advisorinstaller.exe is developed by Belarc, Inc. according to the advisorinstaller.exe version information.
advisorinstaller.exe's description is "Belarc Advisor Installer"
advisorinstaller.exe is digitally signed by Belarc, Inc..
advisorinstaller.exe is usually located in the 'c:\users\%USERNAME%\downloads\' folder.
None of the anti-virus scanners at VirusTotal reports anything malicious about advisorinstaller.exe.
If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.
The following is the available information on advisorinstaller.exe:
Property | Value |
---|---|
Company name | Belarc, Inc. |
File description | Belarc Advisor Installer |
Legal copyright | Copyright (c) 2019 Belarc, Inc. |
File version | 9.0.0.0 |
Here's a screenshot of the file properties when displayed by Windows Explorer:
Company name | Belarc, Inc. |
File description | Belarc Advisor Installer |
Legal copyright | Copyright (c) 2019 Belarc, Inc. |
File version | 9.0.0.0 |
advisorinstaller.exe has a valid digital signature.
Property | Value |
---|---|
Signer name | Belarc, Inc. |
Certificate issuer name | Sectigo RSA Code Signing CA |
Certificate serial number | 31a5a09d5c225de221b043a233a50e64 |
None of the 68 anti-virus programs at VirusTotal detected the advisorinstaller.exe file.
The following information was gathered by executing the file inside Cuckoo Sandbox.
Successfully executed process in sandbox.
{ "file_opened": [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html", "C:\\ProgramData", "C:\\", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP", "C:\\Users\\cuck\\Desktop\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html", "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\Desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif", "C:\\Windows\\System32\\oleaccrc.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP", "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP", "C:\\Users\\Public\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP", "C:\\Windows\\AppPatch\\sysmain.sdb", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html", "C:\\Users\\cuck\\AppData\\Roaming", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_1024.db", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility\\Desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif", "C:\\Program Files (x86)", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP", "C:\\ProgramData\\Microsoft\\Windows", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_idx.db", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Python 2.7", "C:\\Windows\\AppPatch\\pcamain.sdb", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0006.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif", "C:\\Users\\Public\\Desktop", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_sr.db", "C:\\Program Files (x86)\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP", "C:\\Program Files (x86)\\Belarc", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html", "C:\\Users\\Public\\Desktop\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html", "C:\\Users\\", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP", "C:\\Users", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_96.db", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html", "C:\\Users\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif", "C:\\Users\\cuck", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_256.db", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP", "C:\\Users\\cuck\\AppData\\", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Desktop.ini", "C:\\Users\\cuck\\AppData", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC\\Desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP", "C:\\Users\\cuck\\Desktop", "C:\\Users\\cuck\\", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png", "C:\\Users\\Public", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html", "C:\\ProgramData\\Microsoft", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html", "C:\\Program Files (x86)\\", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP", "C:\\Windows\\win.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP", "C:\\Users\\cuck\\AppData\\Local\\", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html", "C:\\Windows\\System32\\en-US\\wininet.dll.mui", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP", "c:\\program files (x86)\\Belarc\\belarcadvisor\\belarcadvisor.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools\\Desktop.ini", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP" ], "regkey_opened": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PropertyBag", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\DnsClient", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\BELARC~1.EXE", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D0CBB37A94C46943A90AC5008CF1CC9", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0F4DC93AAA8AD1D448BC4E6A207F4FE0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\ddeexec", "HKEY_CLASSES_ROOT\\CLSID", "HKEY_CLASSES_ROOT\\Outlook.Application.12", "HKEY_CLASSES_ROOT\\Outlook.Application.11", "HKEY_CLASSES_ROOT\\Outlook.Application.10", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0EF52818FCE3E7B488427C1F8266654E", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\11E2BA15171FE704B98E7505E58D7749", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1E82F31DC0D05AA4CB291B7BAA23FC8E", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PropertyBag", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\", "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F356843B045CC0A4BA0D83C1D85AAAFD", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\LSA\\AccessProviders", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A7E9995902A24964C9C5D461E1C86F19", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4486F7CE8F022FB4EB0154C5226C27A0", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4", "HKEY_CURRENT_USER\\Interface", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E429E5BC27530F4786481EC687D9EC9", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0411990C889EE9B47BB0B5D356564877", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CB2182A03B6B11341A1F09A021991CE1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Control", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PropertyBag", "HKEY_CLASSES_ROOT\\.com", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7BF7ABF4D25C03F4582D4BC3082FB208", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Associations", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CF65AB832507EDB4BB357F9D8E0431BD", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9BA984AD4F03E284382FFBB7A68BEE27", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PropertyBag", "HKEY_LOCAL_MACHINE\\Software\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B4BBDDC88CEE4DD439E8BB261CE222A8", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PropertyBag", "HKEY_LOCAL_MACHINE\\System\\Setup", "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3D197E722531D614AB40C182904D9A31", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A558E619ABC4CE5479C1DA5070EFBF81", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\669C9DC1419C0F240B35B36B99AAB50C", "HKEY_CLASSES_ROOT\\VoilaXctl.VoilaXctl.1", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E40FDF839772BEB41AC977860DBB4853", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN", "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ThumbnailCache", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_CURRENT_USER\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\863CA21BBA4DFCE489FDF96EAB898616", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\1.0", "HKEY_CLASSES_ROOT\\.chm", "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler", "HKEY_CLASSES_ROOT\\VoilaXctl.VoilaXctl", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Belarc\\Advisor", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FBEAAA6C37E8AF24B87AAEA0047433BD", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\BELARC~1_RASMANCS", "HKEY_CLASSES_ROOT\\.ade", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\(Default)", "HKEY_CLASSES_ROOT\\.adp", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-699399860-4089948139-3198924279-1001\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D725CB8E57307E64EB574E04214D8B5F", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18F5DB38C45303843B06B1B5025E4820", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\Progid", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\VersionIndependentProgID", "HKEY_CLASSES_ROOT\\Belarc.Computer.Inventory\\shell\\open\\command", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C4040CC509FB0DC4886F590DDF6B6132", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F21868A51A175874BB819DCA5FAA40A3", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE", "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F41A458014D57E54E8DBD0B0CBC361A2", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9E40FDB6330EBA242A4BD5F4FDD0B803", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E3DAE67887931944BCD7171908FA775", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\965742E8F65116F4BB2CB01341464FA7", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters", "HKEY_CLASSES_ROOT\\Belarc.Computer.Inventory", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\335F6F64CD461D9469519574D34757EB", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\17E23EF6C775D324DB90E0E2B7D1CA72", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95EE473833000D6409127D1B85882AC9", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib", "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Network\\Location Awareness", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\HELPDIR", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F05C8358C56DAD54BB81D0A11DD52F41", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\895805CC90C04694887EF6BD140A622D", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B06071FE021ECB04E8B3BF1E39AD5BB3", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8020CF43278B2644190F51544810251E", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\Clsid", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}", "HKEY_CLASSES_ROOT\\.cer", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PropertyBag", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D3541DFF9B79C584284E8981624C04CB", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.EXE", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E85E64F0A7FC58E47A87E5AB98A6F2DD", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\belarc", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B1D5EA6004F809D48B117CE563261011", "HKEY_CLASSES_ROOT\\.html", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B04950B5EC5C924B8F428B5484A2720", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Logins\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\75B368B60C908BA4E87C31F66B02F3F0", "HKEY_CLASSES_ROOT\\Belarc.Computer.Inventory\\DefaultIcon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\ProductOptions", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\DnsCache\\Parameters", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE\\Tracing", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\63B1AF366905AF641BA514CCBAE803C4", "HKEY_CLASSES_ROOT\\.cpl", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-699399860-4089948139-3198924279-1001\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\285499F23409ED14FB4A01230F5DFA91", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}", "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9F5ED6B416EF0A1448D94799D0FF20BA", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FEB01D34D0F67E4F9CD810B432C1B91", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4514EC211C8947C4B9BA24F353AFFD50", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7814D91294731FF4DBBB840810BEB3BB", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\67C12EF40671B7342A2F990919031A57", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PropertyBag", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B690B72A999998C47B5F93C94A8D43B2", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LanmanWorkstation\\Parameters", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0", "HKEY_CURRENT_USER\\Software\\Microsoft\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7C0477DE66D1A6749864FCE02A6DCB6C", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32", "HKEY_CLASSES_ROOT\\.csh", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\315C767EFC72D8445B1D2D16F72653F0", "HKEY_CURRENT_USER\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PropertyBag", "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PropertyBag", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89BBBC8A0D32B014696C4BA3C20CDD34", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9DD74C0626DC33C479C1929714AB5295", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Associations", "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\53F08364FFD17F14B8FD7CA7F52FAE76", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\ShellEx\\IconHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PropertyBag", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A0256FF64030E0746A4AA95D3FFD0BE4", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D04063BE69797D4D8505462827A0D19", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\DropTarget", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\73964AA699D5B5140ADC41ED3F7DB38A", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9753E3A35E3BDFB468DF95B5D19C8A04", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Sharing", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PropertyBag", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StuckRects2", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AD21E12039BB3BC47B1938BC4ABDFEE2", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\(Default)", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\034A8F8E06031EF46BCB4C10469098E5", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84BBAC70FB00B6046881B55CB3122F0F", "HKEY_CURRENT_USER\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OleAut", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\CurVer", "HKEY_CLASSES_ROOT\\.bat", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E116C831A95AB5B4787CE3086FE83631", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D5FD8239A83FE564F97379EA15CE8CB6", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING", "HKEY_CLASSES_ROOT\\.asp", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_INCLUDE_PORT_IN_SPN_KB908209", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PropertyBag", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}", "HKEY_CLASSES_ROOT\\exefile", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PropertyBag", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7636A94AA21EDBB48B6AFFB17E5907B8", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\BELARC~1.EXE", "HKEY_CLASSES_ROOT\\.html\\OpenWithProgids", "HKEY_CLASSES_ROOT\\.cmd", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList", "HKEY_CLASSES_ROOT\\FirefoxHTML-E7CF176E110C211B", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ToolboxBitmap32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\BE0BD5097A638224EB0DAAE870267F03", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B5C8B2FB95B57147954C18085D53ACE", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\040E2A370D6DB2F45AE45A0032BC2179", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\30FAECE2400494D4FB69207288EB5B73", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\FLAGS", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\87C48B95924E3294FBC1766C9225DD0C", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\OpenWithProgids", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\33AB3CD4D27277545B5A93CD4ECB96B4", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus\\1", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FE547D6F0D72534A80F89C4AB727618", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89DF671CDA74E9D4EB10275B10D5CF3F", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9D22CD4619F5DBC499A083AAD70FE7B3", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_CURRENT_USER\\Software\\Belarc", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CE5B971A0DBB8FD4F83AE0DADC348104", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LanmanServer\\DefaultSecurity", "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\shell\\open", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\Clsid", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\InprocServer32", "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Wpad", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0A191B45599EEB74CA305184EA3C2A94", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\(Default)", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\System\\DNSClient", "HKEY_CURRENT_USER\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Programmable", "HKEY_CURRENT_USER\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\04C56B5D827A9194FA2CBFD014EAD0DA", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18D84E9490A485948A17A1F02CDAA62A", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D38A6F5FC8262149A9FAAE8C621EE3F", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95E2C34402A93A14FA8CB3420B85375C", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C1EF68F348457B246A0AD0C18B3079AF", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1C1ED53B8F25FD248955C15232E46886", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\(Default)", "HKEY_CLASSES_ROOT\\Outlook.Application", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\AppCompat", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F591EF48DE97A00428A5BC1AFFFAA868", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LDAP", "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\Memory Management\\PrefetchParameters", "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1A0857155A8EF604FA5D1648CF382DC7", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing", "HKEY_CLASSES_ROOT\\.app", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.EXE\\OpenWithProgids", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PropertyBag", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\2.0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\", "HKEY_LOCAL_MACHINE\\software\\microsoft\\windows\\currentversion\\setup\\PnpLockdownFiles", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLEAUT", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PropertyBag", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\UserChoice", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}", "HKEY_CLASSES_ROOT\\.EXE\\OpenWithProgids", "HKEY_CURRENT_USER\\TypeLib", "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\CurVer", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CLSID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\CLSID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\TreatAs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\ShellEx\\IconHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CDBF699A8F2EAC2438564C3D50E9E638", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PropertyBag", "HKEY_CLASSES_ROOT\\.bas", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\103857F24A2EDA54A800A41FA570861F", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\958C4A0DE6C8D5C428C6E9D875BC33B6", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\msasn1", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AE5A0040C41ACA642AF6DB16F4D2F638", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\MS Shell Dlg 2", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\2FA90A429E82313489DAA2E2C2F0872C", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\62293D511DB84E5489074C5AFA18E882", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FF9FDEA72CD9DDC47A6DAB85F9F76B81", "HKEY_CLASSES_ROOT\\MIME\\Database\\Content Type\\application\/vnd.belarc-bci", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\Insertable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610", "HKEY_LOCAL_MACHINE\\Software\\Classes\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8691BCC36FF121849A90B085BFAF5E5E", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ProgID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE19F224928A59468049F045950CB08", "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Connections", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84C584688CFC74A4E9D36E5EE2E02FA7", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CurVer", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE462B32EFD81040A184ED17E00452B", "HKEY_CURRENT_USER\\Software\\Microsoft\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\296744B7EBFEB2741A47781AE6E32269", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\92F9143E715DEF045A539256438E41FB", "HKEY_CLASSES_ROOT\\.EXE", "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\shell\\open\\command", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\16AC40BE991DF1643B2800729063B2F9", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Version", "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4626147D107665540A84D43A5908E74D", "HKEY_CLASSES_ROOT\\.crt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion", "HKEY_CLASSES_ROOT\\SystemFileAssociations\\.EXE", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1\\KnownFolders", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\", "HKEY_CURRENT_USER\\software", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8ECC347096FA78C4E8291F449F71E16E", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FE056816E41FD2F4CACD03E7A2CA2E6E", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid", "HKEY_CLASSES_ROOT\\.bci", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PropertyBag", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FFFA6DF7EA9EDFC45A1F02FE6DF8F067", "HKEY_CURRENT_USER\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\ProgIDs\\exefile", "HKEY_LOCAL_MACHINE\\NOT_FOUND", "HKEY_CLASSES_ROOT\\htmlfile", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl", "HKEY_CURRENT_USER\\SOFTWARE\\Belarc\\Advisor\\Settings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0\\win32", "HKEY_CURRENT_USER\\SOFTWARE\\Belarc\\Advisor\\Prompts", "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3C68656E520593A45925ADFB41F821B5", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\90860AAA7BD3DE34EB32330DD29CAD62", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\002F6EFFA8A0A40498F3035BD153685A", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PropertyBag", "HKEY_CLASSES_ROOT\\PROTOCOLS", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\Logins", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\BELARC~1.EXE", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\717591555BCB1604BA9777E8A55D0E41", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppCompat", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0FD387D006FD9734FA65B249F36DE42A", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\EEF8AA9EB45B5DB4BBE46B8634C910CD", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}" ], "fetches_url": [ "https:\/\/www.belarc.com\/Programs\/defs.xml?dv=2019.11.14.2&av=9.0&df=B&au=1.0.0" ], "guid": [ "{fdada2fa-894d-47d8-ae78-adf1fd7f28df}", "{00000003-0000-0000-c000-000000000046}", "{49f371e1-8c5c-4d9c-9a3b-54a6827f513c}", "{a4341687-7593-47aa-9554-4b0ffc8b2214}", "{00021401-0000-0000-c000-000000000046}", "{688c934d-0c26-40f6-8d29-d56d72c76b48}", "{c0a6c367-c264-4385-a704-9088bdc3640e}", "{b2952b16-0e07-4e5a-b993-58c52cb94cae}", "{660b90c8-73a9-4b58-8cae-355b7f55341b}", "{54410b83-6787-4418-9735-5aaaabe83a9a}", "{427fd3d4-f30a-4033-84ef-cbb1a955d9f7}", "{dcb00c01-570f-4a9b-8d69-199fdba5723b}", "{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}", "{42aedc87-2188-41fd-b9a3-0c966feabec1}", "{f6166dad-d3be-4ebd-8419-9b5ead8d0ec7}", "{00000000-0000-0000-c000-000000000046}", "{1c1800c1-3258-44c2-be80-3deadb6c5e39}", "{00000146-0000-0000-c000-000000000046}", "{cef04fdf-fe72-11d2-87a5-00c04f6837cf}", "{d0074ffd-570f-4a9b-8d69-199fdba5723b}", "{76765b11-3f95-4af2-ac9d-ea55d8994f1a}", "{79eac9ee-baf9-11ce-8c82-00aa004ba90b}", "{6746c347-576b-4f73-9012-cdfeea251bc4}", "{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}", "{2fb499a3-cfce-480f-a5f3-2453db7a2b7a}", "{00000323-0000-0000-c000-000000000046}", "{6e682784-1eca-4cf2-988d-96b6e89e9a4d}", "{75121952-e0d0-43e5-9380-1d80483acf72}", "{ab8902b4-09ca-4bb6-b78d-a8f59079a8d5}", "{000214ee-0000-0000-c000-000000000046}", "{dcb00000-570f-4a9b-8d69-199fdba5723b}", "{dc8f8556-efbd-4efa-8b64-bba84b4ecd7f}", "{f676c15d-596a-4ce2-8234-33996f445db1}", "{a47979d2-c419-11d9-a5b4-001185ad2b89}", "{46a6eeff-908e-4dc6-92a6-64be9177b41c}", "{50ef4544-ac9f-4a8e-b21b-8a26180db13f}", "{edb5f444-cb8d-445a-a523-ec5ab6ea33c7}", "{7b8a2d94-0ac9-11d1-896c-00c04fb6bfc4}" ], "connects_ip": [ "127.0.0.1" ], "regkey_written": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\InprocServer32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\UninstallString", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus\\1\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\Sort", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\Publisher", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Test2", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Serial Number", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bci\\Content Type", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupView", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByKey:PID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bci\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayIcon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayVersion", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecision", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Computer ID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\UuidMethod", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CurVer\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\InprocServer32\\ThreadingModel", "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts\\License Agreement", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\IconSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\shell\\open\\command\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\InstallLocation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\HELPDIR\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Version\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CLSID\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts\\C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\HelpLink", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\LanguageList", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\CLSID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLUpdateInfo", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)", "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\UserStartTime", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StuckRects2\\Settings", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ProgID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\MaxFileSize", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionTime", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\FLAGS\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Home", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Logins\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\DefaultIcon\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileDirectory", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\GetIpAddress", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadNetworkName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ColInfo", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\ProgramsCache", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByDirection", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\(Default)", "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\LastAdvertisement", "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\PastIconsStream", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionReason", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\Mode", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\belarc\\CLSID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Downloaded From", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Streams\\Desktop\\TaskbarWinXP", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\belarc\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByKey:FMTID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\FFlags", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableFileTracing", "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\IconStreams", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\application\/vnd.belarc-bci\\Extension", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableConsoleTracing", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLInfoAbout", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\ConsoleTracingMask", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ToolboxBitmap32\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\ShellBrowser\\ITBar7Layout", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\VersionIndependentProgID\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\LogicalViewMode", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0\\win32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\ShowNtAdminMessage", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileTracingMask", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)" ], "command_line": [ "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp\" C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll", "\"C:\\PROGRA~2\\Belarc\\BELARC~1\\BELARC~1.EXE\" ", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe" ], "regkey_deleted": [ "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupCollapseState", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\2.0", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ItemPos800x600x96(1)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ItemOrder" ], "mutex": [ "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwReaderRefs", "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer", "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer", "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer", "Local\\Shell.CMruPidlList", "Local\\ZonesLockedCacheCounterMutex", "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer", "Local\\ZoneAttributeCacheCounterMutex", "IESQMMUTEX_0_208", "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit", "Local\\ZonesCacheCounterMutex", "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer", "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex" ], "file_read": [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\desktop.ini", "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif", "C:\\Users\\cuck\\Desktop\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\Desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html", "C:\\Users\\Public\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp", "C:\\Windows\\win.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility\\Desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif", "C:\\Program Files (x86)\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html", "C:\\Users\\Public\\Desktop\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html", "C:\\Users\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC\\Desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools\\Desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll" ], "regkey_read": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0A191B45599EEB74CA305184EA3C2A94\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\67C12EF40671B7342A2F990919031A57\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\90860AAA7BD3DE34EB32330DD29CAD62\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_PowerButtonAction", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\rhqprqvg.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Erzbgr Qrfxgbc Pbaarpgvba.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InfoTip", "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\IsShortcut", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.VagreargRkcybere.Qrsnhyg", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html", "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts\\AutoDownloadDefs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Category", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollDelay", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CF65AB832507EDB4BB357F9D8E0431BD\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\safer\\codeidentifiers\\TransparentEnabled", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E85E64F0A7FC58E47A87E5AB98A6F2DD\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Serial Number", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D04063BE69797D4D8505462827A0D19\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Attributes", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\FuncrPbyyrpgbe.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoProxyDetectType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResource", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Jvaqbjf Sverjnyy jvgu Nqinaprq Frphevgl.yax", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Domain", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableImprovedZoneCheck", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Stream", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Znvagranapr\\Erzbgr Nffvfgnapr.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bat\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zntavsl.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{NN198O3P-PQ8P-7QR1-98Q1-O460S637193O}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\ProfileImagePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\ProgramFilesDir", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Stream", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\QIQ Znxre\\QIQZnxre.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Qvfx Pyrnahc.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\863CA21BBA4DFCE489FDF96EAB898616\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1E82F31DC0D05AA4CB291B7BAA23FC8E\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B4BBDDC88CEE4DD439E8BB261CE222A8\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClearRecentDocsOnExit", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0411990C889EE9B47BB0B5D356564877\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\Content Type", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\InProcServer32\\ThreadingModel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResourceType", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\EnableBalloonTips", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D3541DFF9B79C584284E8981624C04CB\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\FavoritesRemovedChanges", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Zngu Vachg Cnary.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InfoTip", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy VFR.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Security", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\FavoritesChanges", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Category", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\AppData", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bmp\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\285499F23409ED14FB4A01230F5DFA91\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{53123611-QN37-S8QN-SNP9-03R76QO9Q64Q}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7BF7ABF4D25C03F4582D4BC3082FB208\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\DefaultSecurity\\SrvsvcDefaultShareInfo", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A7E9995902A24964C9C5D461E1C86F19\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8691BCC36FF121849A90B085BFAF5E5E\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy (k86).yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Snk naq Fpna.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B06071FE021ECB04E8B3BF1E39AD5BB3\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\FLAGS\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FE056816E41FD2F4CACD03E7A2CA2E6E\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InitFolderHandler", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.TrggvatFgnegrq", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PreCreate", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\FavccvatGbby.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\Shell Folders\\Common AppData", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_LargeMFUIcons", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Gnfx Fpurqhyre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\Auto Update\\UAS\\UpdateCount", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Category", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\qsethv.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\ArgjbexCebwrpgvba.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\103857F24A2EDA54A800A41FA570861F\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\Public", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{P1P6S8NP-40N3-0S5P-146S-65N9QP70OOO4}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\\SuppressionPolicy", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AE5A0040C41ACA642AF6DB16F4D2F638\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\MaxFileSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\freivprf.zfp", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\FavoritesRemovedChanges", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\StartMenu_Balloon_Time", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95E2C34402A93A14FA8CB3420B85375C\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FEB01D34D0F67E4F9CD810B432C1B91\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\\SuppressionPolicy", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Personal", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\FolderTypeID", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FF9FDEA72CD9DDC47A6DAB85F9F76B81\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU Size", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Category", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Pnyphyngbe.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalRedirectOnly", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{15067OP1-P5N8-425R-37P6-SN0O891674S9}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\296744B7EBFEB2741A47781AE6E32269\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InitFolderHandler", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.FgvpxlAbgrf", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Downloaded From", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ZrqvnCynlre32", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Jvaqbjf Rkcybere.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\62293D511DB84E5489074C5AFA18E882\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7636A94AA21EDBB48B6AFFB17E5907B8\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\RelativePath", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Jvaqbjf Rkcybere.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\DevicePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Icon", "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\shell\\open\\command\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8ECC347096FA78C4E8291F449F71E16E\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Icon", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\\JvaqbjfCbjreFuryy\\i1.0\\CbjreFuryy_VFR.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Jvaqbjf CbjreFuryy Zbqhyrf.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\InprocServer32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableFileTracing", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{OQ3S924R-55SO-N1ON-9QR6-O50S9S2460NP}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Favorites", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\MSBulletinVersion", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E429E5BC27530F4786481EC687D9EC9\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9BA984AD4F03E284382FFBB7A68BEE27\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\*", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89DF671CDA74E9D4EB10275B10D5CF3F\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfcnvag.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InitFolderHandler", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\Jvaqbjf Wbheany.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\AlwaysShowExt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\ProfilesDirectory", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParentFolder", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pnyp.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Security", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy VFR (k86).yax", "HKEY_CURRENT_USER\\Control Panel\\Desktop\\SmoothScroll", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Roamable", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewShadow", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResource", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Pictures", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5\\TclTk", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Znvagranapr\\Perngr Erpbirel Qvfp.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\895805CC90C04694887EF6BD140A622D\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfen.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemDrive%\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\\rkcybere.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lnk\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Jvaqbjf Zrqvn Cynlre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89BBBC8A0D32B014696C4BA3C20CDD34\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileTracingMask", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Nalgvzr Hctenqr.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4626147D107665540A84D43A5908E74D\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features\\DefaultFeature", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Fvqrone.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_MinMFU", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Category", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Flfgrz Gbbyf\\Cevingr Punenpgre Rqvgbe.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4486F7CE8F022FB4EB0154C5226C27A0\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Vagrearg Rkcybere.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParsingName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\qsethv.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F05C8358C56DAD54BB81D0A11DD52F41\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\WMI Timeout", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\BELARC~1.EXE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonVideo", "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zboflap.rkr", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\SNTSearch.dll,-505", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9D22CD4619F5DBC499A083AAD70FE7B3\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9DD74C0626DC33C479C1929714AB5295\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_TrackProgs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\InProcServer32\\InprocServer32", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\FbhaqErpbeqre.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\ProfileImagePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\002F6EFFA8A0A40498F3035BD153685A\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bci\\Content Type", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalRedirectOnly", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{374DE290-123F-4565-9164-39C4925E467B}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Description", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\ProgramData", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Icon", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\efgehv.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\zvc.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\717591555BCB1604BA9777E8A55D0E41\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\InProcServer32\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\vFPFV Vavgvngbe.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Computer ID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayVersion", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.cer\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\bqopnq32.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResource", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\displayswitch.exe,-320", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_MinMFU", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.com\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9753E3A35E3BDFB468DF95B5D19C8A04\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\R7PS176R110P211O", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\UuidMethod", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayIcon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{Q4N262QQ-PR44-Q105-S36O-9Q77N8PO65N4}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5\\DefaultFeature", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE462B32EFD81040A184ED17E00452B\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\LastDefsCheck", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\GlobalSession", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\HELPDIR\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Description", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3C68656E520593A45925ADFB41F821B5\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Description", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Roamable", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\KCF Ivrjre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Vagrearg Rkcybere.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Name", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Programs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalizedName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Zrqvn Cynlre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PreCreate", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jbeqcnq.