa8_summarynet.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarynet.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "d7101488ce0dfaa885e71204f3d480f868e83dc5cb953d4c42e50709505b3d22",
        "urls": [],
        "crc32": "6A2F4724",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d7101488ce0dfaa8_summarynet.html",
        "ssdeep": null,
        "size": 194,
        "sha512": "18ff6ee5927928edc968352b0adf14580b776081f1e62364a1e4f3ccd7db85e2e8984f4befcc7b378794c7132038a0709c49dd582f8a09ab746e37e321939bb6",
        "pids": [
            2740
        ],
        "md5": "85f7a4aed1bbec6b382069ed170e7da3"
    },
    {
        "yara": [],
        "sha1": "371d19942006bf5ae2b1c0eb6f8f9386a34563b0",
        "name": "f9982fa41942dd67_BAlicense.txt",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "f9982fa41942dd67d8be1f6fce9aa4b1e6fc2dfc6e2ad7e23b073d3fe9420e6d",
        "urls": [
            "http:\/\/www.belarc.com"
        ],
        "crc32": "4DD6F4F1",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f9982fa41942dd67_BAlicense.txt",
        "ssdeep": null,
        "size": 4485,
        "sha512": "567a8944b3476e25b66159070a07c49ca3e4100bd51a40073cdf68a7c2c612fb2050d1586752ee3302bbd8447220e9dc24033c9040d009d42d3d5d7253a97d9e",
        "pids": [
            2740
        ],
        "md5": "df8145a6613a01542696625ccc502898"
    },
    {
        "yara": [],
        "sha1": "9411764e3d85035c3fc14a1d4b64f594ae969416",
        "name": "953f7968829ded7c_summarylocaldriveitem.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylocaldriveitem.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "953f7968829ded7c549d60739e6048b32bc47fc4ea3e76562137c05f265f1407",
        "urls": [],
        "crc32": "D3F4D13E",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/953f7968829ded7c_summarylocaldriveitem.html",
        "ssdeep": null,
        "size": 241,
        "sha512": "61c685749d0daee3f5b2a89d6e2182bb507c268b8396bbe34011421f51d03f5708f9cabed23ed009b917102fbada66c6ad5dfd99d0854057e56d8db6074973d1",
        "pids": [
            2740
        ],
        "md5": "df11aecb3f919eb9afdf4c39b355bd43"
    },
    {
        "yara": [],
        "sha1": "0f1405c1a4669fae9f361630cc6850b640d6ede5",
        "name": "cf3ab6c2a33dba1c_summarynetworkdrivehdr.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarynetworkdrivehdr.html",
        "type": "exported SGML document, ASCII text, with CRLF line terminators",
        "sha256": "cf3ab6c2a33dba1cf8028b1d097d286de0331324765bd7cfbe6f2b7ece9972f1",
        "urls": [],
        "crc32": "563D9E22",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/cf3ab6c2a33dba1c_summarynetworkdrivehdr.html",
        "ssdeep": null,
        "size": 135,
        "sha512": "4a51a992e4a5034795ea499111457e4d8e3109833ecf41c04b385fc5f77e61a579f7d8086af2b2388818bc0ce9b443cb62640bffb7ade7aadbb07253aae051cd",
        "pids": [
            2740
        ],
        "md5": "01fcfcb33c29eb9b19eb8ebb7477ff30"
    },
    {
        "yara": [],
        "sha1": "79cb27bfa9f36574805cb6461b950e354ed84221",
        "name": "2ae18b89fc5c51bf_summaryqfe.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfe.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "2ae18b89fc5c51bfeb44cd3d3fb73bd86d115a82fd3e716e1027bc6d2b700964",
        "urls": [],
        "crc32": "7EBEB938",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/2ae18b89fc5c51bf_summaryqfe.html",
        "ssdeep": null,
        "size": 515,
        "sha512": "d4fa145822ec722bbab1becd3f7fbe4836c0672fa4ab4a5f304518c7e846f7cf178cc9d6c716a48b279137b2cb16b57ebf45da9423fb9e52a9e961eba410a624",
        "pids": [
            2740
        ],
        "md5": "690dce20db563a7f2e3ce92ba9706842"
    },
    {
        "yara": [],
        "sha1": "8183178b535a2b6e94a97aa8d8a0440047fe1e0b",
        "name": "1c328e592e9b7e6f_summaryqfeitems.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfeitems.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "1c328e592e9b7e6fc823b1f44da20e53833090335764d939fae54d3286a9c5c8",
        "urls": [
            "http:\/\/www.belarc.com\/cgi-bin\/qferefer?%7"
        ],
        "crc32": "4A4C1038",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/1c328e592e9b7e6f_summaryqfeitems.html",
        "ssdeep": null,
        "size": 939,
        "sha512": "30877a552b692a9ac77f7adbbaf905b2fbd0c4712ecea126ef56326c4ba86c412e88c0327fbc9f25284dbec38298c42749701bcedcd07cb4274c7523a648dbeb",
        "pids": [
            2740
        ],
        "md5": "f488e20f0a076ef8ef945f57d1e0c9de"
    },
    {
        "yara": [],
        "sha1": "80cf0399b7584de9ca760e2eefb055d9fab50bdc",
        "name": "379e1070c78bff65_summaryantivirus.html",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryantivirus.html",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "379e1070c78bff65428a48b768e77801045765de5fe0a96113af061dedb7b015",
        "urls": [],
        "crc32": "26BF2710",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/379e1070c78bff65_summaryantivirus.html",
        "ssdeep": null,
        "size": 98,
        "sha512": "ad82d35599bba939a129062306280d23869337509de2ca0db8f0bc2cbed003a49c4b609599670622c8976305eeb46a7e903eba5f411a7619c7bbe07e5388b2c0",
        "pids": [
            2740
        ],
        "md5": "88ca4580bc39c745d949aac8640027a9"
    },
    {
        "yara": [],
        "sha1": "e08d4f3aba109bb29273dc0183cafa053631f062",
        "name": "f9df7b68baab06cd_sp_s9.gif",
        "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s9.gif",
        "type": "GIF image data, version 89a, 24 x 24",
        "sha256": "f9df7b68baab06cd19a213cc8bc604fa608577d906e336097bdd1e3a8f19485a",
        "urls": [],
        "crc32": "9763B2E3",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f9df7b68baab06cd_sp_s9.gif",
        "ssdeep": null,
        "size": 1194,
        "sha512": "fd91150cbb44f3bb9d5126a4e763f9095f6ccc995cf717d48da31c6ca7d1a42516e54da217d254cc7395e67540b6fbdd7b1e88422412ac1c4ec83750bf7c3772",
        "pids": [
            2740
        ],
        "md5": "125dcb9a29a2c474bb7441f5a3ec6a0a"
    }
]