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4514EC211C8947C4B9BA24F353AFFD50\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\HelpLink", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\GetIpAddress", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\MachineThrottling", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8020CF43278B2644190F51544810251E\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Music", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalRedirectOnly", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Zrqvn Pragre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\RelativePath", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Video", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A0256FF64030E0746A4AA95D3FFD0BE4\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C4040CC509FB0DC4886F590DDF6B6132\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\MaxFileSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Sharing\\UsersShareName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonMusic", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParentFolder", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfCbjreFuryy\\i1.0\\cbjrefuryy.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0EF52818FCE3E7B488427C1F8266654E\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7C0477DE66D1A6749864FCE02A6DCB6C\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{35786D3C-B075-49b9-88DD-029876E11C01}\\SuppressionPolicy", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0F4DC93AAA8AD1D448BC4E6A207F4FE0\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Roamable", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\erpqvfp.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParsingName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\P:\\Clguba27\\clguba.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\EnableShareDenyNone", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D725CB8E57307E64EB574E04214D8B5F\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\DisableProcessIsolation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Paint.Picture\\IsShortcut", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileDirectory", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Punenpgre Znc.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollInterval", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\*", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CE5B971A0DBB8FD4F83AE0DADC348104\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Hostname", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PreCreate", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Startup", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParsingName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalRedirectOnly", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.VagreargRkcybere.64Ovg", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\IsShortcut", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Rirag Ivrjre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NoStaticDefaultVerb", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InfoTip", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\GnoGvc.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.chm\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\FavoritesRemovedChanges", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Icon", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Sversbk.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Qngn Fbheprf (BQOP).yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\315C767EFC72D8445B1D2D16F72653F0\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Security", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{7SR8Q22N-SO1Q-N8OR-01R3-6P8693961R6R}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3D197E722531D614AB40C182904D9A31\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\FuncrPbyyrpgbe.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Security", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\mstsc.exe,-4000", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\ConsoleTracingMask", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\HfdefsUrl", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\958C4A0DE6C8D5C428C6E9D875BC33B6\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84C584688CFC74A4E9D36E5EE2E02FA7\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Description", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\qvfcynlfjvgpu.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\lnkfile\\IsShortcut", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\SuppressionPolicy", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1A0857155A8EF604FA5D1648CF382DC7\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap\\.exe", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParentFolder", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Sversbk.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalRedirectOnly", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Pbzcbarag Freivprf.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JS.zfp", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\17E23EF6C775D324DB90E0E2B7D1CA72\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InitFolderHandler", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\GnoGvc.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InitFolderHandler", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\MenuUserExpanded", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\UninstallString", "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts\\AutoCheckDefs", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\FXSRESM.dll,-114", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfNalgvzrHctenqrHV.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Security", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{56784854-C6CB-462B-8169-88E350ACB882}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_NotifyNewApps", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\DelegateExecute", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlot", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\63B1AF366905AF641BA514CCBAE803C4\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Name", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice\\Progid", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1806", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Security", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewAlphaSelect", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\Publisher", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flap Pragre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Test2", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84BBAC70FB00B6046881B55CB3122F0F\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\RelativePath", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Vagrearg Rkcybere (64-ovg).yax", "HKEY_CURRENT_USER\\.html\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Stream", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Fgvpxl Abgrf.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JSF.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\040E2A370D6DB2F45AE45A0032BC2179\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B04950B5EC5C924B8F428B5484A2720\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ProductOptions\\ProductType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Description", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pzq.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E40FDF839772BEB41AC977860DBB4853\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Cnvag.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.crt\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Attributes", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Npprffvovyvgl\\Fcrrpu Erpbtavgvba.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Desktop", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\ArgCebw.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FBEAAA6C37E8AF24B87AAEA0047433BD\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Abgrcnq.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\EnableConsoleTracing", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Security", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{8NOQ94SO-R7Q6-84N6-N997-P918RQQR0NR5}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\Clguba (pbzznaq yvar).yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Documents", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugHeapFlags", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollInset", "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Cresbeznapr Zbavgbe.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\Flags", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\53F08364FFD17F14B8FD7CA7F52FAE76\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\\SortOrderIndex", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\Flags", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Security", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\cevagznantrzrag.zfp", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Paint.Picture\\CLSID\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ErzbgrQrfxgbc", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Home", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Fbhaq Erpbeqre.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\\Orynep\\OrynepNqivfbe\\OrynepNqivfbe.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Category", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\bfx.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_TrackProgs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 6", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Jvaqbjf Rnfl Genafsre Ercbegf.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\Flags", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bas\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Stream", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_LargeMFUIcons", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9F5ED6B416EF0A1448D94799D0FF20BA\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Flfgrz Pbasvthengvba.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\04C56B5D827A9194FA2CBFD014EAD0DA\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Icon", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\puneznc.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLUpdateInfo", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AlwaysShowMenus", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InitFolderHandler", "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\PromotedIconCache", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\RelativePath", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\abgrcnq.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\qvfcynlfjvgpu.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant\\AllowNetworkPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\034A8F8E06031EF46BCB4C10469098E5\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\BELARC~1.EXE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\NoOplock", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InitFolderHandler", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Favccvat Gbby.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParsingName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\TurnOffSPIAnimations", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParsingName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{P804OON7-SN5S-POS7-8O55-2096R5S972PO}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zvtjvm\\cbfgzvt.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Description", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\MEMORY MANAGEMENT\\PrefetchParameters\\EnablePrefetcher", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Cevag Znantrzrag.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Flfgrz Erfgber.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragDelay", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.cpl\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F356843B045CC0A4BA0D83C1D85AAAFD\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\System.NamespaceCLSID", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Zntavsl.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C1EF68F348457B246A0AD0C18B3079AF\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lnk\\ShellEx\\{BB2E617C-0920-11D1-9A0B-00C04FC2D6C1}\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorUseSystemHeap", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Jvaqbjf Wbheany\\Wbheany.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\RelativePath", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\SnippingTool.exe,-15051", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\FavoritesChanges", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F591EF48DE97A00428A5BC1AFFFAA868\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Icon", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE19F224928A59468049F045950CB08\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\669C9DC1419C0F240B35B36B99AAB50C\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParsingName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\kcfepuij.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\2FA90A429E82313489DAA2E2C2F0872C\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\TaskbarAnimations", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Pbzznaq Cebzcg.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\AlwaysShowExt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonPictures", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParentFolder", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\aneengbe.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResource", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{8NN47365-O2O3-1961-69RO-S866R376O12S}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\87C48B95924E3294FBC1766C9225DD0C\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\92F9143E715DEF045A539256438E41FB\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResourceType", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\Zbqhyr Qbpf.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NeverShowExt", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ZrqvnPragre", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\FolderTypeID", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Gnfx Fpurqhyre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B1D5EA6004F809D48B117CE563261011\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\335F6F64CD461D9469519574D34757EB\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0\\win32\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\\JvaqbjfCbjreFuryy\\i1.0\\cbjrefuryy.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResourceType", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Cache", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Category", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfvasb32.rkr", "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F41A458014D57E54E8DBD0B0CBC361A2\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalizedName", "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Description", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\ZqFpurq.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\command", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap\\.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\InstallLocation", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResourceType", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Frphevgl Pbasvthengvba Znantrzrag.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7814D91294731FF4DBBB840810BEB3BB\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\OobeFldr.dll,-33056", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FE547D6F0D72534A80F89C4AB727618\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Description", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{QNN168QR-4306-P8OP-8P11-O596240OQQRQ}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\NoWorkingDirectory", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SharedDir", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\33AB3CD4D27277545B5A93CD4ECB96B4\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\*", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B690B72A999998C47B5F93C94A8D43B2\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.cmd\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN\\*", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_PowerButtonAction", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLInfoAbout", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\InheritConsoleHandles", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D0CBB37A94C46943A90AC5008CF1CC9\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\FileTracingMask", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E3DAE67887931944BCD7171908FA775\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D5FD8239A83FE564F97379EA15CE8CB6\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfCbjreFuryy\\i1.0\\CbjreFuryy_VFR.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Aneengbe.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\Segoe UI", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InfoTip", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Jvaqbjf AG\\Npprffbevrf\\jbeqcnq.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\CommonFilesDir", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0FD387D006FD9734FA65B249F36DE42A\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\Flags", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{OO044OSQ-25O7-2SNN-22N8-6371N93R0456}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E116C831A95AB5B4787CE3086FE83631\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FFFA6DF7EA9EDFC45A1F02FE6DF8F067\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalRedirectOnly", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D38A6F5FC8262149A9FAAE8C621EE3F\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemDrive%\\PROGRA~2\\Belarc\\BELARC~1\\BELARC~1.EXE", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\Flags", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A558E619ABC4CE5479C1DA5070EFBF81\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\FileDirectory", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95EE473833000D6409127D1B85882AC9\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\EnableFileTracing", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features\\TclTk", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PublishExpandedPath", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Zbovyvgl Pragre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\965742E8F65116F4BB2CB01341464FA7\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\73964AA699D5B5140ADC41ED3F7DB38A\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalizedName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pyrnazte.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Stream", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\StartMenu_Balloon_Time", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Startup", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InfoTip", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_NotifyNewApps", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalizedName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\P:\\Hfref\\Choyvp\\Qrfxgbc\\Orynep Nqivfbe.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalRedirectOnly", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Ba-Fperra Xrlobneq.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\FolderTypeID", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\freivprf.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-18\\ProfileImagePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Stream", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Pbzchgre Znantrzrag.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jrypbzr Pragre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\EEF8AA9EB45B5DB4BBE46B8634C910CD\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Jvaqbjf Rnfl Genafsre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AD21E12039BB3BC47B1938BC4ABDFEE2\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18F5DB38C45303843B06B1B5025E4820\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorSystemHeapIsPrivate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\ThreadingModel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\BE0BD5097A638224EB0DAAE870267F03\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\NeverDefault", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AlwaysShowMenus", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\VQYR (Clguba THV).yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CDBF699A8F2EAC2438564C3D50E9E638\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Security_HKLM_only", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DisallowRun", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.asp\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InfoTip", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Zrzbel Qvntabfgvpf Gbby.yax", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Parameters\\RpcCacheTimeout", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\vfpfvpcy.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\SetWorkingDirectoryFromTarget", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9E40FDB6330EBA242A4BD5F4FDD0B803\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Flfgrz Vasbezngvba.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\UseOutOfProcHandlerCache", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1806", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\UseInProcHandlerCache", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\16AC40BE991DF1643B2800729063B2F9\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1C1ED53B8F25FD248955C15232E46886\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zvtjvm\\zvtjvm.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableConsoleTracing", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\30FAECE2400494D4FB69207288EB5B73\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfpbasvt.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Orynep Nqivfbe.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\ConsoleTracingMask", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf QIQ Znxre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CB2182A03B6B11341A1F09A021991CE1\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F21868A51A175874BB819DCA5FAA40A3\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledProcesses\\7914760B", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\XpsRchVw.exe,-102", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B5C8B2FB95B57147954C18085D53ACE\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragMinDist", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\RestrictRun", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18D84E9490A485948A17A1F02CDAA62A\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\11E2BA15171FE704B98E7505E58D7749\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Erfbhepr Zbavgbe.yax", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\NeverShowExt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\ShowNtAdminMessage", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\75B368B60C908BA4E87C31F66B02F3F0\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\RelativePath", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pbzrkc.zfp" ], "file_created": [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP", "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLB63F0.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP", "C:\\Windows\\System32\\GLBSINST.%$D" ], "dll_loaded": [ "C:\\Windows\\system32\\wininet.dll", "C:\\Windows\\system32\\sfc.dll", "C:\\Windows\\System32\\mswsock.dll", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "API-MS-Win-Core-LocalRegistry-L1-1-0.dll", "C:\\Windows\\system32\\advapi32.dll", "srvcli.dll", "apphelp.dll", "CRYPT32.dll", "DNSAPI.dll", "DHCPCSVC.DLL", "kernel32.dll", "UxTheme.dll", "netutils.dll", "C:\\Windows\\system32\\ole32.dll", "POWRPROF.DLL", "dwmapi.dll", "C:\\Windows\\system32\\napinsp.dll", "CABINET.DLL", "imm32.dll", "profapi.dll", "ntmarta.dll", "schannel", "API-MS-WIN-Service-Management-L1-1-0.dll", "PROPSYS.dll", "C:\\Windows\\syswow64\\MSCTF.dll", "WININET.dll", "slc.dll", "KERNEL32.DLL", "OLEAUT32.DLL", "RASMAN.DLL", "comctl32", "ole32.dll", "C:\\Windows\\system32\\uxtheme.dll", "USER32.dll", "Comctl32.dll", "MPR.dll", "API-MS-Win-Security-SDDL-L1-1-0.dll", "API-MS-WIN-Service-winsvc-L1-1-0.dll", "wintrust.dll", "rtutils.dll", "IPHLPAPI.DLL", "SETUPAPI.dll", "C:\\PROGRA~2\\Belarc\\BELARC~1\\System\\NPBelv32.dll", "wininet.dll", "SHELL32.DLL", "C:\\Windows\\system32\\xmllite.dll", "OLEAUT32.dll", "C:\\Windows\\system32\\pnrpnsp.dll", "SHELL32.dll", "RPCRT4.dll", "C:\\Windows\\System32\\winrnr.dll", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp", "SHLWAPI.dll", "C:\\Windows\\system32\\NLAapi.dll", "ntshrui.dll", "RICHED32.DLL", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "DEVRTL.dll", "C:\\Windows\\SysWOW64\\oleaut32.dll", "ADVAPI32.dll", "LINKINFO.dll", "OLE32.DLL", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll", "WS2_32.dll" ], "file_moved": [ [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0006.TMP" ] ], "file_written": [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP", "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP" ], "file_recreated": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp" ], "directory_created": [ "C:\\ProgramData", "C:\\Users\\cuck\\AppData", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System", "C:\\Users\\cuck\\AppData\\Local\\Temp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks", "C:\\Users\\Public", "C:\\Users\\cuck\\AppData\\Roaming", "C:\\ProgramData\\Microsoft", "C:\\Users", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer", "C:\\Users\\cuck", "C:\\Program Files (x86)", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu", "C:\\ProgramData\\Microsoft\\Windows", "C:\\Users\\cuck\\AppData\\Local", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft", "C:\\Users\\Public\\Desktop", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer", "C:\\Program Files (x86)\\Belarc" ], "file_failed": [ "C:\\Windows\\winsxs\\FileMaps\\program_files_x86_belarc_belarcadvisor_system_2911269189da9f55.cdf-ms", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html", "C:\\Windows\\BAVoilaX.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif", "C:\\Windows\\System32\\BAVoilaX.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html", "C:\\Users\\cuck\\Desktop\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html", "C:\\cuckoo_2648.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html", "C:\\cuckoo_1504.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif", "C:\\cuckoo_1788.ini", "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAVoilaX.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif", "C:\\Windows\\winsxs\\FileMaps\\progra_2_belarc_belarc_1_8c5c07b07cc16182.cdf-ms", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html", "C:\\ProgramData\\Microsoft\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif", "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll" ], "resolves_host": [ "wpad", "cuckpc", "www.belarc.com" ], "file_deleted": [ "", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLB63F0.tmp", "C:\\Windows\\System32\\GLBSINST.%$D" ], "file_exists": [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP", "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP", "C:\\Program Files\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BELARC~1.EXE:Zone.Identifier", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html", "C:\\Windows\\System32\\propsys.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif", "C:\\Python27\\python.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP", "C:\\Windows\\SysWOW64\\propsys.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html", "C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif", "C:\\Program Files (x86)", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0006.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif", "C:\\Users\\Public\\Desktop", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP", "C:\\cuckoo_2648.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP", "C:\\cuckoo_1788.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html", "C:\\Users", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP", "C:\\Users\\cuck\\Desktop", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP", "C:\\Python27\\pythonw.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png", "C:\\Users\\Public", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\ThumbCacheToDelete", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP", "C:\\cuckoo_1504.ini", "C:\\Users\\cuck", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html", "C:\\ProgramData\\Microsoft\\Internet Explorer\\Quick Launch", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP" ], "directory_enumerated": [ "", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html", "C:\\Users\\cuck\\AppData\\Local\\Temp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Windows\\System32\\ras\\*.pbk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif", "C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\*.pbk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\*.*", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor2_startup.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif", "C:\\Program Files (x86)", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif", "C:\\Windows", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html", "C:\\Program Files (x86)\\Belarc", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html", "C:\\Users", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif", "C:\\Users\\cuck", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html", "C:\\Users\\cuck\\AppData\\Local", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif", "C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\*.pbk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html", "C:\\Windows\\System32\\rundll32.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif", "C:\\Users\\cuck\\AppData", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif", "C:\\Windows\\System32", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll" ] }
[ { "yara": [], "sha1": "cd1ba54eb4d66a31ee8197fae9b8fef3b8b97a5d", "name": "f8ad2043143cd46e_box+.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\box+.gif", "type": "GIF image data, version 89a, 11 x 11", "sha256": "f8ad2043143cd46e744c6572dd4e474f770547066a250ad1aeca438d0e10faff", "urls": [], "crc32": "39748FA4", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f8ad2043143cd46e_box+.gif", "ssdeep": null, "size": 73, "sha512": "5743ca1ffd126925963bd6123f582bc5b0443a961fba566c1db3f0ebaa13f26a3b8bec1e68179cab3ce4232f1a14f52a195fb65ff9fc064534ca02168c01b520", "pids": [ 2740 ], "md5": "9aefef94b5264d3df673072cf3e301b1" }, { "yara": [], "sha1": "1316271497a29063d3dfe47f3839acd60f3d1a2b", "name": "e9be840931007239_summarynetworkdriveitemlinux.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarynetworkdriveitemlinux.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "e9be8409310072394bc6f17dcbf5b36f440a37ae47c6b2613a8a4f4d60a8686c", "urls": [], "crc32": "C4471D32", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e9be840931007239_summarynetworkdriveitemlinux.html", "ssdeep": null, "size": 241, "sha512": "ec314ddd24350a59a51952b1cde34874a5a579f7d0fdd4b786bac49c49bd34690c545ea06e30a2741a1667c1260d13cfd62ffabf953ae3982d8b1bacbc008be7", "pids": [ 2740 ], "md5": "679b41769d731f1d3b257f2b3f8559dc" }, { "yara": [], "sha1": "c3abfb4ad66e1f087f1056d8be9bec6ca09322e9", "name": "8c3fd32b00b3d870_box-.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\box-.gif", "type": "GIF image data, version 89a, 11 x 11", "sha256": "8c3fd32b00b3d870ec37a958070219a65df27101f517f793338e4b73f478a74a", "urls": [], "crc32": "B40E7D60", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/8c3fd32b00b3d870_box-.gif", "ssdeep": null, "size": 72, "sha512": "c8b0ce281b7708bba114559ba486ddcf4187ac83c1546309fae12d6482e26f5bd3ce9cfcafd9640ace7e03825d44b5343b4fb5028e945773181dc2ee90c2e5c4", "pids": [ 2740 ], "md5": "79d1430acc8b3aa2bfe72972268b5966" }, { "yara": [], "sha1": "81450cfe5d97d92e29acd9df03666fd9fc12e60a", "name": "bb12b8b91009bc00_summaryvirtualmachinedetails.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryvirtualmachinedetails.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "bb12b8b91009bc00c1d4edfefe7d9e110487ba5de91191ed379fb9c38594b93b", "urls": [], "crc32": "D5514ECA", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/bb12b8b91009bc00_summaryvirtualmachinedetails.html", "ssdeep": null, "size": 470, "sha512": "a412a16ea1ce149ce290d620187db0bc658a507bd2d92344df99b4c26d5a0ffcde5a03ff8386b299127a9d1a25cef429db9ee47f360a74c759c91cbd485ddfb3", "pids": [ 2740 ], "md5": "7de6fca80c782db5ea6701c3da3f5cfa" }, { "yara": [], "sha1": "ace9f01ebedd2fa7606e4e46c4d0278d0ac6396a", "name": "85e9ed831b0c3786_benchmarknodetails.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarknodetails.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "85e9ed831b0c37864c2e30c1ac22ac654253b7c5a09a698d35250af4e057a31f", "urls": [], "crc32": "F2F0D111", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/85e9ed831b0c3786_benchmarknodetails.html", "ssdeep": null, "size": 654, "sha512": "ab461ce7e1d37322da567bbb2ae4f2465e0d69f0363ec50da2abde0aa9c4f93ac1313cccc5b8561f21a7137ace7a7a60914f05e6d9076b7fba0f091cb4bac910", "pids": [ 2740 ], "md5": "c3055656250552fb5481f97bc59d7529" }, { "yara": [], "sha1": "bad41a989cb33909bdfd200687d14d79278d5da0", "name": "328239cc4b7c9da9_advisor.ico", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\advisor.ico", "type": "MS Windows icon resource - 2 icons, 32x32", "sha256": "328239cc4b7c9da96dbb7cf387d86958e809eb1c758070f3d8e31eadd212235c", "urls": [], "crc32": "37CE247A", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/328239cc4b7c9da9_advisor.ico", "ssdeep": null, "size": 3638, "sha512": "79e00e864680c55bf342602d1dbcffdb9d36d484124f3ba661cca743354eab38a58a4d7392b73e4fab591f1378a7ed2e06101cbec273a1b5bf05728385f4e6c5", "pids": [ 2740 ], "md5": "dbc017ea686a9ccba18f63db48c57ccf" }, { "yara": [], "sha1": "8109c256172eac6984fead0cdca8d2bd01d2fcf2", "name": "2260ad0937278006_sp_ok.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_ok.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "2260ad093727800628b14f039910de0361f9861a9978473469a915d373313d29", "urls": [], "crc32": "1EE43177", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/2260ad0937278006_sp_ok.gif", "ssdeep": null, "size": 102, "sha512": "720c0e3b01fdf6725e5088e76c1d63fa69d4ea965489cabe0675adb74d54cac511abaf78320dc244360a7664f5c524f9a8976ed12948bb63a8e58667a32daa7f", "pids": [ 2740 ], "md5": "ccaf35ea19f29888b2799375379a2287" }, { "yara": [], "sha1": "ba9e0e136a43e994236420ae86f7de54fe552b57", "name": "db6ea267203e047e_privacy.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\privacy.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "db6ea267203e047ec6cc8cfef48a16f952ddcbe9a4fb4bea239ad0dae50c109b", "urls": [ "http:\/\/www.belarc.com\/Advisor2\/legal_notice.html", "http:\/\/www.belarc.com\/ba5.html?B", "http:\/\/www.belarc.com\/privacy.html", "http:\/\/www.belarc.com\/ctadvisor.html?B" ], "crc32": "17F7E5F9", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/db6ea267203e047e_privacy.html", "ssdeep": null, "size": 2379, "sha512": "b034ec207813d164ffcb00e953a7c882c18ccb05b1d35c47fc4a3f1d877f4452311d2fca2c6689735670825d56046461fd5b4add6db8daa8dda8e46f89aabd70", "pids": [ 2740 ], "md5": "29d5eaba883670efab3e5c2c1bce30d0" }, { "yara": [], "sha1": "cc930b9bcb9b624798331bfa28abfb6e62df5d97", "name": "bbf26c273c6ae6b2_lock.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\lock.gif", "type": "GIF image data, version 87a, 13 x 10", "sha256": "bbf26c273c6ae6b20492f7beff37b6ec4aa91b1292e563005727484428523241", "urls": [], "crc32": "5E26BC5F", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/bbf26c273c6ae6b2_lock.gif", "ssdeep": null, "size": 140, "sha512": "fed6c25a14ea3f114ed0fa63074bd78a298e010bb049b724b56447f5ca5cbac30ded7cccc4c1bfc584b777edc024756c91fe9519290ca43dd3dedfb63b093487", "pids": [ 2740 ], "md5": "4aede16b3cec0a29066cdd7e1daeeb91" }, { "yara": [], "sha1": "0cdf49082ef4cdc15f8bcd6ec787cc1b08257edd", "name": "408366548e6ca13b_osautoupdateformats.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\osautoupdateformats.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "408366548e6ca13b7db2cbcf8be8ba291bb773e0887f0aa21e168f727c6eba4e", "urls": [], "crc32": "F0E800A9", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/408366548e6ca13b_osautoupdateformats.html", "ssdeep": null, "size": 658, "sha512": "ad9c65f611753cb0ff9f3191f3cfc2225ac03c89deb3ec6a3160872f6c86bb38b731588ab79e16851a8133d8cae34f2ea28e15ad1f6d9fa48dd1f436512adb27", "pids": [ 2740 ], "md5": "9d49bd8f5b2083381efe60b739212c01" }, { "yara": [], "sha1": "35b69ee49c8d3643f370ca5335d45e4a36d1f1b1", "name": "912df781f305ffb9_corner_bl.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\corner_bl.gif", "type": "GIF image data, version 89a, 16 x 16", "sha256": "912df781f305ffb9367967b941de7cb5ab79cf8011193080fbc6bc36c0855cf8", "urls": [], "crc32": "47EEBA1F", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/912df781f305ffb9_corner_bl.gif", "ssdeep": null, "size": 71, "sha512": "03f72e344f964649432d27288a8a11943de367671b6d4890fb6fba37dfc3a64c9fc0f757bcde5ca1d38666de0a043f1400881e9e2ea2a2406832fcf27ad61f92", "pids": [ 2740 ], "md5": "ed3f3adb2fcb8730320b1a9cbfe3ef7c" }, { "yara": [], "sha1": "bf76ecbcd819faf9196734ac9244749d00aa6b3b", "name": "316b646a9adc7939_securitypanelsu_alert.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelsu_alert.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "316b646a9adc793953786d826394ceac1b8ba1bbfb660c84467858609de0a3f4", "urls": [], "crc32": "5F8869F4", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/316b646a9adc7939_securitypanelsu_alert.html", "ssdeep": null, "size": 411, "sha512": "46cc26499129e15b756a51bb00f4aa347f98678e93805a181e3300cd3678636bac3514eb1ed1606915408a25ea8f6a74c9f108cf1024684cae33c1456f557cad", "pids": [ 2740 ], "md5": "d40804fb0c796dcf2f8b95d759a21d02" }, { "yara": [], "sha1": "7aed252dc4e235e6f596ed4de19006cc804f40b6", "name": "7b536b3e7de1ca42_summaryusbstorage.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryusbstorage.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "7b536b3e7de1ca42bf825c26af98f2ca36ce616690085e949419a907b0579770", "urls": [], "crc32": "800DED95", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/7b536b3e7de1ca42_summaryusbstorage.html", "ssdeep": null, "size": 257, "sha512": "99d7ce6189702887ea33e057a24cf04ea4784da100acf0a5bb5c8c40900ec529bc142c64b2de4b3591416773ce872cf83929af13a6ce74fe34500d0ac8aa2120", "pids": [ 2740 ], "md5": "3914f20325a3a7defc661d0bbbd394e6" }, { "yara": [], "sha1": "bb82145e86516859dae6d4b3bffb08c727b13c65", "name": "49833d2820afb1d7_GLJ5837.tmp", "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp", "type": "PE32 executable (GUI) Intel 80386, for MS Windows", "sha256": "49833d2820afb1d7409dfbd916480f2cdf5787d2e2d94166725beb9064922d5d", "urls": [], "crc32": "858B906D", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/49833d2820afb1d7_GLJ5837.tmp", "ssdeep": null, "size": 2560, "sha512": "c14b7ec747357c232f9d958b44760e3a018df628291e87de52b8174ccc4ada546eba90a0e70172d1db54feca01b40cd3aeaa61b8a2b6f22d414baad1f62e8e54", "pids": [ 2740 ], "md5": "6f608d264503796bebd7cd66b687be92" }, { "yara": [], "sha1": "4637bff23431d165bdd9ac29a9fba205e3ab807e", "name": "ff515c4555dd28d0_summarylogins.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylogins.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "ff515c4555dd28d0628902c3fd4e61bf25b53a25feadda694797387678deffd2", "urls": [], "crc32": "D19DBB9F", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ff515c4555dd28d0_summarylogins.html", "ssdeep": null, "size": 71, "sha512": "8d816616620663751a639a17041382983309d0a87c1183e22a0abf657ba68538d2f6957c129dec8cd4c7824bdf7c78d4c219febc428a039bcaf2eaf40f0c6414", "pids": [ 2740 ], "md5": "e65919ca4ec8330229824c4e52e4a4dd" }, { "yara": [], "sha1": "8e15bebbdf5faddf7f1c3aaebd0b00a59f4f0550", "name": "80323601c0b978a1_shfs2.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\shfs2.gif", "type": "GIF image data, version 89a, 13 x 10", "sha256": "80323601c0b978a19a87cf755a23d8988398ea3d535b6c439b35f18c9c7114e2", "urls": [], "crc32": "C5C704FC", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/80323601c0b978a1_shfs2.gif", "ssdeep": null, "size": 72, "sha512": "50c4d4830d5c2a92c281822997028f81d33555f46a02b6be54413e92c303559873252b025b81ca6b5b1ec34150f6f9a12496d15b57c3b23dddc00d2bef8119c3", "pids": [ 2740 ], "md5": "3e59f73ddfe472eb2591769e9fac3879" }, { "yara": [], "sha1": "b106dcca002a19cd84ad795e5d3dd3cc7e62178d", "name": "fedde999e79b8451_advisor.bcx", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\security\\advisor.bcx", "type": "data", "sha256": "fedde999e79b8451cd405a1e395e36e53ad2b3d6144928d7857a03188a8811d4", "urls": [], "crc32": "7F42744F", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/fedde999e79b8451_advisor.bcx", "ssdeep": null, "size": 459, "sha512": "f051afd51ef47073e01477e3d59f8c684b3a28ab02ae697bfe73c1c7ced82002abed10f9aa783f3d9f2533c2cdbaaa151c32a5bfd06b23be2f0e9567c011ccf7", "pids": [ 2740 ], "md5": "5016766a9d608ab1c6d53d454f2a9409" }, { "yara": [], "sha1": "098bcc45c7e32ba8dd0870c37bb6953a676ff937", "name": "d18c054f455f8a2e_securitypanelsu_ok.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelsu_ok.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "d18c054f455f8a2e2b9f01e6614619d442af20f69efd11db62cc2514902672a9", "urls": [], "crc32": "55EFD95D", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d18c054f455f8a2e_securitypanelsu_ok.html", "ssdeep": null, "size": 396, "sha512": "14f4dccb920dc5ea9fc16645b7bdf59fcacd087159b92b1c821aebedf127f31bc68584bf9c89cbaf0e13b987e9235840e131edfeb6b16e1d3225427dea5cbc37", "pids": [ 2740 ], "md5": "4482f0d4dd328d06dbace17e8620ecee" }, { "yara": [], "sha1": "040c8efec94061ff735d00a4be7a839fb08cfb0c", "name": "b1fc0b4b0dbfa982_shfs0.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\shfs0.gif", "type": "GIF image data, version 89a, 13 x 10", "sha256": "b1fc0b4b0dbfa982a9166dc54c6c55cff01c6eddef42bf58738c03ab3fe8775a", "urls": [], "crc32": "DC292604", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/b1fc0b4b0dbfa982_shfs0.gif", "ssdeep": null, "size": 43, "sha512": "a12886009b0c48e27acc4fd122f7d4c6abfb235cfbf8eb10fc73fd50e59e8ee37bfc7cc23967506c10569281eb8548bf0990e20574ad14959bf21cd28a630b37", "pids": [ 2740 ], "md5": "c2d263df831635d0a9e00505b38d4e59" }, { "yara": [], "sha1": "84c00e4cd196a2edcbf30a25ecc9283c3e4985e1", "name": "746fb2936e6c2f30_corner_br.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\corner_br.gif", "type": "GIF image data, version 89a, 16 x 16", "sha256": "746fb2936e6c2f30f820742c73c8b890e5cd507e8927189585d72f35f610bad5", "urls": [], "crc32": "01820616", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/746fb2936e6c2f30_corner_br.gif", "ssdeep": null, "size": 71, "sha512": "e0d7fefb08b8f3cfe851e0bc24a6d2ca295ee498963daee77b93e1381a59d7ca4a63895aa97d05cc9cb1ef6b45c826f9db4a1fb256f584fd59d8a3bebb6bd297", "pids": [ 2740 ], "md5": "5d1ac1c75cce09f6a18b7140d90addc0" }, { "yara": [], "sha1": "0fa0d3f6692f31fdabefb719b0f7a28cbf5d5415", "name": "1c574eab5e83ccfe_GLC5826.tmp", "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp", "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows", "sha256": "1c574eab5e83ccfe5a0bb7b59e028cc5fa2f4e77868051e305d83c709711ff77", "urls": [], "crc32": "D88E1477", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/1c574eab5e83ccfe_GLC5826.tmp", "ssdeep": null, "size": 164864, "sha512": "d73e3832777341a4176dbd9988002ec94a32f162492e869a8c03d9bb10f1833821f99e15710e9fc103a2820c862cf14a0b990d7c7c09150bb14618a7c93ca5fd", "pids": [ 2740 ], "md5": "09e59d00df5d2effd8dd9b30385cb9d2" }, { "yara": [], "sha1": "37d116f82c927b2a13f788f63df215c8e71ab65a", "name": "a286513b56f2766d_sp_s4.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s4.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "a286513b56f2766d304491b869538c8b22c5c10b8b2a9a560d7055f93c4ba814", "urls": [], "crc32": "D7BD2E79", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/a286513b56f2766d_sp_s4.gif", "ssdeep": null, "size": 1170, "sha512": "a2608ade2ea76899032e644459521cfc232143cff9e010ad16aea5dacfe48d85d11c49754a37d92f4a6b53ccb286a46b7fbc0450436785cccbe01fbe7016b3a5", "pids": [ 2740 ], "md5": "b83528fb0d08d33269f23f0c2f83fa2f" }, { "yara": [], "sha1": "9f027f2b0d3e67a31ee7ea73c7229e277cfb89f1", "name": "f87eeefa46d506fe_benchmarksummary.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarksummary.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "f87eeefa46d506fe3cbb2763d30550da630ea6e0b63e1b80bec9fd6f7f43a675", "urls": [ "http:\/\/www.belarc.com\/ctsecurity.html?B" ], "crc32": "CDBCD5B4", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f87eeefa46d506fe_benchmarksummary.html", "ssdeep": null, "size": 4607, "sha512": "1d8f9ea57b34ca9f47d615cb5a2b0e4a887a2ae664fde0fd607f476c7441e4c05588ba07f7c201f59d8a5b7209c2fc9171ab5065584e4a3a8395ed5b2aa89847", "pids": [ 2740 ], "md5": "f4a268e7dff0a093c7bda4cc6612686c" }, { "yara": [], "sha1": "ac991ffd54ea192d32eff9ed0a4c9c56d305835d", "name": "6d69ec3e21200294_securitypanelsu_unknown.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelsu_unknown.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "6d69ec3e21200294efd146354e9d3185772d698d83aa56db235752b33647433d", "urls": [], "crc32": "7E8437A3", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/6d69ec3e21200294_securitypanelsu_unknown.html", "ssdeep": null, "size": 416, "sha512": "9d1b2ca3a1c91701803679dc9b0bb352d506141b3f7e74edcf46ec3232b06b842157528222778ca019356806af2f66a574aeb66f068b38df87c78f7dd7a727dd", "pids": [ 2740 ], "md5": "e18ea5e71e8be06727eefcb038f7c906" }, { "yara": [], "sha1": "9d29601802ee7bc83518c09fbca94a6ed7a98f03", "name": "eae26c02bd9e19bf_sp_s14.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s14.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "eae26c02bd9e19bff8bcbc43396424ec71add32714c47cab8b66a1beaf92997b", "urls": [], "crc32": "0C85E829", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/eae26c02bd9e19bf_sp_s14.gif", "ssdeep": null, "size": 1205, "sha512": "d9658d97e27581efb34783e181cf6767fe95ceb5b2143d787a75b67d208e286dfeac51f54a51b703950f1f4048cb2f1d3ac02778057d6525d10f930abf683aa5", "pids": [ 2740 ], "md5": "3d6085ecb305e83d7965834e1cd9447c" }, { "yara": [], "sha1": "53a9c158aa76a30b35cb058093478bbf1f5115f7", "name": "b62288fb14044b41_antivirusitems.