Generic

[
    {
        "process_path": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
        "process_name": "BelarcAdvisor.exe",
        "pid": 2648,
        "summary": {
            "regkey_written": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\UuidMethod",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileDirectory",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableFileTracing",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionReason",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\ConsoleTracingMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\MaxFileSize",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecision",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadNetworkName",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionTime",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Serial Number",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableConsoleTracing",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileTracingMask"
            ],
            "dll_loaded": [
                "C:\\Windows\\system32\\wininet.dll",
                "C:\\Windows\\System32\\mswsock.dll",
                "CRYPT32.dll",
                "DNSAPI.dll",
                "DHCPCSVC.DLL",
                "kernel32.dll",
                "C:\\Windows\\system32\\ole32.dll",
                "dwmapi.dll",
                "C:\\Windows\\system32\\napinsp.dll",
                "imm32.dll",
                "schannel",
                "API-MS-WIN-Service-Management-L1-1-0.dll",
                "PROPSYS.dll",
                "C:\\Windows\\syswow64\\MSCTF.dll",
                "WININET.dll",
                "OLEAUT32.DLL",
                "RASMAN.DLL",
                "ole32.dll",
                "C:\\Windows\\system32\\uxtheme.dll",
                "USER32.dll",
                "Comctl32.dll",
                "API-MS-Win-Security-SDDL-L1-1-0.dll",
                "API-MS-WIN-Service-winsvc-L1-1-0.dll",
                "wintrust.dll",
                "rtutils.dll",
                "IPHLPAPI.DLL",
                "C:\\PROGRA~2\\Belarc\\BELARC~1\\System\\NPBelv32.dll",
                "wininet.dll",
                "OLEAUT32.dll",
                "C:\\Windows\\system32\\pnrpnsp.dll",
                "SHELL32.dll",
                "RPCRT4.dll",
                "C:\\Windows\\System32\\winrnr.dll",
                "SHLWAPI.dll",
                "C:\\Windows\\system32\\NLAapi.dll",
                "C:\\Windows\\SysWOW64\\oleaut32.dll",
                "ADVAPI32.dll",
                "WS2_32.dll"
            ],
            "file_opened": [
                "C:\\Windows\\System32\\oleaccrc.dll",
                "C:\\",
                "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax",
                "C:\\Windows\\System32\\en-US\\wininet.dll.mui",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\"
            ],
            "regkey_opened": [
                "HKEY_CLASSES_ROOT\\.html\\OpenWithProgids",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\DnsClient",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\BELARC~1.EXE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
                "HKEY_CLASSES_ROOT\\FirefoxHTML-E7CF176E110C211B",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\OpenWithProgids",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\BELARC~1_RASMANCS",
                "HKEY_CLASSES_ROOT\\.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\msasn1",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\MS Shell Dlg 2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\DnsCache\\Parameters",
                "HKEY_CURRENT_USER\\Software\\Belarc",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE\\Tracing",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\shell\\open",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Connections",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Wpad",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32",
                "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\System\\DNSClient",
                "HKEY_CURRENT_USER\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}",
                "HKEY_CURRENT_USER\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\TreatAs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
                "HKEY_CURRENT_USER\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
                "HKEY_CURRENT_USER\\software",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler32",
                "HKEY_CURRENT_USER\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Belarc\\Advisor",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing",
                "HKEY_CURRENT_USER\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32",
                "HKEY_CLASSES_ROOT\\htmlfile",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Network\\Location Awareness",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\(Default)",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32",
                "HKEY_CURRENT_USER\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OleAut",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLEAUT",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\CurVer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_INCLUDE_PORT_IN_SPN_KB908209"
            ],
            "resolves_host": [
                "wpad",
                "cuckpc",
                "www.belarc.com"
            ],
            "connects_ip": [
                "127.0.0.1"
            ],
            "file_exists": [
                "C:\\Windows\\SysWOW64\\propsys.dll",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx",
                "C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\",
                "C:\\Windows\\System32\\propsys.dll"
            ],
            "mutex": [
                "IESQMMUTEX_0_208"
            ],
            "fetches_url": [
                "https:\/\/www.belarc.com\/Programs\/defs.xml?dv=2019.11.14.2&av=9.0&df=B&au=1.0.0"
            ],
            "file_failed": [
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System"
            ],
            "guid": [
                "{dcb00c01-570f-4a9b-8d69-199fdba5723b}",
                "{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
                "{a47979d2-c419-11d9-a5b4-001185ad2b89}",
                "{d0074ffd-570f-4a9b-8d69-199fdba5723b}",
                "{dcb00000-570f-4a9b-8d69-199fdba5723b}",
                "{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}"
            ],
            "file_read": [
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax"
            ],
            "regkey_read": [
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\UuidMethod",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\ConsoleTracingMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorUseSystemHeap",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\HfdefsUrl",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\FileTracingMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\MSBulletinVersion",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\EnableConsoleTracing",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\LastDefsCheck",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap\\.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\EnableFileTracing",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\shell\\open\\command\\(Default)",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\WMI Timeout",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\BELARC~1.EXE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileDirectory",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\InprocServer32",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugHeapFlags",
                "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts\\AutoDownloadDefs",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice\\Progid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\*",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\*",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Hostname",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Serial Number",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\ThreadingModel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableConsoleTracing",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\ProgramData",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\MaxFileSize",
                "HKEY_CURRENT_USER\\.html\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\FileDirectory",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoProxyDetectType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\ConsoleTracingMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Domain",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableImprovedZoneCheck",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorSystemHeapIsPrivate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableFileTracing",
                "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts\\AutoCheckDefs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileTracingMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\MaxFileSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Downloaded From",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\BELARC~1.EXE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Security_HKLM_only",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Home"
            ],
            "directory_enumerated": [
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk",
                "C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk",
                "C:\\Windows\\System32\\ras\\*.pbk",
                "C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\*.pbk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\*.pbk"
            ]
        },
        "first_seen": 1574546003.62475,
        "ppid": 2740
    },
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp",
        "process_name": "GLJ5837.tmp",
        "pid": 1504,
        "summary": {
            "regkey_written": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\InprocServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CurVer\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\InprocServer32\\ThreadingModel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Version\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CLSID\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\HELPDIR\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ToolboxBitmap32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\CLSID\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\VersionIndependentProgID\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ProgID\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\belarc\\CLSID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0\\win32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\FLAGS\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus\\1\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\belarc\\(Default)"
            ],
            "dll_loaded": [
                "SETUPAPI.dll",
                "kernel32.dll",
                "DEVRTL.dll",
                "ADVAPI32.dll",
                "OLE32.DLL",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll"
            ],
            "file_opened": [
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System",
                "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
            ],
            "regkey_opened": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Control",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\Insertable",
                "HKEY_CLASSES_ROOT\\PROTOCOLS",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}",
                "HKEY_CLASSES_ROOT\\VoilaXctl.VoilaXctl.1",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\VersionIndependentProgID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ProgID",
                "HKEY_CURRENT_USER\\TypeLib",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib",
                "HKEY_LOCAL_MACHINE\\System\\Setup",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CurVer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0\\win32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\FLAGS",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus",
                "HKEY_LOCAL_MACHINE\\software\\microsoft\\windows\\currentversion\\setup\\PnpLockdownFiles",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLEAUT",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\belarc",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}",
                "HKEY_CLASSES_ROOT\\VoilaXctl.VoilaXctl",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus\\1",
                "HKEY_CLASSES_ROOT\\CLSID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\InprocServer32",
                "HKEY_CURRENT_USER\\Interface",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Version",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ToolboxBitmap32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\HELPDIR",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CLSID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\CLSID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Programmable"
            ],
            "file_failed": [
                "C:\\Windows\\winsxs\\FileMaps\\program_files_x86_belarc_belarcadvisor_system_2911269189da9f55.cdf-ms"
            ],
            "file_read": [
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\HELPDIR\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemDrive%\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0\\win32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\FLAGS\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)"
            ]
        },
        "first_seen": 1574546002.265375,
        "ppid": 2740
    },
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
        "process_name": "c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
        "pid": 2740,
        "summary": {
            "file_created": [
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP",
                "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLB63F0.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP",
                "C:\\Windows\\System32\\GLBSINST.%$D"
            ],
            "file_recreated": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp"
            ],
            "directory_created": [
                "C:\\ProgramData",
                "C:\\Users\\cuck\\AppData",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System",
                "C:\\Users\\cuck\\AppData\\Local\\Temp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks",
                "C:\\Users\\Public",
                "C:\\Users\\cuck\\AppData\\Roaming",
                "C:\\ProgramData\\Microsoft",
                "C:\\Users",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer",
                "C:\\Users\\cuck",
                "C:\\Program Files (x86)",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
                "C:\\ProgramData\\Microsoft\\Windows",
                "C:\\Users\\cuck\\AppData\\Local",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft",
                "C:\\Users\\Public\\Desktop",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs",
                "C:\\Program Files (x86)\\Belarc"
            ],
            "dll_loaded": [
                "C:\\Windows\\system32\\sfc.dll",
                "netutils.dll",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
                "API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
                "C:\\Windows\\system32\\advapi32.dll",
                "srvcli.dll",