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\antivirusitems.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "b62288fb14044b419c9ec726ea8608f9594aceb895f0db483d5f27bca0e77a13", "urls": [], "crc32": "5BAB4F2C", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/b62288fb14044b41_antivirusitems.html", "ssdeep": null, "size": 702, "sha512": "a588c45e94bd80384d08d4afd60dd5201ef5649f633fde337c196e6afbbef555eedfa5d89c3380da37f5754901f211a3be56f9b2c2a7e202a0a18864d604c621", "pids": [ 2740 ], "md5": "2aeffcc254dd6ca230725d8803fef704" }, { "yara": [], "sha1": "32fd9f89230e68c0769b9925060646366c182aaa", "name": "7281b20fad0368d3_brandlinks.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\brandlinks.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "7281b20fad0368d3abeafaf8a1649f08474f23631978c962663112478dd67b2f", "urls": [ "http:\/\/www.belarc.com\/ba5.html?B", "http:\/\/www.belarc.com\/ctadvisor.html?B-saas", "http:\/\/www.belarc.com\/ctadvisor.html?B" ], "crc32": "0022EA1B", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/7281b20fad0368d3_brandlinks.html", "ssdeep": null, "size": 446, "sha512": "104e45430deb19d88fcf8595352531c72c4bce99150dafebfdf39907eea268112b4eb1b900d6cd54dbfbcee782c28532bd038408cfa0e8349f102a2aa50c3e07", "pids": [ 2740 ], "md5": "94db17d2ced4c5927f88b2e9744c5c67" }, { "yara": [], "sha1": "524bdb79fbeaaf1507ebd40869c950037bea2919", "name": "2c627929b971a7b6_summaryusbstoragefootnotes.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryusbstoragefootnotes.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "2c627929b971a7b6476a7349b9903625ef51322bf41baf5f0998aa045109fad8", "urls": [], "crc32": "F91B2225", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/2c627929b971a7b6_summaryusbstoragefootnotes.html", "ssdeep": null, "size": 171, "sha512": "e2b77df82cc62d63736ec334c7d6e9d3dc12bde32a782f67e46cf05d2257c64079df3f826c1ec46bcb2a38a0bca6ee1a2bdc1785643899fa17fed03cd2ad7095", "pids": [ 2740 ], "md5": "2198e4dae600fa4d7976b72f37e712e0" }, { "yara": [], "sha1": "8b3c0c8633f1bb48a55f86874f0217bae7f8b01a", "name": "9887a5e64da2a094_sp_s11.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s11.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "9887a5e64da2a094a67bd6a052a7586f9653f1e89d6db413669abf4b6fa55ed8", "urls": [], "crc32": "A480B424", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/9887a5e64da2a094_sp_s11.gif", "ssdeep": null, "size": 1195, "sha512": "00b9485a45669d42885c287b0626ff199537909dd8e850cb44adffc380965535d12717dedb80bd1cde296d7f042fe1a6d5c6abf1d769592093e4fb605d8ac0bd", "pids": [ 2740 ], "md5": "772bd8800d5d137daf717917bec3d62f" }, { "yara": [], "sha1": "3c9c28fd352015b0e3c2374dd6b3088a9718dad4", "name": "e6b90dc03f8c7516_summaryusbstorageitem.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryusbstorageitem.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "e6b90dc03f8c751628a0e6dbe2e0741f094eb106aed32fe99814a7b23b3167ca", "urls": [], "crc32": "DCE4608A", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e6b90dc03f8c7516_summaryusbstorageitem.html", "ssdeep": null, "size": 169, "sha512": "c024faabba67e1633a97bb621f6b1f2aff3de8be47b2a17eb074abedff5cb761ba3cd7f2170a8e857e221c86d0ccdeebdd18c0d398505690d47d052eec8b2df7", "pids": [ 2740 ], "md5": "98d1929d1d65d9945adce328091a86ed" }, { "yara": [], "sha1": "24c450f0ee635f783e8002ba943c0de7791491d3", "name": "d355cec4dcf65568_securitypanelav_ok.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelav_ok.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "d355cec4dcf65568e82c77d555a4b38bf9d466a6b37368cbc244742c52841bb4", "urls": [], "crc32": "1650227C", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d355cec4dcf65568_securitypanelav_ok.html", "ssdeep": null, "size": 397, "sha512": "3c69be7c06aeefbf9287ce3e211d26451b2d2403605647e851b568fe6ba7527d5d9156e3191017778b498668ff007089d94627e60a18e7fc7afde5911812aa64", "pids": [ 2740 ], "md5": "393b4b0eaf81fd669b7bb7f41e39d298" }, { "yara": [], "sha1": "17e73f95269b712e43279f84af56bac7fd05adda", "name": "96b70ccb73625f9b_summarylocaldrives.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylocaldrives.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "96b70ccb73625f9bf1c122cf00ea72ac4a767fa7888e4c6356b378c044609624", "urls": [], "crc32": "D613EAA2", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/96b70ccb73625f9b_summarylocaldrives.html", "ssdeep": null, "size": 267, "sha512": "d935e7422780494d694b53ec355add1e52add0e012ee21c918a1290a00dafb096e3d0a6e9528055bf3d68f6e8c51db336162635783eb12848ad544fcb3accf08", "pids": [ 2740 ], "md5": "3098ea6db32de3fbcaa4fcd58d2a870b" }, { "yara": [], "sha1": "e9d08afb387c74c5805d02d4b8b9302688ce599b", "name": "6e7ecd76b22fd066_sp_s13.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s13.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "6e7ecd76b22fd066329a11e2e1e23f6a6f9e589046456a684b52f54898e3d91a", "urls": [], "crc32": "F65DDB4A", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/6e7ecd76b22fd066_sp_s13.gif", "ssdeep": null, "size": 1199, "sha512": "a545d6e03c7dc0d3943e79ee14a7326c5754af695ea4ffedff553306da9bfb00cfa0cf2e1cdd8f00e553125cdfb30d1a77575720c7c5e590770728e08a213afa", "pids": [ 2740 ], "md5": "a67fce4bc2e6483a6b5d30aa5472a641" }, { "yara": [], "sha1": "93c094896df3c2af556ec4bb4a3fda6c96dc458c", "name": "8b0882bb863686b2_belarcadvisor.exe", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\belarcadvisor.exe", "type": "PE32 executable (GUI) Intel 80386, for MS Windows", "sha256": "8b0882bb863686b28c0fbc1b982371f632243043055cf0d62dc56cbe72326dc6", "urls": [ "http:\/\/www.usertrust.com1", "http:\/\/ocsp.comodoca.com0", "http:\/\/crl.usertrust.com\/UTN-USERFirst-Object.crl05", "http:\/\/crl.comodoca.com\/COMODORSACertificationAuthority.crl0q", "http:\/\/crl.comodoca.com\/COMODORSACodeSigningCA.crl0t", "https:\/\/secure.comodo.net\/CPS0C", "http:\/\/ocsp.usertrust.com0", "http:\/\/crt.comodoca.com\/COMODORSACodeSigningCA.crt0", "http:\/\/crt.comodoca.com\/COMODORSAAddTrustCA.crt0" ], "crc32": "4D26B1EE", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/8b0882bb863686b2_belarcadvisor.exe", "ssdeep": null, "size": 134824, "sha512": "0f2cd2dee6623a57177060f48faca2bc78757aee9150764f4d73172906e668b7e487a12de64a7065b4e948e17438a83c887fa5846b529d00a0e6a96ea9430344", "pids": [ 2740 ], "md5": "7b32f61c6410664877fccaac4c810350" }, { "yara": [], "sha1": "c844e4f897668adf219b6d048ba769a689cfc83f", "name": "ba5e9c26700b7ba6_summarylocaldrivesfootnotes.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylocaldrivesfootnotes.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "ba5e9c26700b7ba66c4e0f7aa4a3c76d89ab49a5c9cc5d47d418ac206c52ff40", "urls": [], "crc32": "D4F1BF5E", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ba5e9c26700b7ba6_summarylocaldrivesfootnotes.html", "ssdeep": null, "size": 385, "sha512": "06a5050658e90a0ac2fbc4cbd6c4cbdbdd89db9806e7b069ea5ff6383d62ad2bbe7a0c925294da86c937a35eaf1bf9fe196ecdf27ded64adebe37ba0d162e4c9", "pids": [ 2740 ], "md5": "cd5931793ff7ff983581270bacfadef3" }, { "yara": [], "sha1": "092e0f5a68ce3b7f0589688ca12db729dfa1bbf2", "name": "98faa1c7f95e1b93_no.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\no.gif", "type": "GIF image data, version 89a, 10 x 10", "sha256": "98faa1c7f95e1b93781263af7552f48652298fe47115cbc64236d2694c16ca51", "urls": [], "crc32": "F2AB791D", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/98faa1c7f95e1b93_no.gif", "ssdeep": null, "size": 61, "sha512": "e10cd6b09f756f0acf59ac1a94e54347c6b411bbe00c4030e89802b9081726b0e9cc1b16a0139b1b6f4e0648a0bf888a2aa9b1fcc899f055cae47a9294371493", "pids": [ 2740 ], "md5": "951b6ed803d9dd6615a064b9c510375d" }, { "yara": [], "sha1": "044741717d24d750a882ed25d8fa5755d8483dc1", "name": "284682a9fd7d1f22_sp_alert.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_alert.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "284682a9fd7d1f2281b850b842de0bdaa3e3238ec0f19827c05b5c0d0f1ced9c", "urls": [], "crc32": "E17BA28C", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/284682a9fd7d1f22_sp_alert.gif", "ssdeep": null, "size": 148, "sha512": "036ab222b571e338c89b7180831aa68cfe895759970b18ff6ee70109309f1699a600bf1708dd83d93c18bc7bbd1494a0d95df179bc1953a21e15989e701dc1db", "pids": [ 2740 ], "md5": "2edb6cff76a0fc1eaaa7500674c67fa8" }, { "yara": [], "sha1": "25032bcc7e8e9a10060bdcb2ca95a8b4ebeb7554", "name": "2307d540f9986c74_summaryusername.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryusername.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "2307d540f9986c740c8e45e61f814e74ddd2f892d56e664acd726f0e68b860a6", "urls": [], "crc32": "389AB10C", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/2307d540f9986c74_summaryusername.html", "ssdeep": null, "size": 95, "sha512": "b4bf7411adfc649bb2f05adc4fdb61bca12d2527a0f0e91f34ba160a34c26285952e927fd9d5d4b9caafdcce1965ff13a39810097ec978e6c82a1302a61c3fcb", "pids": [ 2740 ], "md5": "9d077d7a70da7306bf8353f6af124ea1" }, { "yara": [], "sha1": "d087235cc220ee1b61ffae9fc336472e36a8e229", "name": "729c401d41ea4503_sp_s6.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s6.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "729c401d41ea45039fa04bcd62a87eb31e2b52f120439aaa90271f91a56c7c81", "urls": [], "crc32": "5AC0AEC0", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/729c401d41ea4503_sp_s6.gif", "ssdeep": null, "size": 1200, "sha512": "5c77f69d8819514d876c76935cc422120e2997dc9f5b7ec31255dd84e9c7cffcda14ca752b66e2e84c22a73809bf45788375497af33ece2ad92832298cf7b122", "pids": [ 2740 ], "md5": "f77da2ce3870489f09a93fa9d2f73df2" }, { "yara": [], "sha1": "dde7e6429029513fc8a2a6f3d213f610592969be", "name": "e474dd417221a1e5_sp_s3.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s3.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "e474dd417221a1e56948047fa28711454342231812836726bb34630b5be6bff4", "urls": [], "crc32": "654A3083", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e474dd417221a1e5_sp_s3.gif", "ssdeep": null, "size": 1181, "sha512": "ef19bfd137a3e898bdb7c1fcc8cc20ed7d5a3eb14eab4e0c514c8d75a2b4060a3d9c5dbdc60ee34603161b2d55b5a59a25fbcb68146c6d1f8c83d06eb7e66142", "pids": [ 2740 ], "md5": "f64e613f8f3c9341cb8ec5109e8f71f3" }, { "yara": [], "sha1": "08acbdd75f69b69bd4bf0b0dd39e8eafce3c3492", "name": "762cf68db65598ae_summarydnssuffix.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarydnssuffix.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "762cf68db65598aebcdc2d6e2adcd8bfed122f788d2ef894775dd77f39a91348", "urls": [], "crc32": "6B58264F", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/762cf68db65598ae_summarydnssuffix.html", "ssdeep": null, "size": 94, "sha512": "e2c26e7fabb81c6c2bddec561f3039195d63d8f4c901e9a837ddc475d7da38a9767cf1542e74bbab6f936ee06146565eb0fd00ff3f61a380582bbd9f667db830", "pids": [ 2740 ], "md5": "fe6837c27e02f34810c51a50a7f30d98" }, { "yara": [], "sha1": "1f0df1bd53a30e8bef5b05189c6ef734d83e90b2", "name": "aff420b165422950_summarynetitems.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarynetitems.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "aff420b1654229508f062c71eb3ce479145e2fa16cb4fe9a605b51f283e6d9ca", "urls": [], "crc32": "C869A5BC", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/aff420b165422950_summarynetitems.html", "ssdeep": null, "size": 1509, "sha512": "ad38a85368b7f604ffbfc6b9173e6687d201e13d180e042af5f5fc2f388310514d640c47660411d8dec4943a0d5e21ebff0e468776e8665bdbf946908f99d0eb", "pids": [ 2740 ], "md5": "d944eae9fc656490ba838835c93bd99b" }, { "yara": [], "sha1": "5dbdd67015cc2f77743f3261330863ab54c77aaf", "name": "d177e4729385bcd1_corner_tr.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\corner_tr.gif", "type": "GIF image data, version 89a, 16 x 16", "sha256": "d177e4729385bcd1027679b704342517ea37fc55b94b61e16a022cbb9f9fbcbd", "urls": [], "crc32": "FC4720FD", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d177e4729385bcd1_corner_tr.gif", "ssdeep": null, "size": 72, "sha512": "faa94d0a5248b4d910c6cc6c42e8ac2ec0864e33ca69e5a082ce80e4c469393c7b42f0d6abd3227d38367f376f666037228ac048b3d45c87f40ff0b6e6e8bedd", "pids": [ 2740 ], "md5": "a3b7431e4ec6e09e23d2fe00558a6137" }, { "yara": [], "sha1": "ff7692f3fac23efc1ab7b94ca1cba97f92941198", "name": "4088f0981eabd7de_scoring.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarks\\scoring.html", "type": "exported SGML document, ISO-8859 text, with CRLF line terminators", "sha256": "4088f0981eabd7de01d824b75937a2e4174dc00a0fb67dfa860c3257f628518a", "urls": [], "crc32": "4F634158", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/4088f0981eabd7de_scoring.html", "ssdeep": null, "size": 774, "sha512": "c4be2f7d25c250694cb9bb7c4fe4f44d976e7e4a5c05ff65686a1e842a15eb6a9e4e628cdabc69e4f8f13b4dc525f14289f30876d3eb5306e23d947a90888892", "pids": [ 2740 ], "md5": "f2d5840384273ba3da4c45fa9567f07c" }, { "yara": [], "sha1": "1e04b813edb07aa8c526ceafba3d21f9990aac07", "name": "093b69eea436d692_softwarelinkformats.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\softwarelinkformats.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "093b69eea436d6925fea2c32f850376c674f10b8ff49e3451fed7179d4aa14d3", "urls": [], "crc32": "7A94EB33", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/093b69eea436d692_softwarelinkformats.html", "ssdeep": null, "size": 2550, "sha512": "96f1d09d7ce776b11956b15e23938209f5c80c49790c25111a28c90c8d660455880627e94d99d31a80e88e8a5fc0445242687c64c9707a33f0676875483a2b98", "pids": [ 2740 ], "md5": "cd6cb649dce3c8f601410abc1dbd4bc7" }, { "yara": [], "sha1": "185855351c1ac14c30d3b2bdf5416a011335e58c", "name": "92d5ab5230b0d3bb_sp_unknown.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_unknown.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "92d5ab5230b0d3bbc62e5d87e4c182c296aca9812a4856f83dfc512b6838d3a0", "urls": [], "crc32": "3DD7A90B", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/92d5ab5230b0d3bb_sp_unknown.gif", "ssdeep": null, "size": 97, "sha512": "a240a284be05d662fd16a0239e4d14b3bda5bfad28c6cc065128138b5dffb4f9009cda56f5eaebdb83bb5985bc45255f1ea7693219e10d5b2b2de931e3e12671", "pids": [ 2740 ], "md5": "dbef34749a1fd7fa508a1dfffdc13d2e" }, { "yara": [], "sha1": "c276cd256737c1a40bb73ba5de2807c999edf8b5", "name": "ca912049688490a0_advisorbrand.css", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\advisorbrand.css", "type": "ASCII text, with CRLF line terminators", "sha256": "ca912049688490a06ee95dc126cc0838f5583f6797f674de41ed1c16f518ebcf", "urls": [], "crc32": "06A43EBC", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ca912049688490a0_advisorbrand.css", "ssdeep": null, "size": 52, "sha512": "a5f83e0c232928cd6e8ff339796b67392b79bae82fee480bcd6e1eadbfbc97ac507532c77abb4ba157452d024f11b628b0d980ddf6219c7079cb5ee59ec4ff92", "pids": [ 2740 ], "md5": "01e511983547ab24e450d80853c31e5f" }, { "yara": [], "sha1": "720e5f3b8380b8a5d04e7a99e4f743e44d738314", "name": "d697b0de3cbb1133_belarc-logo-small.png", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\belarc-logo-small.png", "type": "PNG image data, 114 x 54, 8-bit\/color RGBA, non-interlaced", "sha256": "d697b0de3cbb1133a0899a8facab39e787e5b8dfb3227fe62ac8807e3b2d3c96", "urls": [], "crc32": "A704D14B", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d697b0de3cbb1133_belarc-logo-small.png", "ssdeep": null, "size": 1777, "sha512": "5d613babef21e0dcf81c9aee419841e9cb67d505d75840dc6162b566269878a1927c9f176f726c53747e203f7afca542b2f4e67947603f55d4590b9941bc7d09", "pids": [ 2740 ], "md5": "63ca5f180525e8348a56d2adc85781c4" }, { "yara": [], "sha1": "fd448d4a9165bc848a1e6c579010a3ec21b4137e", "name": "7128574752f0a7da_uninstall.exe", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\uninstall.exe", "type": "PE32 executable (GUI) Intel 80386, for MS Windows", "sha256": "7128574752f0a7da1284d589c195aafe25c29f825d7028cebdb21a7ecc44dc00", "urls": [], "crc32": "ACD7A536", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/7128574752f0a7da_uninstall.exe", "ssdeep": null, "size": 164864, "sha512": "310ac39dd9f13d18d87320e1a10167ba206f01819c384dbda341ee8c63d57c6c6cd366f74fa26db94e90904ff5b98388e62905866ee761344f93d532e8f0b2dd", "pids": [ 2740 ], "md5": "2b85fe26ca828485bff6a454b881a295" }, { "yara": [], "sha1": "c9a1026dfc6659ce02c39677cc599bdb61daa721", "name": "d8c9fb8a647762f8_securitypaneltextitems.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypaneltextitems.html", "type": "HTML document, ASCII text, with very long lines, with CRLF line terminators", "sha256": "d8c9fb8a647762f8ce3473cdfa282b74e78240e3cfe934089fae6d4ff8828d67", "urls": [ "http:\/\/www.belarc.com\/cgi-bin\/SecurityAdvisorUpdate?version=" ], "crc32": "7057A418", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d8c9fb8a647762f8_securitypaneltextitems.html", "ssdeep": null, "size": 1825, "sha512": "eab89fbd9c6fbcb9ee1eec4574055fcfcff4eebd4b0e129b5761fce7cfc018794a7942d0fc3456423e298ecb1e82f74bf894348dd95b6d520e7693f81029a8ae", "pids": [ 2740 ], "md5": "37b433dcf2a1e78bc682e85a250178d6" }, { "yara": [], "sha1": "ce24feb23df0099986c9aded8b8e70c328646e70", "name": "6053e9ee6544414f_sp_s2.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s2.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "6053e9ee6544414fc717ed4b70f0220244a0dd3603b7dcae3dc75848f5fce0f3", "urls": [], "crc32": "D64371F1", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/6053e9ee6544414f_sp_s2.gif", "ssdeep": null, "size": 1187, "sha512": "905d8e0976b5d222b23e51709fdc407d47b8fd502a2c186fdeeb36a36916715e65c2f292b148d3cdc31bd1049884947d3766e5a4e7f6f2bd22dee88963034d6c", "pids": [ 2740 ], "md5": "1458db0aa0132f367b0cb92c58637378" }, { "yara": [], "sha1": "cd403f6875d91475c253ba65013e497a62081737", "name": "9823f8eb44898548_summarypageheader.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarypageheader.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "9823f8eb448985484dc49885e11fc69ac8c5892c08745b72ada9d9a8fa83d136", "urls": [ "http:\/\/www.belarc.com\/ba5.html?B" ], "crc32": "2F304AF1", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/9823f8eb44898548_summarypageheader.html", "ssdeep": null, "size": 973, "sha512": "0e46780e23c66958b704a494aede6dad73b45e92d3c1f9f062f0d26c33a448d37a5f3d455fb859f87ffba0ab652a039d504ae1410d64f725f59d60ca0ab7b2a4", "pids": [ 2740 ], "md5": "79033c1c5940538689b5769bcbe044c0" }, { "yara": [], "sha1": "b654dfafb535137fefca03fc979e3ab9c84ea008", "name": "3bbee86c84910d5e_summaryusernamenotes.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryusernamenotes.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "3bbee86c84910d5efc8f3583324edd9657a353450ac1e7cbead6847096ec1f5e", "urls": [], "crc32": "F2E8CCFE", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/3bbee86c84910d5e_summaryusernamenotes.html", "ssdeep": null, "size": 107, "sha512": "9a62c513290fd08588b690b968134f506f5c524b8f191656bc83711b73f53c8749fd03eda46c9a7e9e4bf25a781a17d1f98e69686ed175983ba7c8e4a9d5ebb4", "pids": [ 2740 ], "md5": "a9ced68b1a856cb57e616b9ab41acbbd" }, { "yara": [], "sha1": "b3ad9f69a90c03b79edebb250295f9eadb7eb490", "name": "8f344606d9572f54_sp_s5.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s5.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "8f344606d9572f54f7e5d89655da5a1c1b206efca9c9360f047cfb929f5dfb78", "urls": [], "crc32": "4C97EBA8", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/8f344606d9572f54_sp_s5.gif", "ssdeep": null, "size": 1194, "sha512": "4efdde985151c49b8726828e3215b8b5a4261bfa60e8310f10edfd3493d89798159fd146622b328e8c64cb5d524dea8c732a92b7b148b2f1f102e97a9c13ec72", "pids": [ 2740 ], "md5": "16d000897c503d6c231c8cbf6c11f47a" }, { "yara": [], "sha1": "b9cf0ebf06cd4239b14f2a8cf7cc59ec0e02e021", "name": "fcdc88c9c4384c93_summaryuserentry.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryuserentry.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "fcdc88c9c4384c931030ac4abd49f3346033e02806c829158426fc79250ea5ed", "urls": [], "crc32": "5E731402", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/fcdc88c9c4384c93_summaryuserentry.html", "ssdeep": null, "size": 74, "sha512": "51f0c96587823b0191554982ee399deb302cb02d79c74efecb0b16a61acb89ed52cb2761a4d173191aa9aef3aaefbf5f26ff9309bb6ef329db7918ab4267d622", "pids": [ 2740 ], "md5": "044f3b834cc18e3682d0d1fe018d54eb" }, { "yara": [], "sha1": "048e9ac4d7224682ca0e7649d995b801527c9b2a", "name": "67bee1c01b3ac6c2_sp_s15.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s15.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "67bee1c01b3ac6c2b6e7e27294fc00951b970d0e855ede5dd70eb5ccf66dd66b", "urls": [], "crc32": "474E8B73", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/67bee1c01b3ac6c2_sp_s15.gif", "ssdeep": null, "size": 1191, "sha512": "4f611a55d4d3dc9f97673d5b4477c986f0b6e98ad9022001b8c609781ad53d9c80b5e6d0c60d6985bbfabb247eae32ee5509cc26d7cad80c62965d3041e9ee75", "pids": [ 2740 ], "md5": "1f1c7cac45519f1855a73200c9ca9355" }, { "yara": [], "sha1": "b589b993fb4c3923ed6643c8ce0b2f2212eec4e4", "name": "51dd0a9bfe326cc3_yes.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\yes.gif", "type": "GIF image data, version 89a, 10 x 10", "sha256": "51dd0a9bfe326cc392544251171de4e58eeaaa0da89828732d64dec1e06b4a28", "urls": [], "crc32": "145644C6", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/51dd0a9bfe326cc3_yes.gif", "ssdeep": null, "size": 58, "sha512": "faa7f43ed89ac814ffa30767a9b063b514e64f31af483027cbd28dad8e868fdf6373ed7d7344dfe08ffe0c86af05ccd63cf311192a403bcfdb70953605c55b24", "pids": [ 2740 ], "md5": "79853686b6e0beae68d52bb36488f1f1" }, { "yara": [], "sha1": "124a6ef34de29890a0e59b9ef55f99b10ea12957", "name": "0246c4ca3bdc4bf6_summarygrouppolicyitem.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarygrouppolicyitem.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "0246c4ca3bdc4bf621f1e8f3919882cc2cecadc2c5fbd548e64bef71ae5863a1", "urls": [], "crc32": "B40186FD", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/0246c4ca3bdc4bf6_summarygrouppolicyitem.html", "ssdeep": null, "size": 137, "sha512": "1719e28ab0fe8aa81e7d2e9b11ef30ab23e63a2b9f468504a7a780c80d4fe8e1819ba0d5c70ca919951508dff9a148b253d3138228eeb6d74ddfc1e76bca39c9", "pids": [ 2740 ], "md5": "c23106622d948817e975db68387b5d6e" }, { "yara": [], "sha1": "b1b56d3fd7df0671e736ccafbef7650621c3ae68", "name": "d9a58bc9eb807c5c_cux.bcx", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\security\\cux.bcx", "type": "data", "sha256": "d9a58bc9eb807c5c12fe389c9dd42ade00f66774969df5f90ce925581c28ca5c", "urls": [], "crc32": "69908211", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d9a58bc9eb807c5c_cux.bcx", "ssdeep": null, "size": 4738, "sha512": "84e6e0498bce39166a486b390b34d640c457bff6131af52b5e092ab53a57f88e5a7cc205048dec208e72cd1a063ee2399c92861cb795eaf91e77fa924c87b93e", "pids": [ 2740 ], "md5": "342df05af89710c91e6f2a4f55949966" }, { "yara": [], "sha1": "c82845e58e36b63ed83f1a8fff0ece7895f06f0b", "name": "f9cfe20ababff595_summaryprinteritem.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryprinteritem.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "f9cfe20ababff595d9042277140dc444a50605f2d495e994c87328fee4c1b2b5", "urls": [], "crc32": "56036489", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f9cfe20ababff595_summaryprinteritem.html", "ssdeep": null, "size": 84, "sha512": "d8126e42a3a66270aec6b33958b594aa31406e16d0fb2f9ade557f6143776614d904854d07da9b6a4caab5ddc19a89c06cfb59c071d1a5bcbe793bc882d9dcc6", "pids": [ 2740 ], "md5": "5458494c416ed46fd0565a1dd2d157cb" }, { "yara": [], "sha1": "6b33b9f9a4f6961e93b53bc209719961dca7746e", "name": "adb3069d8514d497_securitypanelcis_unknown.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelcis_unknown.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "adb3069d8514d497fe9c97175c37de70187ae83ac19ec7630ec2e9ba7c5cce16", "urls": [], "crc32": "1F02A952", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/adb3069d8514d497_securitypanelcis_unknown.html", "ssdeep": null, "size": 342, "sha512": "48b3f0bd1d22720481f13335a097af1a66ac9375cc41a2408f06a4f796fae3c4cd3f9e9a71d6bc102a7c7d300aa13a4289a2329d7a52d47f2a701c6da7f02355", "pids": [ 2740 ], "md5": "a2e4519be3c00b1e7c73b3fc247f5dc5" }, { "yara": [], "sha1": "f73298d750363a4df36a50a19ee890d6d223e566", "name": "89b673f93af29a27_summarynetworkdriveitem.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarynetworkdriveitem.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "89b673f93af29a27119a8192502bb4c2c092024a771b17ad66ba52ed39859968", "urls": [], "crc32": "70C43FCE", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/89b673f93af29a27_summarynetworkdriveitem.html", "ssdeep": null, "size": 187, "sha512": "18a0ab247bee00996ddf6a938cd171032c8caa379b0780f350fbe2278fb5f6f124fb0e27b116bb084b49f9b91adb8d18ee2d5ec8196c76d7a05c4ba77f265439", "pids": [ 2740 ], "md5": "8f2a3197390742ef9b04b7e7116e98f5" }, { "yara": [], "sha1": "ff14c6e48e6867d902563870572a3fbb149340c7", "name": "e4e27fc41da08d2e_summarylicenseitem.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylicenseitem.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "e4e27fc41da08d2e43bc2eec56efadcf2e08d0aca4d9015d3a23e986be1a62a7", "urls": [], "crc32": "5970D81B", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e4e27fc41da08d2e_summarylicenseitem.html", "ssdeep": null, "size": 90, "sha512": "9f4509476a583cbdc2258e92a3bced199fb9bef5ca57a47767a093f356fefeb6ca40e8ee4aa8cfa79b085d015a7103ee3e5fa0f0596c5e8d35f371410b445e6e", "pids": [ 2740 ], "md5": "59690b46a3e4844bb78da25967b09bd5" }, { "yara": [], "sha1": "84462cc58a9520d29ec2724380f65c0b104ea46b", "name": "0c9c1cada7c04163_summaryqfemissingempty.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfemissingempty.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "0c9c1cada7c041635a49c39d0dbd085407d575c8723833ed151b1b1bdbffdca6", "urls": [], "crc32": "CACB028C", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/0c9c1cada7c04163_summaryqfemissingempty.html", "ssdeep": null, "size": 297, "sha512": "e20d23483f69fd3fd59c61576374ca213eedfb69e3bf8ffedc069a1995aa516b5b3bf4d9743f13b9eca3f82002a48a9dc7c606909ac7a596b9e743481fb5bc6e", "pids": [ 2740 ], "md5": "2a73f405b734e8d3125fb907c5a82632" }, { "yara": [], "sha1": "65e91d2ac8580927ec57856372402399ec9d98b8", "name": "297d4166c7b76e1c_advisor.css", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\advisor.css", "type": "ASCII text, with CRLF line terminators", "sha256": "297d4166c7b76e1c9e4b6c08d9650de019d545c768ffc26e36f649c1b311c9fd", "urls": [ "https:\/\/fonts.googleapis.com\/css?family=Roboto:500", "https:\/\/fonts.googleapis.com\/css?family=Roboto:700", "https:\/\/fonts.googleapis.com\/css?family=Roboto" ], "crc32": "03BB69FF", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/297d4166c7b76e1c_advisor.css", "ssdeep": null, "size": 12696, "sha512": "9ce26370302559023e157f703e638813338a9f22f936f478c9e5a7eb2329856e59bc11f9173f9764dc58af619948dc657091593211407858ac8f5e8e283cab9e", "pids": [ 2740 ], "md5": "e07295dbc51aa07a0a5ff43d2f91da09" }, { "yara": [], "sha1": "51b9e573e509cb7cc8b4f275572d79898a5d597a", "name": "63ce5d09bae0776d_benchmarkscorewarning.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarkscorewarning.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "63ce5d09bae0776d41caa666150c5ba1c791b4328138bddc4766dbdcaa55a88b", "urls": [ "http:\/\/www.belarc.com\/cgi-bin\/SecurityAdvisorUpdate?version=" ], "crc32": "997DDAB9", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/63ce5d09bae0776d_benchmarkscorewarning.html", "ssdeep": null, "size": 399, "sha512": "140cc27d654db97c0b4cc62153a60ff6878e053976a20d1efca005a8ac9a4e50640835eb34b4dbfb4bd112caf9e5c2b33e67423199bc56d41de949077eee9846", "pids": [ 2740 ], "md5": "fc273f432d9bd605869eee133244457b" }, { "yara": [], "sha1": "775de7cad437fd3f7225fa9efbb1b02f59c25028", "name": "564c221fdad409dd_securitypanelcis_alert.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelcis_alert.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "564c221fdad409ddbcf4619c77959a946b58da4eda00ead4c313df05953996a7", "urls": [], "crc32": "92484A66", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/564c221fdad409dd_securitypanelcis_alert.html", "ssdeep": null, "size": 322, "sha512": "d87524f2074b6eb8fcbba7467523b08db96ba44d03cf694939d114c270ecb2b7563ae3829d8518860af7a37f2361f8a5228d770184d4c8a66a9a5d058b15842f", "pids": [ 2740 ], "md5": "5057512bb34f7947c917aa1cbc6d9dda" }, { "yara": [], "sha1": "7bc6a62341cbe78f1bf6d6517f08f9a3a67bcf3f", "name": "d6f895223c63e9e5_summaryvirtualmachineitem.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryvirtualmachineitem.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "d6f895223c63e9e52cfd5fbbc75f5b0ae0078decd70f89ad84b4b906caacf0c3", "urls": [], "crc32": "076DF11A", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d6f895223c63e9e5_summaryvirtualmachineitem.html", "ssdeep": null, "size": 154, "sha512": "4ba30d9d53a73e994a500290ade977a5fc70d3f1f3119e191f3ca4ea7e5139200922ff8456c78813fd8748d74b50408919f9854a0278fdd8cd140c30a6b631bd", "pids": [ 2740 ], "md5": "a9d65e9b85baa3c42a4d5d6ba00d7311" }, { "yara": [], "sha1": "6d95615e1c9c572f9d6fc1884fc8262635815f12", "name": "0cfa75537347b687_sp_s0.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s0.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "0cfa75537347b6878f57fed73a7548d291d317e82ee9767219e33d3dfce583d8", "urls": [], "crc32": "6B1BB39A", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/0cfa75537347b687_sp_s0.gif", "ssdeep": null, "size": 1146, "sha512": "c8a218530757c5cf880f95955ea30561ac6f6c3698c57994913742022eafd5d8af49aa809946634136af189da8b490d1e58d48038038953edcd6ff3ec4414968", "pids": [ 2740 ], "md5": "abbc9e59b73537b7af1a5804f371fcb0" }, { "yara": [], "sha1": "dcc855a43cbc73d806824941cf75e6c4bf5645f5", "name": "ef7cfd00f31e0bed_bar1.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\bar1.gif", "type": "GIF image data, version 89a, 1 x 5", "sha256": "ef7cfd00f31e0bedf0989e89083331c361394c1b370b2d4f8dbebca451ab0474", "urls": [], "crc32": "1BD19F7A", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ef7cfd00f31e0bed_bar1.gif", "ssdeep": null, "size": 42, "sha512": "739d31ecbd65a70b25257ed6ba83af6cfcb470a5ef610571e362f0aa539b074da59097b04141ddb498aa99bfc7ed39a2d3c2abd8b6db1154e6eb62904267b507", "pids": [ 2740 ], "md5": "45084103841150c88d02ab55bb76f63c" }, { "yara": [], "sha1": "b5acea29f94a351bad838e77fdf29893d2055e29", "name": "d48787ae16db0039_summaryloginsitems.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryloginsitems.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "d48787ae16db003995b52455f743bc6bfa21ad4407790c0167f88635c5e6f758", "urls": [], "crc32": "9B6DA2D6", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d48787ae16db0039_summaryloginsitems.html", "ssdeep": null, "size": 1566, "sha512": "f734cea73ec4756825b7dc191b75f8136cdc70422d7b34c9e255f488b65b6e9714e8e5c7155f09cee5e3c01d4dd6002f6765ae57072a081a7ef21babc1898c6b", "pids": [ 2740 ], "md5": "2d59021641a2358d181c08a407926dfd" }, { "yara": [], "sha1": "60641c600c69d9c15f23b4350f2cda55afa49520", "name": "8a831ef1dcf91927_summary.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summary.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "8a831ef1dcf919279aa1670d2ba51969fa74873ce8f86843e8b3c88a64e22c49", "urls": [ "http:\/\/www.belarc.com\/ctadvisor.html?B-versions", "http:\/\/www.belarc.com\/msproductkeys.html", "http:\/\/www.belarc.com\/ctadvisor.html?B-hotfixes", "http:\/\/www.belarc.com\/ctadvisor.html?B-net", "http:\/\/www.belarc.com\/ctadvisor.html?B-licenses", "http:\/\/www.belarc.com\/ctadvisor.html?B-missing", "http:\/\/www.belarc.com\/ctadvisor.html?B-top" ], "crc32": "B4A22A20", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/8a831ef1dcf91927_summary.html", "ssdeep": null, "size": 10670, "sha512": "052477903873c57a2decc772fdb1b4ca83acfe42e22465659c40a8d190e78da4f3c701bc083844a0534866dce30172008b075c880655bcd6bd46f169b6354cec", "pids": [ 2740 ], "md5": "302ba424f79a5447318884f71abdaab2" }, { "yara": [], "sha1": "7b55247dacd15768000caf3607277f0cde5df081", "name": "764148dc26d30b97_fdcc - windows vista,v1.2.1.0.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarks\\fdcc - windows vista,v1.2.1.0.html", "type": "HTML document, ISO-8859 text, with very long lines, with CRLF line terminators", "sha256": "764148dc26d30b97871b08bffc33232e24a43c4d5f1d1b86dec57501f3c3ec2e", "urls": [ "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5018", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3082", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2525", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2521", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3033", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4869", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4863", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4861", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3076", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4867", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4866", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5089", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3888", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3929", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2359", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2457", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4568", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4569", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4564", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3426", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4215", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3421", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3429", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4597", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4047", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4046", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4040", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4043", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5061", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4048", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5067", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4694", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2854", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3518", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4184", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3696", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2858", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4627", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3452", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3450", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4962", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4963", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3454", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3459", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4969", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3214", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3217", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3216", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4916", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4915", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3199", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4919", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2679", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4139", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3351", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3601", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3996", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2719", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3855", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3853", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5084", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3998", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4988", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3283", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3287", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3285", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3288", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4828", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3072", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3075", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3041", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2557", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4152", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4001", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4150", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3976", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5020", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5023", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2398", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5028", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4793", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4792", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3271", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4797", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4796", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3270", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3553", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2785", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3417", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4704", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3414", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4703", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4317", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4098", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4099", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3875", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4161", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4093", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4382", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3486", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3482", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2953", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2825", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2821", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2820", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3251", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4673", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3252", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3255", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4891", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3259", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4956", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4955", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4898", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4774", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3325", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4763", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3323", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3023", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2697", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3024", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3744", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4872", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4877", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3933", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2519", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4201", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2467", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5181", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4053", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4050", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5114", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4581", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4583", "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/WinVista-FDCC-V1.2.1.0.htm", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3164", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2999", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2998", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4639", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3564", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3115", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4902", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3160", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4904", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3166", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3165", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4907", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3168", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2868", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3378", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2641", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3361", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3360", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3364", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3367", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4643", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3201", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3207", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3204", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3706", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3338", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4594", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4833", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2746", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4110", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3015", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3963", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3380", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3385", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4016", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4017", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4013", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4011", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3945", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3941", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4018", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5016", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2380", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4122", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2339", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4781", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4264", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4267", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4300", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3400", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3403", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4062", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4066", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4068", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5163", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5008", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3891", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2724", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4166", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4175", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2838", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4162", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4163", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4160", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4174", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3246", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3244", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4948", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3240", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4761", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3125", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4947", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4940", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4941", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3248", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3120", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3233", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3232", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3230", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3623", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3584", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3239", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4285", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4629", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4119", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4118", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2755", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2754", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3330", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3331", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3336", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3337", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4115", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3054", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3050", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3751", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3754", "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/WinVista-FDCC-Firewall-V1.2.1.0.htm", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4845", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4841", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2471", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2477", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3909", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4213", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3457", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4507", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3905", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4501", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3456", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5128", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4342", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4026", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