                "apphelp.dll",
                "LINKINFO.dll",
                "kernel32.dll",
                "UxTheme.dll",
                "C:\\Windows\\system32\\ole32.dll",
                "dwmapi.dll",
                "CABINET.DLL",
                "C:\\Windows\\system32\\uxtheme.dll",
                "ntmarta.dll",
                "PROPSYS.dll",
                "C:\\Windows\\syswow64\\MSCTF.dll",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp",
                "slc.dll",
                "KERNEL32.DLL",
                "OLEAUT32.DLL",
                "comctl32",
                "SHLWAPI.dll",
                "USER32.dll",
                "MPR.dll",
                "API-MS-Win-Security-SDDL-L1-1-0.dll",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
                "SHELL32.DLL",
                "profapi.dll",
                "SHELL32.dll",
                "RPCRT4.dll",
                "RICHED32.DLL",
                "DEVRTL.dll",
                "ADVAPI32.dll",
                "SETUPAPI.dll",
                "ntshrui.dll"
            ],
            "file_opened": [
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP",
                "C:\\",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif",
                "C:\\Windows\\System32\\oleaccrc.dll",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP",
                "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif",
                "C:\\Program Files (x86)",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP",
                "C:\\Windows\\AppPatch\\pcamain.sdb",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0006.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP",
                "C:\\Program Files (x86)\\desktop.ini",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP",
                "C:\\Program Files (x86)\\Belarc",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP"
            ],
            "command_line": [
                "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp\" C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll",
                "\"C:\\PROGRA~2\\Belarc\\BELARC~1\\BELARC~1.EXE\" ",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe"
            ],
            "regkey_opened": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PropertyBag",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\BELARC~1.EXE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\ShellEx\\IconHandler",
                "HKEY_CLASSES_ROOT\\.cmd",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\AppCompat",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions",
                "HKEY_CLASSES_ROOT\\.bas",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Logins\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\Clsid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
                "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\LSA\\AccessProviders",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
                "HKEY_CLASSES_ROOT\\Belarc.Computer.Inventory\\DefaultIcon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\ProductOptions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CLASSES_ROOT\\.com",
                "HKEY_CLASSES_ROOT\\MIME\\Database\\Content Type\\application\/vnd.belarc-bci",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE\\Tracing",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610",
                "HKEY_CLASSES_ROOT\\.cpl",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\ddeexec",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security",
                "HKEY_LOCAL_MACHINE\\System\\Setup",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\Clsid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PropertyBag",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PropertyBag",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
                "HKEY_CLASSES_ROOT\\.EXE",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LanmanWorkstation\\Parameters",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
                "HKEY_CLASSES_ROOT\\Belarc.Computer.Inventory\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\(Default)",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}",
                "HKEY_CLASSES_ROOT\\.crt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion",
                "HKEY_CLASSES_ROOT\\SystemFileAssociations\\.EXE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1\\KnownFolders",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppCompat",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup",
                "HKEY_LOCAL_MACHINE\\software\\microsoft\\windows\\currentversion\\setup\\PnpLockdownFiles",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PropertyBag",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\BELARC~1.EXE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Associations",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\ShellEx\\IconHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\1.0",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\(Default)",
                "HKEY_CLASSES_ROOT\\.chm",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Associations",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\DropTarget",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
                "HKEY_CLASSES_ROOT\\.cer",
                "HKEY_CLASSES_ROOT\\.ade",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LDAP",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\ProgIDs\\exefile",
                "HKEY_CLASSES_ROOT\\.adp",
                "HKEY_LOCAL_MACHINE\\NOT_FOUND",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\Memory Management\\PrefetchParameters",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PropertyBag",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders",
                "HKEY_CURRENT_USER\\SOFTWARE\\Belarc\\Advisor\\Settings",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}",
                "HKEY_CLASSES_ROOT\\.app",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\Progid",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.EXE\\OpenWithProgids",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}",
                "HKEY_CURRENT_USER\\SOFTWARE\\Belarc\\Advisor\\Prompts",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\2.0",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\CurVer",
                "HKEY_CLASSES_ROOT\\.bat",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.EXE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\.bci",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\Logins",
                "HKEY_CLASSES_ROOT\\.asp",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLEAUT",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\.csh",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\UserChoice",
                "HKEY_CLASSES_ROOT\\Belarc.Computer.Inventory",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
                "HKEY_CLASSES_ROOT\\exefile",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CLASSES_ROOT\\.EXE\\OpenWithProgids",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
            ],
            "file_moved": [
                [
                    "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000",
                    "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0006.TMP"
                ]
            ],
            "file_written": [
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP",
                "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP"
            ],
            "regkey_deleted": [
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\2.0"
            ],
            "file_deleted": [
                "",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLB63F0.tmp",
                "C:\\Windows\\System32\\GLBSINST.%$D"
            ],
            "file_exists": [
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP",
                "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif",
                "C:\\Windows\\SysWOW64\\propsys.dll",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BELARC~1.EXE:Zone.Identifier",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0006.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP",
                "C:\\Windows\\System32\\propsys.dll",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html",
                "C:\\ProgramData\\Microsoft\\Internet Explorer\\Quick Launch",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP"
            ],
            "mutex": [
                "Local\\ZonesCacheCounterMutex",
                "Local\\ZoneAttributeCacheCounterMutex",
                "Local\\ZonesLockedCacheCounterMutex"
            ],
            "file_failed": [
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html",
                "C:\\Windows\\BAVoilaX.dll",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif",
                "C:\\Windows\\System32\\BAVoilaX.dll",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAVoilaX.dll",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif",
                "C:\\Windows\\winsxs\\FileMaps\\progra_2_belarc_belarc_1_8c5c07b07cc16182.cdf-ms",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll"
            ],
            "guid": [
                "{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
                "{00021401-0000-0000-c000-000000000046}",
                "{79eac9ee-baf9-11ce-8c82-00aa004ba90b}",
                "{000214ee-0000-0000-c000-000000000046}",
                "{7b8a2d94-0ac9-11d1-896c-00c04fb6bfc4}",
                "{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}"
            ],
            "file_read": [
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif",
                "C:\\Program Files (x86)\\desktop.ini",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\RelativePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\Flags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PreCreate",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Favorites",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bat\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Icon",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\AppData",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\Content Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\HelpLink",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\Flags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLUpdateInfo",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\MEMORY MANAGEMENT\\PrefetchParameters\\EnablePrefetcher",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\Shell Folders\\Common AppData",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SharedDir",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\CommonFilesDir",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Parameters\\RpcCacheTimeout",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Personal",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Downloaded From",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\ProfilesDirectory",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResource",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Pictures",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap\\.exe",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DisallowRun",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Name",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bci\\Content Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalRedirectOnly",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{374DE290-123F-4565-9164-39C4925E467B}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Computer ID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayVersion",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.cer\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\UuidMethod",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ProductOptions\\ProductType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\GlobalSession",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonVideo",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Description",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Name",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Programs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\GetIpAddress",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\MachineThrottling",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Attributes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Music",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\RelativePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Video",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonMusic",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.com\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\*",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PreCreate",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Startup",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NoStaticDefaultVerb",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.chm\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Desktop",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Security",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\Flags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\UninstallString",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\ProgramFilesDir",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InfoTip",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{56784854-C6CB-462B-8169-88E350ACB882}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\DelegateExecute",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\Publisher",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\*",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Test2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Stream",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayIcon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.crt\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\InstallLocation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN\\*",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalRedirectOnly",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Roamable",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Home",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PublishExpandedPath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\Flags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bas\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant\\AllowNetworkPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Attributes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\TurnOffSPIAnimations",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.cpl\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorUseSystemHeap",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Icon",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonPictures",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalizedName",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1806",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalizedName",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalizedName",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResourceType",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Cache",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalizedName",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalizedName",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\command",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\NoWorkingDirectory",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\safer\\codeidentifiers\\TransparentEnabled",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\NeverDefault",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.cmd\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\InheritConsoleHandles",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\Public",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\Flags",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemDrive%\\PROGRA~2\\Belarc\\BELARC~1\\BELARC~1.EXE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Startup",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Description",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorSystemHeapIsPrivate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Documents",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.asp\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\SetWorkingDirectoryFromTarget",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1806",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLInfoAbout",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\ShowNtAdminMessage",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledProcesses\\7914760B",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\RestrictRun",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Category"
            ],
            "directory_enumerated": [
                "",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\*.*",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor2_startup.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif",
                "C:\\Program Files (x86)",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif",
                "C:\\Windows",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html",
                "C:\\Program Files (x86)\\Belarc",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html",
                "C:\\Users",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif",
                "C:\\Users\\cuck",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html",
                "C:\\Users\\cuck\\AppData\\Local",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html",
                "C:\\Windows\\System32\\rundll32.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif",
                "C:\\Users\\cuck\\AppData",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif",
                "C:\\Windows\\System32",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll"
            ],
            "regkey_written": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\UuidMethod",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\UninstallString",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Logins\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\DefaultIcon\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayName",
                "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts\\License Agreement",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\InstallLocation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\application\/vnd.belarc-bci\\Extension",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\Publisher",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Test2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLInfoAbout",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bci\\Content Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\HelpLink",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\GetIpAddress",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Home",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLUpdateInfo",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bci\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Computer ID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayIcon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayVersion",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Downloaded From",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\ShowNtAdminMessage"
            ]
        },
        "first_seen": 1574545988.640625,
        "ppid": 1564
    },
    {
        "process_path": "C:\\Windows\\explorer.exe",
        "process_name": "explorer.exe",
        "pid": 1788,
        "summary": {
            "directory_created": [
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer"
            ],
            "dll_loaded": [
                "C:\\Windows\\system32\\xmllite.dll",
                "POWRPROF.DLL"
            ],
            "file_opened": [
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories",
                "C:\\ProgramData",
                "C:\\",
                "C:\\Users\\cuck\\AppData",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC",
                "C:\\Users\\cuck\\Desktop",
                "C:\\Users\\Public\\Desktop",
                "C:\\ProgramData\\Microsoft",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
                "C:\\ProgramData\\Microsoft\\Windows",
                "C:\\Users\\Public\\Desktop\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC\\Desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\desktop.ini",
                "C:\\Windows\\AppPatch\\sysmain.sdb",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance",
                "C:\\Users",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
                "C:\\Users\\",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\Desktop.ini",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\",
                "C:\\Users\\Public",
                "C:\\Users\\cuck\\AppData\\Roaming",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_96.db",
                "C:\\Users\\cuck\\Desktop\\desktop.ini",
                "C:\\Program Files (x86)\\",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_1024.db",
                "C:\\Users\\desktop.ini",
                "C:\\Windows\\win.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility\\Desktop.ini",
                "C:\\Users\\cuck",
                "C:\\Users\\cuck\\AppData\\Local\\",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
                "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_256.db",
                "C:\\Users\\cuck\\",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_sr.db",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_idx.db",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Python 2.7",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games\\desktop.ini",
                "C:\\Users\\Public\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs",
                "c:\\program files (x86)\\Belarc\\belarcadvisor\\belarcadvisor.exe",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools\\Desktop.ini",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db",
                "C:\\Program Files (x86)\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools"
            ],
            "regkey_opened": [
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F05C8358C56DAD54BB81D0A11DD52F41",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D0CBB37A94C46943A90AC5008CF1CC9",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0F4DC93AAA8AD1D448BC4E6A207F4FE0",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\895805CC90C04694887EF6BD140A622D",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\BE0BD5097A638224EB0DAAE870267F03",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B06071FE021ECB04E8B3BF1E39AD5BB3",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CDBF699A8F2EAC2438564C3D50E9E638",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B5C8B2FB95B57147954C18085D53ACE",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\040E2A370D6DB2F45AE45A0032BC2179",
                "HKEY_CLASSES_ROOT\\Outlook.Application.12",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\30FAECE2400494D4FB69207288EB5B73",
                "HKEY_CLASSES_ROOT\\Outlook.Application.10",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0EF52818FCE3E7B488427C1F8266654E",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\669C9DC1419C0F240B35B36B99AAB50C",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1E82F31DC0D05AA4CB291B7BAA23FC8E",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FBEAAA6C37E8AF24B87AAEA0047433BD",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\103857F24A2EDA54A800A41FA570861F",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D3541DFF9B79C584284E8981624C04CB",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F356843B045CC0A4BA0D83C1D85AAAFD",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A7E9995902A24964C9C5D461E1C86F19",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\87C48B95924E3294FBC1766C9225DD0C",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E85E64F0A7FC58E47A87E5AB98A6F2DD",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\958C4A0DE6C8D5C428C6E9D875BC33B6",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4486F7CE8F022FB4EB0154C5226C27A0",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B1D5EA6004F809D48B117CE563261011",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\33AB3CD4D27277545B5A93CD4ECB96B4",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E429E5BC27530F4786481EC687D9EC9",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FE547D6F0D72534A80F89C4AB727618",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AE5A0040C41ACA642AF6DB16F4D2F638",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0411990C889EE9B47BB0B5D356564877",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\2FA90A429E82313489DAA2E2C2F0872C",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\75B368B60C908BA4E87C31F66B02F3F0",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B04950B5EC5C924B8F428B5484A2720",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89DF671CDA74E9D4EB10275B10D5CF3F",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CB2182A03B6B11341A1F09A021991CE1",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\62293D511DB84E5489074C5AFA18E882",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9D22CD4619F5DBC499A083AAD70FE7B3",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FF9FDEA72CD9DDC47A6DAB85F9F76B81",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7BF7ABF4D25C03F4582D4BC3082FB208",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E40FDF839772BEB41AC977860DBB4853",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CE5B971A0DBB8FD4F83AE0DADC348104",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LanmanServer\\DefaultSecurity",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CF65AB832507EDB4BB357F9D8E0431BD",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\63B1AF366905AF641BA514CCBAE803C4",
                "HKEY_LOCAL_MACHINE\\Software\\Classes\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8691BCC36FF121849A90B085BFAF5E5E",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F591EF48DE97A00428A5BC1AFFFAA868",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-699399860-4089948139-3198924279-1001\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\285499F23409ED14FB4A01230F5DFA91",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9BA984AD4F03E284382FFBB7A68BEE27",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE19F224928A59468049F045950CB08",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84C584688CFC74A4E9D36E5EE2E02FA7",
                "HKEY_CLASSES_ROOT\\Outlook.Application.11",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9F5ED6B416EF0A1448D94799D0FF20BA",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FEB01D34D0F67E4F9CD810B432C1B91",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4514EC211C8947C4B9BA24F353AFFD50",
                "HKEY_LOCAL_MACHINE\\Software\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE462B32EFD81040A184ED17E00452B",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7814D91294731FF4DBBB840810BEB3BB",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\67C12EF40671B7342A2F990919031A57",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B4BBDDC88CEE4DD439E8BB261CE222A8",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\296744B7EBFEB2741A47781AE6E32269",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\92F9143E715DEF045A539256438E41FB",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8020CF43278B2644190F51544810251E",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B690B72A999998C47B5F93C94A8D43B2",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3D197E722531D614AB40C182904D9A31",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\16AC40BE991DF1643B2800729063B2F9",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7C0477DE66D1A6749864FCE02A6DCB6C",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D5FD8239A83FE564F97379EA15CE8CB6",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\04C56B5D827A9194FA2CBFD014EAD0DA",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4626147D107665540A84D43A5908E74D",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A558E619ABC4CE5479C1DA5070EFBF81",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18D84E9490A485948A17A1F02CDAA62A",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\315C767EFC72D8445B1D2D16F72653F0",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\11E2BA15171FE704B98E7505E58D7749",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D38A6F5FC8262149A9FAAE8C621EE3F",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8ECC347096FA78C4E8291F449F71E16E",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FE056816E41FD2F4CACD03E7A2CA2E6E",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ThumbnailCache",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89BBBC8A0D32B014696C4BA3C20CDD34",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9DD74C0626DC33C479C1929714AB5295",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95E2C34402A93A14FA8CB3420B85375C",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\53F08364FFD17F14B8FD7CA7F52FAE76",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C1EF68F348457B246A0AD0C18B3079AF",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E116C831A95AB5B4787CE3086FE83631",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\863CA21BBA4DFCE489FDF96EAB898616",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A0256FF64030E0746A4AA95D3FFD0BE4",
                "HKEY_CLASSES_ROOT\\Outlook.Application",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1A0857155A8EF604FA5D1648CF382DC7",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D04063BE69797D4D8505462827A0D19",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FFFA6DF7EA9EDFC45A1F02FE6DF8F067",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\73964AA699D5B5140ADC41ED3F7DB38A",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9753E3A35E3BDFB468DF95B5D19C8A04",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Sharing",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-699399860-4089948139-3198924279-1001\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D725CB8E57307E64EB574E04214D8B5F",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1C1ED53B8F25FD248955C15232E46886",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StuckRects2",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18F5DB38C45303843B06B1B5025E4820",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AD21E12039BB3BC47B1938BC4ABDFEE2",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\034A8F8E06031EF46BCB4C10469098E5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C4040CC509FB0DC4886F590DDF6B6132",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84BBAC70FB00B6046881B55CB3122F0F",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F21868A51A175874BB819DCA5FAA40A3",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0A191B45599EEB74CA305184EA3C2A94",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3C68656E520593A45925ADFB41F821B5",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\90860AAA7BD3DE34EB32330DD29CAD62",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\002F6EFFA8A0A40498F3035BD153685A",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F41A458014D57E54E8DBD0B0CBC361A2",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9E40FDB6330EBA242A4BD5F4FDD0B803",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E3DAE67887931944BCD7171908FA775",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\965742E8F65116F4BB2CB01341464FA7",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\717591555BCB1604BA9777E8A55D0E41",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\335F6F64CD461D9469519574D34757EB",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\17E23EF6C775D324DB90E0E2B7D1CA72",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0FD387D006FD9734FA65B249F36DE42A",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95EE473833000D6409127D1B85882AC9",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\EEF8AA9EB45B5DB4BBE46B8634C910CD",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7636A94AA21EDBB48B6AFFB17E5907B8"
            ],
            "regkey_deleted": [
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupCollapseState",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ItemOrder",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ItemPos800x600x96(1)"
            ],
            "file_exists": [
                "C:\\Users\\cuck\\Desktop",
                "C:\\Python27\\pythonw.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
                "C:\\Program Files\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor",
                "C:\\Python27\\python.exe",
                "C:\\cuckoo_1788.ini",
                "C:\\Users\\Public",
                "C:\\Users",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
                "C:\\Users\\cuck",
                "C:\\Program Files (x86)",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
                "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\ThumbCacheToDelete",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu",
                "C:\\Users\\Public\\Desktop",
                "C:\\cuckoo_2648.ini",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db",
                "C:\\cuckoo_1504.ini"
            ],
            "mutex": [
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwReaderRefs",
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer",
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer",
                "Local\\Shell.CMruPidlList",
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer",
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer",
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit",
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer",
                "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex"
            ],
            "file_failed": [
                "C:\\cuckoo_1504.ini",
                "C:\\ProgramData\\Microsoft\\desktop.ini",
                "C:\\cuckoo_2648.ini",
                "C:\\Users\\cuck\\Desktop\\Belarc Advisor.lnk",
                "C:\\cuckoo_1788.ini",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\desktop.ini"
            ],
            "guid": [
                "{fdada2fa-894d-47d8-ae78-adf1fd7f28df}",
                "{00000003-0000-0000-c000-000000000046}",
                "{49f371e1-8c5c-4d9c-9a3b-54a6827f513c}",
                "{a4341687-7593-47aa-9554-4b0ffc8b2214}",
                "{688c934d-0c26-40f6-8d29-d56d72c76b48}",
                "{c0a6c367-c264-4385-a704-9088bdc3640e}",
                "{b2952b16-0e07-4e5a-b993-58c52cb94cae}",
                "{660b90c8-73a9-4b58-8cae-355b7f55341b}",
                "{54410b83-6787-4418-9735-5aaaabe83a9a}",
                "{42aedc87-2188-41fd-b9a3-0c966feabec1}",
                "{f6166dad-d3be-4ebd-8419-9b5ead8d0ec7}",
                "{00000000-0000-0000-c000-000000000046}",
                "{1c1800c1-3258-44c2-be80-3deadb6c5e39}",
                "{00000146-0000-0000-c000-000000000046}",
                "{cef04fdf-fe72-11d2-87a5-00c04f6837cf}",
                "{427fd3d4-f30a-4033-84ef-cbb1a955d9f7}",
                "{76765b11-3f95-4af2-ac9d-ea55d8994f1a}",
                "{6746c347-576b-4f73-9012-cdfeea251bc4}",
                "{2fb499a3-cfce-480f-a5f3-2453db7a2b7a}",
                "{00000323-0000-0000-c000-000000000046}",
                "{6e682784-1eca-4cf2-988d-96b6e89e9a4d}",
                "{75121952-e0d0-43e5-9380-1d80483acf72}",
                "{ab8902b4-09ca-4bb6-b78d-a8f59079a8d5}",
                "{dc8f8556-efbd-4efa-8b64-bba84b4ecd7f}",
                "{f676c15d-596a-4ce2-8234-33996f445db1}",
                "{46a6eeff-908e-4dc6-92a6-64be9177b41c}",
                "{50ef4544-ac9f-4a8e-b21b-8a26180db13f}",
                "{edb5f444-cb8d-445a-a523-ec5ab6ea33c7}"
            ],
            "file_read": [
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\desktop.ini",
                "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
                "C:\\Users\\Public\\Desktop\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC\\Desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
                "C:\\Users\\cuck\\Desktop\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\desktop.ini",
                "C:\\Users\\desktop.ini",
                "C:\\Windows\\win.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility\\Desktop.ini",
                "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\Desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games\\desktop.ini",
                "C:\\Users\\Public\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools\\Desktop.ini",
                "C:\\Program Files (x86)\\desktop.ini"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4626147D107665540A84D43A5908E74D\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0A191B45599EEB74CA305184EA3C2A94\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features\\DefaultFeature",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Fvqrone.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F41A458014D57E54E8DBD0B0CBC361A2\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_MinMFU",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Flfgrz Gbbyf\\Cevingr Punenpgre Rqvgbe.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4486F7CE8F022FB4EB0154C5226C27A0\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\zvc.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\90860AAA7BD3DE34EB32330DD29CAD62\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\FavccvatGbby.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\qsethv.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F05C8358C56DAD54BB81D0A11DD52F41\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\rhqprqvg.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfNalgvzrHctenqrHV.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Erzbgr Qrfxgbc Pbaarpgvba.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{8NOQ94SO-R7Q6-84N6-N997-P918RQQR0NR5}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\StartMenu_Balloon_Time",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\InProcServer32\\ThreadingModel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\\SortOrderIndex",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\63B1AF366905AF641BA514CCBAE803C4\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Rirag Ivrjre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B06071FE021ECB04E8B3BF1E39AD5BB3\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Zbovyvgl Pragre.yax",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\SNTSearch.dll,-505",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CF65AB832507EDB4BB357F9D8E0431BD\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E85E64F0A7FC58E47A87E5AB98A6F2DD\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jbeqcnq.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9D22CD4619F5DBC499A083AAD70FE7B3\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7814D91294731FF4DBBB840810BEB3BB\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9DD74C0626DC33C479C1929714AB5295\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\MenuUserExpanded",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84BBAC70FB00B6046881B55CB3122F0F\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_TrackProgs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\InProcServer32\\InprocServer32",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\FbhaqErpbeqre.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\67C12EF40671B7342A2F990919031A57\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9BA984AD4F03E284382FFBB7A68BEE27\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{QNN168QR-4306-P8OP-8P11-O596240OQQRQ}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\002F6EFFA8A0A40498F3035BD153685A\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\FuncrPbyyrpgbe.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_PowerButtonAction",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragDelay",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\GnoGvc.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Vagrearg Rkcybere.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Jvaqbjf Sverjnyy jvgu Nqinaprq Frphevgl.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Fgvpxl Abgrf.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JSF.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\33AB3CD4D27277545B5A93CD4ECB96B4\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\efgehv.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\040E2A370D6DB2F45AE45A0032BC2179\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Znvagranapr\\Erzbgr Nffvfgnapr.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\mstsc.exe,-4000",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B690B72A999998C47B5F93C94A8D43B2\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\717591555BCB1604BA9777E8A55D0E41\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B04950B5EC5C924B8F428B5484A2720\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\InProcServer32\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\vFPFV Vavgvngbe.yax",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\FXSRESM.dll,-114",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zntavsl.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pzq.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\kcfepuij.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E40FDF839772BEB41AC977860DBB4853\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Cnvag.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{53123611-QN37-S8QN-SNP9-03R76QO9Q64Q}",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\displayswitch.exe,-320",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\ProfileImagePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_MinMFU",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Nalgvzr Hctenqr.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\ZqFpurq.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\Auto Update\\UAS\\UpdateCount",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9753E3A35E3BDFB468DF95B5D19C8A04\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Npprffvovyvgl\\Fcrrpu Erpbtavgvba.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_PowerButtonAction",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\VQYR (Clguba THV).yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Znvagranapr\\Perngr Erpbirel Qvfp.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\QIQ Znxre\\QIQZnxre.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Orynep Nqivfbe.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{15067OP1-P5N8-425R-37P6-SN0O891674S9}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\863CA21BBA4DFCE489FDF96EAB898616\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{Q4N262QQ-PR44-Q105-S36O-9Q77N8PO65N4}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1E82F31DC0D05AA4CB291B7BAA23FC8E\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Vagrearg Rkcybere (64-ovg).yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FBEAAA6C37E8AF24B87AAEA0047433BD\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D0CBB37A94C46943A90AC5008CF1CC9\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B4BBDDC88CEE4DD439E8BB261CE222A8\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E3DAE67887931944BCD7171908FA775\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Abgrcnq.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bmp\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pyrnazte.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE462B32EFD81040A184ED17E00452B\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84C584688CFC74A4E9D36E5EE2E02FA7\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.FgvpxlAbgrf",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D5FD8239A83FE564F97379EA15CE8CB6\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\FavoritesChanges",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfCbjreFuryy\\i1.0\\CbjreFuryy_VFR.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Aneengbe.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0411990C889EE9B47BB0B5D356564877\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\EnableBalloonTips",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3C68656E520593A45925ADFB41F821B5\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pbzrkc.zfp",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollInset",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\bfx.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Cresbeznapr Zbavgbe.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\abgrcnq.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\qsethv.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\KCF Ivrjre.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ZrqvnCynlre32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\53F08364FFD17F14B8FD7CA7F52FAE76\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Gnfx Fpurqhyre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D3541DFF9B79C584284E8981624C04CB\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_NotifyNewApps",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Vagrearg Rkcybere.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\FavoritesRemovedChanges",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Zngu Vachg Cnary.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy VFR.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Zrqvn Cynlre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClearRecentDocsOnExit",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4514EC211C8947C4B9BA24F353AFFD50\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlot",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\SnippingTool.exe,-15051",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\OobeFldr.dll,-33056",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\Segoe UI",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\puneznc.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\285499F23409ED14FB4A01230F5DFA91\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Jvaqbjf AG\\Npprffbevrf\\jbeqcnq.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ErzbgrQrfxgbc",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewShadow",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.VagreargRkcybere.Qrsnhyg",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\UseOutOfProcHandlerCache",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\cevagznantrzrag.zfp",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\\Orynep\\OrynepNqivfbe\\OrynepNqivfbe.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8020CF43278B2644190F51544810251E\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7BF7ABF4D25C03F4582D4BC3082FB208\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Punenpgre Znc.yax",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\DefaultSecurity\\SrvsvcDefaultShareInfo",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Zrqvn Pragre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A7E9995902A24964C9C5D461E1C86F19\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A0256FF64030E0746A4AA95D3FFD0BE4\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C4040CC509FB0DC4886F590DDF6B6132\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Snk naq Fpna.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8691BCC36FF121849A90B085BFAF5E5E\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy (k86).yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_TrackProgs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E116C831A95AB5B4787CE3086FE83631\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FFFA6DF7EA9EDFC45A1F02FE6DF8F067\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Sharing\\UsersShareName",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\FavoritesChanges",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3D197E722531D614AB40C182904D9A31\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D38A6F5FC8262149A9FAAE8C621EE3F\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Jvaqbjf Rnfl Genafsre Ercbegf.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AlwaysShowMenus",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A558E619ABC4CE5479C1DA5070EFBF81\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Fbhaq Erpbeqre.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zvtjvm\\zvtjvm.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\R7PS176R110P211O",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5\\TclTk",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95EE473833000D6409127D1B85882AC9\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0EF52818FCE3E7B488427C1F8266654E\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.TrggvatFgnegrq",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7C0477DE66D1A6749864FCE02A6DCB6C\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features\\TclTk",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollDelay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9F5ED6B416EF0A1448D94799D0FF20BA\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Flfgrz Pbasvthengvba.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{35786D3C-B075-49b9-88DD-029876E11C01}\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{P1P6S8NP-40N3-0S5P-146S-65N9QP70OOO4}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\04C56B5D827A9194FA2CBFD014EAD0DA\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Paint.Picture\\CLSID\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Zntavsl.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flap Pragre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\965742E8F65116F4BB2CB01341464FA7\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zboflap.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\erpqvfp.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\73964AA699D5B5140ADC41ED3F7DB38A\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\P:\\Clguba27\\clguba.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\ArgCebw.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\EnableShareDenyNone",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0FD387D006FD9734FA65B249F36DE42A\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D725CB8E57307E64EB574E04214D8B5F\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\DisableProcessIsolation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Paint.Picture\\IsShortcut",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\ArgjbexCebwrpgvba.yax",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\PromotedIconCache",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\103857F24A2EDA54A800A41FA570861F\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{NN198O3P-PQ8P-7QR1-98Q1-O460S637193O}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewAlphaSelect",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollInterval",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_NotifyNewApps",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Jvaqbjf CbjreFuryy Zbqhyrf.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CE5B971A0DBB8FD4F83AE0DADC348104\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\qvfcynlfjvgpu.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\P:\\Hfref\\Choyvp\\Qrfxgbc\\Orynep Nqivfbe.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Ba-Fperra Xrlobneq.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Cevag Znantrzrag.yax",
                "HKEY_CURRENT_USER\\Control Panel\\Desktop\\SmoothScroll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\034A8F8E06031EF46BCB4C10469098E5\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AE5A0040C41ACA642AF6DB16F4D2F638\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-18\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\NoOplock",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\freivprf.zfp",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\FavoritesRemovedChanges",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\StartMenu_Balloon_Time",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\XpsRchVw.exe,-102",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Pbzchgre Znantrzrag.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\qvfcynlfjvgpu.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Favccvat Gbby.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\UseInProcHandlerCache",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\EEF8AA9EB45B5DB4BBE46B8634C910CD\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95E2C34402A93A14FA8CB3420B85375C\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Jvaqbjf Rnfl Genafsre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FEB01D34D0F67E4F9CD810B432C1B91\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_LargeMFUIcons",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Jvaqbjf Wbheany\\Wbheany.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D04063BE69797D4D8505462827A0D19\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.VagreargRkcybere.64Ovg",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18F5DB38C45303843B06B1B5025E4820\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FF9FDEA72CD9DDC47A6DAB85F9F76B81\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU Size",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5\\DefaultFeature",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\BE0BD5097A638224EB0DAAE870267F03\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfen.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{P804OON7-SN5S-POS7-8O55-2096R5S972PO}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zvtjvm\\cbfgzvt.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Pnyphyngbe.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\freivprf.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\FavoritesRemovedChanges",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Qvfx Pyrnahc.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\296744B7EBFEB2741A47781AE6E32269\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FE547D6F0D72534A80F89C4AB727618\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Flfgrz Erfgber.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Sversbk.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Qngn Fbheprf (BQOP).yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\315C767EFC72D8445B1D2D16F72653F0\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\bqopnq32.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lnk\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Jvaqbjf Rkcybere.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CDBF699A8F2EAC2438564C3D50E9E638\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{7SR8Q22N-SO1Q-N8OR-01R3-6P8693961R6R}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 6",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\FuncrPbyyrpgbe.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F356843B045CC0A4BA0D83C1D85AAAFD\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\System.NamespaceCLSID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\62293D511DB84E5489074C5AFA18E882\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C1EF68F348457B246A0AD0C18B3079AF\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lnk\\ShellEx\\{BB2E617C-0920-11D1-9A0B-00C04FC2D6C1}\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Frphevgl Pbasvthengvba Znantrzrag.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7636A94AA21EDBB48B6AFFB17E5907B8\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{OO044OSQ-25O7-2SNN-22N8-6371N93R0456}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Zrzbel Qvntabfgvpf Gbby.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Jvaqbjf Rkcybere.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\vfpfvpcy.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\958C4A0DE6C8D5C428C6E9D875BC33B6\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\Clguba (pbzznaq yvar).yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_LargeMFUIcons",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F591EF48DE97A00428A5BC1AFFFAA868\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8ECC347096FA78C4E8291F449F71E16E\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\\JvaqbjfCbjreFuryy\\i1.0\\CbjreFuryy_VFR.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jrypbzr Pragre.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Flfgrz Vasbezngvba.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE19F224928A59468049F045950CB08\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9E40FDB6330EBA242A4BD5F4FDD0B803\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\669C9DC1419C0F240B35B36B99AAB50C\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E429E5BC27530F4786481EC687D9EC9\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\16AC40BE991DF1643B2800729063B2F9\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\lnkfile\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1C1ED53B8F25FD248955C15232E46886\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\2FA90A429E82313489DAA2E2C2F0872C\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\TaskbarAnimations",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Pbzznaq Cebzcg.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\30FAECE2400494D4FB69207288EB5B73\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0F4DC93AAA8AD1D448BC4E6A207F4FE0\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfpbasvt.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89DF671CDA74E9D4EB10275B10D5CF3F\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfcnvag.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\Jvaqbjf Wbheany.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfvasb32.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf QIQ Znxre.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfCbjreFuryy\\i1.0\\cbjrefuryy.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CB2182A03B6B11341A1F09A021991CE1\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\aneengbe.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F21868A51A175874BB819DCA5FAA40A3\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{8NN47365-O2O3-1961-69RO-S866R376O12S}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\87C48B95924E3294FBC1766C9225DD0C\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\92F9143E715DEF045A539256438E41FB\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1A0857155A8EF604FA5D1648CF382DC7\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\Zbqhyr Qbpf.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pnyp.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ZrqvnPragre",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy VFR (k86).yax",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Gnfx Fpurqhyre.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B1D5EA6004F809D48B117CE563261011\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\75B368B60C908BA4E87C31F66B02F3F0\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{OQ3S924R-55SO-N1ON-9QR6-O50S9S2460NP}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B5C8B2FB95B57147954C18085D53ACE\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragMinDist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18D84E9490A485948A17A1F02CDAA62A\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\11E2BA15171FE704B98E7505E58D7749\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Erfbhepr Zbavgbe.yax",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\895805CC90C04694887EF6BD140A622D\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\335F6F64CD461D9469519574D34757EB\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FE056816E41FD2F4CACD03E7A2CA2E6E\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AD21E12039BB3BC47B1938BC4ABDFEE2\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Sversbk.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\\rkcybere.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AlwaysShowMenus",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\\JvaqbjfCbjreFuryy\\i1.0\\cbjrefuryy.rkr",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Pbzcbarag Freivprf.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Jvaqbjf Zrqvn Cynlre.yax",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JS.zfp",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89BBBC8A0D32B014696C4BA3C20CDD34\\586A8930D8DF3B6489614C37910BFCF5",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Cache",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\GnoGvc.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\17E23EF6C775D324DB90E0E2B7D1CA72\\586A8930D8DF3B6489614C37910BFCF5"
            ],
            "regkey_written": [
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByKey:FMTID",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\IconSize",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\FFlags",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts\\C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\Sort",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\IconStreams",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ColInfo",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\ProgramsCache",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByDirection",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\LanguageList",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\LastAdvertisement",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\ShellBrowser\\ITBar7Layout",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\PastIconsStream",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupView",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\UserStartTime",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StuckRects2\\Settings",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByKey:PID",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\LogicalViewMode",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\Mode",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Streams\\Desktop\\TaskbarWinXP"
            ]
        },
        "first_seen": 1574545996.202875,
        "ppid": 1740
    },
    {
        "process_path": "C:\\Windows\\System32\\lsass.exe",
        "process_name": "lsass.exe",
        "pid": 476,
        "summary": {},
        "first_seen": 1574545988.3125,
        "ppid": 376
    }
]

Signatures

[
    {
        "markcount": 4,
        "families": [],
        "description": "Queries for the computername",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1574545996.077625,
                    "tid": 2436,
                    "flags": {}
                },
                "pid": 2740,
                "type": "call",
                "cid": 2924
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1574545996.187625,
                    "tid": 2436,
                    "flags": {}
                },
                "pid": 2740,
                "type": "call",
                "cid": 4135
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1574545996.202625,
                    "tid": 2436,
                    "flags": {}
                },
                "pid": 2740,
                "type": "call",
                "cid": 4315
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1574545998.421875,
                    "tid": 2808,
                    "flags": {}
                },
                "pid": 1788,
                "type": "call",
                "cid": 1592
            }
        ],
        "references": [],
        "name": "antivm_queries_computername"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Checks if process is being debugged by a debugger",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "system",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741515,
                    "api": "IsDebuggerPresent",
                    "return_value": 0,
                    "arguments": {},
                    "time": 1574545988.718625,
                    "tid": 2436,
                    "flags": {}
                },
                "pid": 2740,
                "type": "call",
                "cid": 31
            },
            {
                "call": {
                    "category": "system",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741511,
                    "api": "IsDebuggerPresent",
                    "return_value": 0,
                    "arguments": {},
                    "time": 1574546003.71875,
                    "tid": 2508,
                    "flags": {}
                },
                "pid": 2648,
                "type": "call",
                "cid": 52
            }
        ],
        "references": [],
        "name": "checks_debugger"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Tries to locate where the browsers are installed",
        "severity": 1,
        "marks": [
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "locates_browser"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "One or more processes crashed",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "__notification__",
                    "status": 1,
                    "stacktrace": [],
                    "raw": [
                        "stacktrace"
                    ],
                    "api": "__exception__",
                    "return_value": 0,
                    "arguments": {
                        "stacktrace": "0\nx\n2\nb\n8\n1\n9\n0\n4\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0",
                        "registers": {
                            "r14": 192924704,
                            "r9": 0,
                            "rcx": 48,
                            "rsi": 192924704,
                            "r10": 0,
                            "rbx": 98185776,
                            "rdi": 192924784,
                            "r11": 192930608,
                            "r8": 2006183236,
                            "rdx": 8796092404304,
                            "rbp": 192923472,
                            "r15": 262145,
                            "r12": 262144,
                            "rsp": 192923352,
                            "rax": 45619456,
                            "r13": 237550496
                        },
                        "exception": {
                            "instruction_r": "83 3d 8d d1 02 00 00 68 53 12 69 fb c7 44 24 04",
                            "instruction": "cmp dword ptr [rip + 0x2d18d], 0",
                            "exception_code": "0xc0000005",
                            "symbol": "",
                            "address": "0x2b81904"
                        }
                    },
                    "time": 1574546004.077875,
                    "tid": 1296,
                    "flags": {}
                },
                "pid": 1788,
                "type": "call",
                "cid": 13296
            }
        ],
        "references": [],
        "name": "raises_exception"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Allocates read-write-execute memory (usually to unpack itself)",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 1504,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70d85000"
                    },
                    "time": 1574546002.327375,
                    "tid": 2572,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 1504,
                "type": "call",
                "cid": 9
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 1504,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x73721000"
                    },
                    "time": 1574546002.327375,
                    "tid": 2572,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 1504,
                "type": "call",
                "cid": 64
            }
        ],
        "references": [],
        "name": "allocates_rwx"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetDiskFreeSpaceExW",
                    "return_value": 1,
                    "arguments": {
                        "root_path": "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer",
                        "free_bytes_available": 23508131840,
                        "total_number_of_free_bytes": 0,
                        "total_number_of_bytes": 0
                    },
                    "time": 1574546001.171875,
                    "tid": 2808,
                    "flags": {}
                },
                "pid": 1788,
                "type": "call",
                "cid": 4648
            }
        ],
        "references": [],
        "name": "antivm_disk_size"
    },
    {
        "markcount": 4,
        "families": [],
        "description": "Creates a shortcut to an executable file",
        "severity": 2,
        "marks": [
            {
                "category": "file",
                "ioc": "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\Desktop\\Belarc Advisor.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "creates_shortcut"
    },
    {
        "markcount": 3,
        "families": [],
        "description": "Drops an executable to the user AppData folder",
        "severity": 2,
        "marks": [
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "exe_appdata"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Checks adapter addresses which can be used to detect virtual network interfaces",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "network",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741772,
                    "api": "GetAdaptersAddresses",
                    "return_value": 111,
                    "arguments": {
                        "flags": 0,
                        "family": 0
                    },
                    "time": 1574546005.65575,
                    "tid": 3000,
                    "flags": {}
                },
                "pid": 2648,
                "type": "call",
                "cid": 1395
            }
        ],
        "references": [],
        "name": "antivm_network_adapters"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Checks for the Locally Unique Identifier on the system for a suspicious privilege",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeShutdownPrivilege"
                    },
                    "time": 1574546003.812875,
                    "tid": 1828,
                    "flags": {}
                },
                "pid": 1788,
                "type": "call",
                "cid": 12931
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeShutdownPrivilege"
                    },
                    "time": 1574546003.843875,
                    "tid": 1828,
                    "flags": {}
                },
                "pid": 1788,
                "type": "call",
                "cid": 12960
            }
        ],
        "references": [],
        "name": "privilege_luid_check"
    },
    {
        "markcount": 9,
        "families": [],
        "description": "Queries for potentially installed applications",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "registry",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741772,
                    "api": "RegOpenKeyExA",
                    "return_value": 2,
                    "arguments": {
                        "access": "0x00000001",
                        "base_handle": "0x80000002",
                        "key_handle": "0x00000000",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "options": 0
                    },
                    "time": 1574545996.046625,
                    "tid": 2436,
                    "flags": {}
                },
                "pid": 2740,
                "type": "call",
                "cid": 2704
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExA",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00000001",
                        "base_handle": "0x80000002",
                        "key_handle": "0x00000178",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "options": 0
                    },
                    "time": 1574545996.046625,
                    "tid": 2436,
                    "flags": {}
                },
                "pid": 2740,
                "type": "call",
                "cid": 2711
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExA",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00000001",
                        "base_handle": "0x80000002",
                        "key_handle": "0x00000178",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "options": 0
                    },
                    "time": 1574545996.046625,
                    "tid": 2436,
                    "flags": {}
                },
                "pid": 2740,
                "type": "call",
                "cid": 2720
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExA",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00000001",
                        "base_handle": "0x80000002",
                        "key_handle": "0x00000178",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "options": 0
                    },
                    "time": 1574545996.046625,
                    "tid": 2436,
                    "flags": {}
                },
                "pid": 2740,
                "type": "call",
                "cid": 2729
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExA",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00000001",
                        "base_handle": "0x80000002",
                        "key_handle": "0x00000178",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "options": 0
                    },
                    "time": 1574545996.046625,
                    "tid": 2436,
                    "flags": {}
                },
                "pid": 2740,
                "type": "call",
                "cid": 2738
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExA",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00000001",
                        "base_handle": "0x80000002",
                        "key_handle": "0x00000178",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "options": 0
                    },
                    "time": 1574545996.046625,
                    "tid": 2436,
                    "flags": {}
                },
                "pid": 2740,
                "type": "call",
                "cid": 2747
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExA",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00000001",
                        "base_handle": "0x80000002",
                        "key_handle": "0x00000178",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "options": 0
                    },
                    "time": 1574545996.046625,
                    "tid": 2436,
                    "flags": {}
                },
                "pid": 2740,
                "type": "call",
                "cid": 2756
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExA",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00000001",
                        "base_handle": "0x80000002",
                        "key_handle": "0x00000178",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "options": 0
                    },
                    "time": 1574545996.062625,
                    "tid": 2436,
                    "flags": {}
                },
                "pid": 2740,
                "type": "call",
                "cid": 2765
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExA",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00000001",
                        "base_handle": "0x80000002",
                        "key_handle": "0x00000178",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor",
                        "options": 0
                    },
                    "time": 1574545996.062625,
                    "tid": 2436,
                    "flags": {}
                },
                "pid": 2740,
                "type": "call",
                "cid": 2774
            }
        ],
        "references": [],
        "name": "queries_programs"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config",
        "severity": 3,
        "marks": [
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtSetValueKey",
                    "return_value": 0,
                    "arguments": {
                        "index": 0,
                        "key_handle": "0x0000000000000f84",
                        "value": "\u0014\u0000\u0000\u0000\u0005\u0000\u0000\u0000\u0001\u0000\u0001\u0000\u0010\u0000\u0000\u0000\u0014\u0000\u0000\u0000IL \u0006\u0010\u0000$\u0000\u0018\u0000\u0010\u0000\u0010\u0000\u00ff\u00ff\u00ff\u00ff!\u0010\u00ff\u00ff\u00ff\u00ff\u00ff\u00ff\u00ff\u00ffBM6\u0000\u0000\u0000\u0000\u0000\u0000\u00006\u0000\u0000\u0000(\u0000\u0000\u0000\u0010\u0000\u0000\u0000@\u0002\u0000\u0000\u0001\u0000 \u0000\u0000\u0000\u0000\u0000\u0000\u0090\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000",
                        "reg_type": 3,
                        "regkey": "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\PastIconsStream"
                    },
                    "time": 1574545998.733875,
                    "tid": 1828,
                    "flags": {
                        "reg_type": "REG_BINARY"
                    }
                },
                "pid": 1788,
                "type": "call",
                "cid": 1855
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtSetValueKey",
                    "return_value": 0,
                    "arguments": {
                        "index": 0,
                        "key_handle": "0x00000000000001e0",
                        "value": "\u0014\u0000\u0000\u0000\u0007\u0000\u0000\u0000\u0001\u0000\u0001\u0000\u0004\u0000\u0000\u0000\u0014\u0000\u0000\u0000{\u0000S\u00003\u00008\u0000O\u0000S\u00004\u00000\u00004\u0000-\u00001\u0000Q\u00004\u00003\u0000-\u00004\u00002\u0000S\u00002\u0000-\u00009\u00003\u00000\u00005\u0000-\u00006\u00007\u0000Q\u0000R\u00000\u0000O\u00002\u00008\u0000S\u0000P\u00002\u00003\u0000}\u0000\\\u0000r\u0000k\u0000c\u0000y\u0000b\u0000e\u0000r\u0000e\u0000.\u0000r\u0000k\u0000r\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000{\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0002\u0000\u0000\u0000\u00e3\u0007\u000b\u0000F\u0000b\u0000y\u0000i\u0000r\u0000 \u0000C\u0000P\u0000 \u0000v\u0000f\u0000f\u0000h\u0000r\u0000f\u0000:\u0000 \u00001\u0000 \u0000z\u0000r\u0000f\u0000f\u0000n\u0000t\u0000r\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u000e\u0000\u0000\u0000v\u00ae x\u00e3#)B\u0082\u00c1\u00e4\u001c\u00b6}[\u009c\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u00b3\u0086;4\u00e6\u00ee\u00d4\u0001\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\r !\u008f\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000{\u0000S\u00003\u00008\u0000O\u0000S\u00004\u00000\u00004\u0000-\u00001\u0000Q\u00004\u00003\u0000-\u00004\u00002\u0000S\u00002\u0000-\u00009\u00003\u00000\u00005\u0000-\u00006\u00007\u0000Q\u0000R\u00000\u0000O\u00002\u00008\u0000S\u0000P\u00002\u00003\u0000}\u0000\\\u0000r\u0000k\u0000c\u0000y\u0000b\u0000e\u0000r\u0000e\u0000.\u0000r\u0000k\u0000r\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000d\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0002\u0000\u0000\u0000\u00e3\u0007\u000b\u0000F\u0000c\u0000r\u0000n\u0000x\u0000r\u0000e\u0000f\u0000:\u0000 \u00006\u00007\u0000%\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u000f\u0000\u0000\u0000s\u00ae x\u00e3#)B\u0082\u00c1\u00e4\u001c\u00b6}[\u009c\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0086\u00e2\u009e\u00956\u0005\u00d4\u0001\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\r !\u008f\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0002\u0000\u0000\u0000{\u0000S\u00003\u00008\u0000O\u0000S\u00004\u00000\u00004\u0000-\u00001\u0000Q\u00004\u00003\u0000-\u00004\u00002\u0000S\u00002\u0000-\u00009\u00003\u00000\u00005\u0000-\u00006\u00007\u0000Q\u0000R\u00000\u0000O\u00002\u00008\u0000S\u0000P\u00002\u00003\u0000}\u0000\\\u0000r\u0000k\u0000c\u0000y\u0000b\u0000e\u0000r\u0000e\u0000.\u0000r\u0000k\u0000r\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000}\u00c0\u0000\u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u00e3\u0007\u000b\u0000H\u0000a\u0000v\u0000q\u0000r\u0000a\u0000g\u0000v\u0000s\u0000v\u0000r\u0000q\u0000 \u0000a\u0000r\u0000g\u0000j\u0000b\u0000e\u0000x\u0000 \u0000A\u0000b\u0000 \u0000V\u0000a\u0000g\u0000r\u0000e\u0000a\u0000r\u0000g\u0000 \u0000n\u0000p\u0000p\u0000r\u0000f\u0000f\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000",
                        "reg_type": 3,
                        "regkey": "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\IconStreams"
                    },
                    "time": 1574545998.733875,
                    "tid": 1828,
                    "flags": {
                        "reg_type": "REG_BINARY"
                    }
                },
                "pid": 1788,
                "type": "call",
                "cid": 1857
            }
        ],
        "references": [],
        "name": "creates_largekey"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Deletes executed files from disk",
        "severity": 3,
        "marks": [
            {
                "category": "file",
                "ioc": "",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "deletes_executed_files"
    },
    {
        "markcount": 5,
        "families": [],
        "description": "Sets or modifies WPAD proxy autoconfiguration file for traffic interception",
        "severity": 3,
        "marks": [
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegSetValueExA",
                    "return_value": 0,
                    "arguments": {
                        "key_handle": "0x0000036c",
                        "value": 1,
                        "regkey_r": "WpadDecisionReason",
                        "reg_type": 4,
                        "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionReason"
                    },
                    "time": 1574546008.20275,
                    "tid": 3000,
                    "flags": {
                        "reg_type": "REG_DWORD"
                    }
                },
                "pid": 2648,
                "type": "call",
                "cid": 1408
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegSetValueExA",
                    "return_value": 0,
                    "arguments": {
                        "key_handle": "0x0000036c",
                        "value": "\u00a0\u00be\u00d0`d\u00a2\u00d5\u0001",
                        "regkey_r": "WpadDecisionTime",
                        "reg_type": 3,
                        "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionTime"
                    },
                    "time": 1574546008.20275,
                    "tid": 3000,
                    "flags": {
                        "reg_type": "REG_BINARY"
                    }
                },
                "pid": 2648,
                "type": "call",
                "cid": 1409
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegSetValueExA",
                    "return_value": 0,
                    "arguments": {
                        "key_handle": "0x0000036c",
                        "value": 3,
                        "regkey_r": "WpadDecision",
                        "reg_type": 4,
                        "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecision"
                    },
                    "time": 1574546008.20275,
                    "tid": 3000,
                    "flags": {
                        "reg_type": "REG_DWORD"
                    }
                },
                "pid": 2648,
                "type": "call",
                "cid": 1410
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegSetValueExW",
                    "return_value": 0,
                    "arguments": {
                        "key_handle": "0x0000036c",
                        "value": "Unidentified network",
                        "regkey_r": "WpadNetworkName",
                        "reg_type": 1,
                        "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadNetworkName"
                    },
                    "time": 1574546008.20275,
                    "tid": 3000,
                    "flags": {
                        "reg_type": "REG_SZ"
                    }
                },
                "pid": 2648,
                "type": "call",
                "cid": 1411
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegSetValueExW",
                    "return_value": 0,
                    "arguments": {
                        "key_handle": "0x00000368",
                        "value": "{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}",
                        "regkey_r": "WpadLastNetwork",
                        "reg_type": 1,
                        "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork"
                    },
                    "time": 1574546008.21875,
                    "tid": 3000,
                    "flags": {
                        "reg_type": "REG_SZ"
                    }
                },
                "pid": 2648,
                "type": "call",
                "cid": 1478
            }
        ],
        "references": [],
        "name": "modifies_proxy_wpad"
    },
    {
        "markcount": 133,
        "families": [],
        "description": "Deletes a large number of files from the system indicative of ransomware, wiper malware or system destruction",
        "severity": 3,
        "marks": [
            {
                "category": "file",
                "ioc": "",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "ransomware_mass_file_delete"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Resumed a suspended thread in a remote process potentially indicative of process injection",
        "severity": 3,
        "marks": [
            {
                "category": "Process injection",
                "ioc": "Process 2740 resumed a thread in remote process 2648",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtResumeThread",
                    "return_value": 0,
                    "arguments": {
                        "thread_handle": "0x000002ac",
                        "suspend_count": 1,
                        "process_identifier": 2648
                    },
                    "time": 1574546003.515625,
                    "tid": 2184,
                    "flags": {}
                },
                "pid": 2740,
                "type": "call",
                "cid": 14742
            }
        ],
        "references": [
            "www.endgame.com\/blog\/technical-blog\/ten-process-injection-techniques-technical-survey-common-and-trending-process"
        ],
        "name": "injection_resumethread"
    }
]

Yara

The Yara rules did not detect anything in the file.

Network

{
    "tls": [],
    "udp": [
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 662,
            "time": 6.215332984924316,
            "dport": 137,
            "sport": 137
        },
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 6638,
            "time": 12.214940071105957,
            "dport": 138,
            "sport": 138
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8482,
            "time": 6.148574113845825,
            "dport": 5355,
            "sport": 51001
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8810,
            "time": 4.179225921630859,
            "dport": 5355,
            "sport": 53595
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 9138,
            "time": 6.157196998596191,
            "dport": 5355,
            "sport": 53848
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 9466,
            "time": 4.689358949661255,
            "dport": 5355,
            "sport": 54255
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 9794,
            "time": 3.052528142929077,
            "dport": 5355,
            "sport": 55314
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 10122,
            "time": 22.277297973632812,
            "dport": 5355,
            "sport": 55880
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 10442,
            "time": 4.683948040008545,
            "dport": 1900,
            "sport": 1900
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 29852,
            "time": 4.1998131275177,
            "dport": 3702,
            "sport": 49152
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 38236,
            "time": 6.2619030475616455,
            "dport": 1900,
            "sport": 53598
        }
    ],
    "dns_servers": [],
    "http": [],
    "icmp": [],
    "smtp": [],
    "tcp": [],
    "smtp_ex": [],
    "mitm": [],
    "hosts": [],
    "pcap_sha256": "460b6ae10ccdebe4ea17ee75b5432b9543449e8a72450bc47b71a7c390a117b3",
    "dns": [],
    "http_ex": [],
    "domains": [],
    "dead_hosts": [],
    "sorted_pcap_sha256": "7e1fa178a2d639f836674b3812a0f2dd69c22d6803f8a955d0b5ccf7b516617a",
    "irc": [],
    "https_ex": []
}

Screenshots

Screenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandbox

Other files also named advisorinstaller.exe

advisorinstaller.exe (14 votes)

Hashes [?]

PropertyValue
MD5cab5a5e41252cba2f0a736146c8a3504
SHA256c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3

Error Messages

These are some of the error messages that can appear related to advisorinstaller.exe:

advisorinstaller.exe has encountered a problem and needs to close. We are sorry for the inconvenience.

advisorinstaller.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.

Belarc Advisor Installer has stopped working.

End Program - advisorinstaller.exe. This program is not responding.

advisorinstaller.exe is not a valid Win32 application.

advisorinstaller.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.

What will you do with the file?

To help other users, please let us know what you will do with the file:



Malware or legitimate?

If you feel that you need more information to determine if your should keep this file or remove it, please read this guide.

Please select the option that best describe your thoughts on the information provided on this web page


Free online surveys

And now some shameless self promotion ;)

A screenshot of FreeFixer's scan result.Hi, my name is Roger Karlsson. I've been running this website since 2006. I want to let you know about the FreeFixer program. FreeFixer is a freeware tool that analyzes your system and let you manually identify unwanted programs. Once you've identified some malware files, FreeFixer is pretty good at removing them. You can download FreeFixer here. It runs on Windows 2000/XP/2003/2008/2016/2019/Vista/7/8/8.1/10. Supports both 32- and 64-bit Windows.

If you have questions, feedback on FreeFixer or the freefixer.com website, need help analyzing FreeFixer's scan result or just want to say hello, please contact me. You can find my email address at the contact page.

Comments

Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.

I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.

No comments posted yet.

Leave a reply