4020", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3469", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5047", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5048", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2376", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2977", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2975", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3576", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3570", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4488", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4722", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4334", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3173", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3177", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3212", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4938", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2650", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2715", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2714", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3376", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4153", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3373", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3279", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3278", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4651", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4652", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3272", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4656", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3379", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3303", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3302", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3307", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2781", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4991", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3093", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3902", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2533", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3993", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3001", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3398", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3906", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3394", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3395", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3953", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3954", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5007", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5004", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5000", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3894", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2322", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2323", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4479", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3432", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3436", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3439", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4372", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4278", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5172", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4071", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5170", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5177", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4077", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4078", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4079", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4158", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4687", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4192", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4196", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4194", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2924", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4970", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4616", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4200", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3138", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4206", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4612", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4976", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4757", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4618", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3220", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3590", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3225", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3181", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2778", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5011", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4132", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3619", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4109", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3349", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3348", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4101", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4104", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3341", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4107", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3045", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3046", "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/IE7-FDCC-V1.2.1.0.htm", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4998", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3299", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4854", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4992", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3297", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4996", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3292", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4922", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4827", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4149", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4535", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3914", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4925", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4405", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3969", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4038", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4034", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5132", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5131", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5036", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5034", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2363", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5038", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4202", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4973", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4207", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3500", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3468", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2967", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2962", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3460", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4714", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3464", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4089", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4088", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4083", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4084", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4086", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3143", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3142", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2883", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4147", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4143", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4889", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4921", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3260", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3261", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3263", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3866", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3311", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3314", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3316", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4813" ], "crc32": "E7EE0EAC", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/764148dc26d30b97_fdcc - windows vista,v1.2.1.0.html", "ssdeep": null, "size": 233322, "sha512": "5616dd3e4fb3920f0f5c8ce25a30bc74ab5eb91673111d88df50700d153fd88de3aca107a1aa6a9fae2b4c545ef6d40dd9da62d899f3fb190b961a4ac37f6ddd", "pids": [ 2740 ], "md5": "b653e79754eae5dba2f0b9eec447de7a" }, { "yara": [ { "meta": { "description": "Contains an embedded Mach-O file", "author": "nex" }, "name": "embedded_macho", "offsets": { "magic1": [ [ 889012, 0 ] ] }, "strings": [ "yv66vg==" ] }, { "meta": { "description": "Possibly employs anti-virtualization techniques", "author": "nex" }, "name": "vmdetect", "offsets": { "vmware24": [ [ 1851766, 0 ], [ 1860628, 0 ], [ 1875480, 1 ], [ 1888301, 0 ], [ 1903628, 0 ], [ 1903644, 0 ], [ 1903660, 0 ], [ 1903676, 0 ], [ 1903692, 0 ], [ 1903708, 0 ], [ 1903724, 0 ], [ 1903740, 0 ], [ 1903756, 0 ], [ 1903772, 0 ], [ 1903788, 0 ], [ 1903804, 0 ], [ 1903820, 0 ], [ 1903836, 0 ], [ 1903852, 0 ], [ 1903868, 0 ], [ 1952650, 1 ], [ 1952664, 0 ], [ 1952818, 0 ], [ 1952862, 0 ], [ 1960096, 1 ], [ 1960108, 1 ], [ 1960316, 0 ] ] }, "strings": [ "Vk13YXJl", "dm13YXJl" ] } ], "sha1": "61e6ed9b208bdd8543e554abb9efef88a74802b1", "name": "6c4d70243ae78f4d_npbelv32.dll", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\npbelv32.dll", "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows", "sha256": "6c4d70243ae78f4d2707cda714f79397ebcb6ca04e515a03f8dc63bedb76f84e", "urls": [ "http:\/\/www.usertrust.com1", "http:\/\/ocsp.comodoca.com0", "http:\/\/crl.usertrust.com\/UTN-USERFirst-Object.crl05", "http:\/\/crl.comodoca.com\/COMODORSACertificationAuthority.crl0q", "http:\/\/crl.comodoca.com\/COMODORSACodeSigningCA.crl0t", "https:\/\/secure.comodo.net\/CPS0C", "http:\/\/www.belarc.com\/BelNotify\/Master.bcf", "http:\/\/ocsp.usertrust.com0", "http:\/\/www.belarc.com\/cgi-bin\/baerror?%s", "http:\/\/crt.comodoca.com\/COMODORSACodeSigningCA.crt0", "http:\/\/www.belarc.com\/cgi-bin\/dellrefer?%s", "http:\/\/crt.comodoca.com\/COMODORSAAddTrustCA.crt0" ], "crc32": "75F836A2", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/6c4d70243ae78f4d_npbelv32.dll", "ssdeep": null, "size": 2625544, "sha512": "ee6a4bdd39deb73e57a0f1bd64acff211d94518848f71685164dc63d20d70521b573096dab347c5b41de504e669d4374a919c42d89680451c8d224130db0924b", "pids": [ 2740 ], "md5": "d2dbe09125727bc00051ccb3ff69d9ba" }, { "yara": [], "sha1": "19604a259d224c6dd39106b78b8aa2ddcc402a50", "name": "f99f3cf558d94ad3_sp_s12.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s12.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "f99f3cf558d94ad32d0bbd3594104f34f59291bebe6ef2ed6fda9761b70441fe", "urls": [], "crc32": "901E0B68", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f99f3cf558d94ad3_sp_s12.gif", "ssdeep": null, "size": 1184, "sha512": "937cd7a9c00e4a53b9c5f06850bd92f77bae5ac9d78beea4835213cfd9de84d783dea9c194955b68676a51f6728e43c261b469835ecf92a0df785622f1e532d4", "pids": [ 2740 ], "md5": "c266d7d0586dde2d1bec595f41b729a5" }, { "yara": [], "sha1": "38eff05f2887bdc91b4bc90c4ec1d114dac04477", "name": "3b09702902dcbffe_summaryqfemissing.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfemissing.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "3b09702902dcbffe93b5b243b477596e262e7d7f05c8ec17a8692e70afe92443", "urls": [], "crc32": "9E93E378", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/3b09702902dcbffe_summaryqfemissing.html", "ssdeep": null, "size": 697, "sha512": "85cd8e2361754608ae52f0b0863ade7440af75520541d6641956200c456edb818146657872a94b952bc4d72fed6e0f800e84a458667075a4fcd022810266a182", "pids": [ 2740 ], "md5": "1abe5f514054896d4d220ed26fb13f44" }, { "yara": [], "sha1": "76049db00744cc2b0be068b22621615644b55a13", "name": "bdaf1446ad030e88_benchmarks.cax", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\security\\benchmarks.cax", "type": "data", "sha256": "bdaf1446ad030e88014af648f53333c07c862401cd5644625b556e7b5d25a557", "urls": [], "crc32": "2C1CEAD1", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/bdaf1446ad030e88_benchmarks.cax", "ssdeep": null, "size": 30627, "sha512": "e880ce4a79649754e463b7231ffaf87b909a4b6f3b11422963e5cf0a4236b670f984c9efa197c3056cec6ec5ec8356b0d08acbe2c7fdd29d0aaed4fbe0fe49ed", "pids": [ 2740 ], "md5": "1e79b03365a1f664effbf2e5422a78ef" }, { "yara": [], "sha1": "922e4b209084ac95a48d35b38305dc904ce6da7e", "name": "c7e923e8acf0d788_summaryqfefootnotes.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfefootnotes.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "c7e923e8acf0d788edbb7c5959a153689a290981cb5c10491c0fbfadcf2e38b8", "urls": [], "crc32": "EA32090B", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/c7e923e8acf0d788_summaryqfefootnotes.html", "ssdeep": null, "size": 581, "sha512": "ee4688e4566faf8f00ebb0f525dc9d3acf41c7f392d11ae2ee4f691fca9c91142059221e6ad1674dffee1f2abeac0c0f5fa4a5f8d324bf676f770d3b24fe9547", "pids": [ 2740 ], "md5": "a28d3794d9278a9eb3d215cb1cfd18d8" }, { "yara": [], "sha1": "2329f1cd91a11b755633884b62eb6785a032d8eb", "name": "1db60562d8704a50_summaryqfeempty.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfeempty.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "1db60562d8704a507ad3d169aa0482d2a14ebb6dbd30081616be1f4f3cb84efd", "urls": [], "crc32": "B537D52A", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/1db60562d8704a50_summaryqfeempty.html", "ssdeep": null, "size": 109, "sha512": "f0358e1c7961e6584cbdbfabaebba149bb6c9d41067a0ef09460d2e5a1d2e00319d29beed11ecd263d5dc8c83db618d2580b3fa91ecb214cbc5b95f0af1ce248", "pids": [ 2740 ], "md5": "788d02bb6e2737c3a3163a877e32cc70" }, { "yara": [], "sha1": "7b9e39df4c9328349e880704975eff66f2d99126", "name": "3094f46c4ad9449a_sp_s1.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s1.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "3094f46c4ad9449a67283e69145974b510a009d0b303a4a070ff074ad99d6c3f", "urls": [], "crc32": "7E7D757F", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/3094f46c4ad9449a_sp_s1.gif", "ssdeep": null, "size": 1171, "sha512": "616b1fe22184e1601427ba8ad3d8b55dcd0079c84164cd434eb4f543b0021be4f51d6c7562e08868500a43474ca64501fe0ad9fdf5a4a643039184238f0173b5", "pids": [ 2740 ], "md5": "98ecc0041d56d628337afbe9223b8146" }, { "yara": [], "sha1": "33a2d0a99115eefd1c63e19f130dc4560e07b524", "name": "cf84452e352ef976_summaryvirtualmachines.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryvirtualmachines.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "cf84452e352ef976b8ba052c30f5bffdbe2c839b0b7daf853cebb6f12d66fc35", "urls": [], "crc32": "CB67C562", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/cf84452e352ef976_summaryvirtualmachines.html", "ssdeep": null, "size": 288, "sha512": "d15e9c1c3e8034121083e7f12067fb81f4e016eb0a67da1ee0f52965418cbf6e7433a5ab278ccc0e326b4452810de9628fabc980bdd06a10f06f8f8e1367c3b6", "pids": [ 2740 ], "md5": "0e7df45173c11a35be4c5ab7e2eb09fd" }, { "yara": [], "sha1": "ff58693ad665566ba06ddf355fe7dd31e7d00429", "name": "aacd4d8756618d25_summaryqfeexternal.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfeexternal.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "aacd4d8756618d25a3adf43b54786396401ff25466d0fb458df4a75d5429a397", "urls": [ "http:\/\/www.belarc.com\/ctadvisor.html?B-hotfixes" ], "crc32": "E8BD1917", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/aacd4d8756618d25_summaryqfeexternal.html", "ssdeep": null, "size": 1998, "sha512": "fb6319e75a681a57ed579175b8150c8005aa83043f6f04b20535fbf31f62eac26bbff257ce4a8b85b63453a5f4df651e4181babb4de866eac4722d63c1487b25", "pids": [ 2740 ], "md5": "127aa876a8d50a0884672217bb4b76e8" }, { "yara": [], "sha1": "dd230da2e31589ae6b8a079f995e206f3230e742", "name": "a12c0b3645750255_summaryprinters.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryprinters.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "a12c0b3645750255458f991a3d5bf6c7e3d771f1e7b541ecb8915d28714c7e0f", "urls": [], "crc32": "ADD23AD5", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/a12c0b3645750255_summaryprinters.html", "ssdeep": null, "size": 95, "sha512": "c97304c12380ef310bc2c4673bdbcd733216445bb9a970b6c101f054ca30b2cf4bb5d39c2b4b538bb5181cc4fd77e251a1f73c67d0a9caa73b5a9354a331f3db", "pids": [ 2740 ], "md5": "eeb2f06dbaff750ddf3205588a4da9ab" }, { "yara": [], "sha1": "2aba6e50f74eb9016991a2a8413a74f9a7f6b1f7", "name": "a5003419390bcfe8_summarylanitem.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylanitem.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "a5003419390bcfe814aa4be870a8e2ba8ea3dd45955ce3e8d0ecb591a9dd30d2", "urls": [], "crc32": "91B79F86", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/a5003419390bcfe8_summarylanitem.html", "ssdeep": null, "size": 192, "sha512": "c6b417ae56d1e4db4618f75b0b31bfe2c0ccf36d3744dbf5bcc28e53549a7fdd57ed49c8964bbd56e23c2fc93ca5335805a1c65d81e532be87b1a73013829e01", "pids": [ 2740 ], "md5": "b3f58d240f044794edde275ec3c7022e" }, { "yara": [], "sha1": "5101cb278dae86183e024db02af72b68802845ca", "name": "7863796bde8134f7_usgcb - windows 7,v2.0.5.1.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarks\\usgcb - windows 7,v2.0.5.1.html", "type": "HTML document, ISO-8859 text, with very long lines, with CRLF line terminators", "sha256": "7863796bde8134f7b799e5432fbb1fef798491333b07a33196d56df15cffa538", "urls": [ "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10403", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10011", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9620", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9301", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9657", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9304", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9307", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9309", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9308", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10083", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9960", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10539", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9496", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9712", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9498", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10535", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8974", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8973", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9406", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9407", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9156", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10277", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9150", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9403", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9400", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9014", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9396", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9395", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10405", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8870", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9274", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8484", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8487", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10623", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10622", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8414", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10620", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10625", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9829", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9945", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9821", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9823", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10744", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10059", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10052", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10055", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10699", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10696", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8460", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10692", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10759", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9753", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9750", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10574", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10472", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9616", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10470", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10578", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10475", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9358", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10275", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10276", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10178", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9357", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9686", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10882", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9683", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8937", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8936", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10373", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8804", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8807", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8806", "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/IE8-USGCB-V1.0.1.0.htm", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9534", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9532", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9531", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9124", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9121", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9432", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8560", "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/Win7-USGCB-V1.0.1.0.htm", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9439", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8513", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9982", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9985", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9864", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9865", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9866", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9863", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9868", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?11252", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9222", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9223", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9226", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9509", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9542", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9540", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8740", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10714", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9918", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9919", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10650", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10651", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8423", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10654", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10655", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9910", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8583", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9914", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9917", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8562", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10486", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9123", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10438", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10434", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10433", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10431", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10002", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8732", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10265", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9317", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9643", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10137", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10293", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10138", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9319", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9669", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10235", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10566", "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/Win7-USGCB-Firewall-V1.0.1.0.htm", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9487", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10509", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9768", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10502", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10500", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9764", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9763", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9760", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10342", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10344", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10347", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9007", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9667", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9361", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10200", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9266", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9265", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9260", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9506", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9503", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9501", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9461", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9464", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9465", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8999", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9189", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10611", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9185", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9819", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9953", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9736", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9814", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9817", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9959", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8789", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9212", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9217", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9215", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9704", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9707", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10763", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10764", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10769", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10685", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8475", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9336", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9330", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10543", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10466", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10461", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9603", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10266", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9329", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9737", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9327", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9326", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10140", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10268", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9048", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9320", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10824", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10828", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10386", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10387", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10380", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10389", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9229", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10319", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8958", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9136", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10311", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9135", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9426", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9786", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9781", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9783", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9858", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8503", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9850", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9857", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8818", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8813", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8811", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8817", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9559", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9254", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9253", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9251", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10725", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10649", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10645", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10646", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10641", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10642", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8431", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9925", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9926", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9289", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10581", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10586", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10420", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10425", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10033", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10037", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9674", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9670", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9673", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9672", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9440", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10522", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10515", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9779", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9774", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10107", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9776", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10105", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9770", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10103", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9773", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10219", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10359", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10215", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9370", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9375", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10811", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8856", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9588", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8912", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9792", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9295", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9793", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9107", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9458", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10547", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9456", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9199", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10603", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10602", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10604", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10607", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10606", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10609", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10608", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9193", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9195", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9967", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9801", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10110", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10074", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?14986", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10778", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10676", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10672", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10782", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10787", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10553", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10554", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?14854", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8612", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10154", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10157", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10156", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10150", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10094", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10095", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10096", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10090", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9021", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9739", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10850", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10856", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10394", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10393", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9040", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10525", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10527", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10250", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9419", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9418", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8945", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9149", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9417", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9389", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9388", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9790", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9026", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9387", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9386", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9098", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9096", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9842", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9898", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10130", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9244", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9249", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9562", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10638", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10730", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10630", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10635", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9832", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9938", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8467", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10182", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10183", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10181", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10021", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10022", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8654", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8655", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8714", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8825", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10664", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10595", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10594", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10597", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10591", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10590", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10561", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9742", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9747", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9749", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9663", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9660", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8591", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10441", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10205", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9068", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9069", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10165", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9067", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10160", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9345", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9344", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9694", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9692", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9342", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9348", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10360", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9593", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9528", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9520", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9522", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9888", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9882", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9449", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9885", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9976", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9973", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9876", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9875", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9874", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9870", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9879", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9878", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9239", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9191", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?8884", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10061", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10709", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9908", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10661", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9901", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9907", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?9905", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10795", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?10496" ], "crc32": "7C23BEFF", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/7863796bde8134f7_usgcb - windows 7,v2.0.5.1.html", "ssdeep": null, "size": 237067, "sha512": "91aa891771297857b4ebfc059548b42685eedf25a3ec0f8b7676034456342cd6bc0ea28a80da1639837873269305736338f61ce74a2cdc4ce49a1f9910a6d297", "pids": [ 2740 ], "md5": "c588e0afef29185c57fb3c0a1aa5fe40" }, { "yara": [], "sha1": "f12464a0fd32f14e30fb5af3d10571a94faccad4", "name": "ce27e9975ca4a86e_shfs3.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\shfs3.gif", "type": "GIF image data, version 89a, 13 x 10", "sha256": "ce27e9975ca4a86e29330bf40c11493a90b17a6f976599e23b7e905282601b3a", "urls": [], "crc32": "CCA14F0B", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ce27e9975ca4a86e_shfs3.gif", "ssdeep": null, "size": 68, "sha512": "51e6348a2ede2be4879a578af2b34b4598f765df8d79221777ba454486d8874b335676cd42858682045013e2a3a8c3ab1f1dd78392720d7f4134d585babd2c56", "pids": [ 2740 ], "md5": "4dd78e7118f10ce9131759a4231f65c6" }, { "yara": [], "sha1": "da39a3ee5e6b4b0d3255bfef95601890afd80709", "name": "e3b0c44298fc1c14_GLB63F0.tmp", "type": "empty", "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855", "urls": [], "crc32": "00000000", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e3b0c44298fc1c14_GLB63F0.tmp", "ssdeep": null, "size": 0, "sha512": "cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e", "md5": "d41d8cd98f00b204e9800998ecf8427e" }, { "yara": [], "sha1": "0cdedfcb1f0b1b6f29276b8d7edbea2843c53064", "name": "e97459d6a5f9b968_summarynetworkdrives.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarynetworkdrives.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "e97459d6a5f9b968a7f157d3115abf5e988dfb026a8eced4a0fc18ebd08ea2ff", "urls": [], "crc32": "A07128B2", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e97459d6a5f9b968_summarynetworkdrives.html", "ssdeep": null, "size": 251, "sha512": "a260e61c8e120d384a8cc06c07d5d5d4b8a7d4ae3e16c3fae100565ad60dfca7e3088c85c4c4e79af353adfb873f524fa4779fa0c8009c6a77b1a554605d25c4", "pids": [ 2740 ], "md5": "e9d10fe5ed34071e60ba60be851a6ea5" }, { "yara": [], "sha1": "ffce22d4447e0c40793b2bcdb808571cc5051011", "name": "049cfd0bc645c517_securitypanelcis_ok.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelcis_ok.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "049cfd0bc645c5172cd5326ed6df5bff2194dca543c34914e6a9943c9c9521d9", "urls": [], "crc32": "11ECD742", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/049cfd0bc645c517_securitypanelcis_ok.html", "ssdeep": null, "size": 569, "sha512": "46ea60a6c75542718883edbf45fcc4ef7c74d1afd632bf9927836cad9324f6a4ee2d3b74d956dcf0f5328966ae9c914052781f54ae91c0d15839aec81eecb2af", "pids": [ 2740 ], "md5": "1e72a2eeb0ebaed4633f79da948abd3e" }, { "yara": [], "sha1": "3955fa0d27094e16624c791e5faf6cb5e5283172", "name": "467390e9116ac881_corner_tl.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\corner_tl.gif", "type": "GIF image data, version 89a, 16 x 16", "sha256": "467390e9116ac8811f2d39f6cf6b1f23a1f2cc4e3da2dd384ab552b517f82057", "urls": [], "crc32": "7D123EC8", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/467390e9116ac881_corner_tl.gif", "ssdeep": null, "size": 71, "sha512": "156b99915f5148f036b116804ba81b33c1a3acc19244085f59828fdc22f87aadf42f4d2908d0b2b8736d82413fb5f48d0b3f2097bad329b6e7e5bf472fbeb542", "pids": [ 2740 ], "md5": "5e6fdb130dff77279ae6815e8e9ecdd3" }, { "yara": [], "sha1": "0e7b303a729cbbe77f3bc6d0ddf2c674637fab0e", "name": "3213501caffe4cb5_hotfixdefs.cax", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\security\\hotfixdefs.cax", "type": "data", "sha256": "3213501caffe4cb5d34aeaf19f80865b307e10bd687027ffc5165fbcdcaa58eb", "urls": [], "crc32": "3BA5A3EF", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/3213501caffe4cb5_hotfixdefs.cax", "ssdeep": null, "size": 1624315, "sha512": "b7e440f67c8c745a694a2791c5b2d1a060609b9bb2121f8e58e691cea9f78cf3a8889f3480bde832ddbe12bc97f264f68e117022fb26911cc428e20c890e0195", "pids": [ 2740 ], "md5": "9d13bbd02ca3356110e78d36929fd54b" }, { "yara": [], "sha1": "f620eacfe3429b4ac848e88216d5e08947e0722c", "name": "098a0093519a12a8_bar2.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\bar2.gif", "type": "GIF image data, version 89a, 1 x 5", "sha256": "098a0093519a12a8f2fe1b76c5d6502a9f48fae8acd49567bbdb47acb47adc72", "urls": [], "crc32": "31EA3A62", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/098a0093519a12a8_bar2.gif", "ssdeep": null, "size": 42, "sha512": "a546ea1f8a2fa95597b9caad5d7e9aca4b9cc91775e916122025f2d0b0cbb924865b7abe278fc145e8d4f564daf148dd6d2f2b1e5d61942e572279b6f784e2e1", "pids": [ 2740 ], "md5": "207067dd6124bdaea177c297bc957ed4" }, { "yara": [], "sha1": "686ff8e30b82ffca4f991b71bf0fcce1000bf546", "name": "8df4016e049186b3_summaryqferecentempty.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqferecentempty.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "8df4016e049186b3d143323859af93e98ec5c203f4f7c1a4c71c543df9aec096", "urls": [], "crc32": "B0AAD27C", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/8df4016e049186b3_summaryqferecentempty.html", "ssdeep": null, "size": 128, "sha512": "a52799a1cd441e476460893ae81d93f5a85dac0ac3a4738d1fd529959a1154cf981d9acf0223d2707f20d1955d09ea9c88b0de42fac45a54f5ed0713aef5e98f", "pids": [ 2740 ], "md5": "bdfba144c276f0ff0ed5afccbed94606" }, { "yara": [], "sha1": "78754ab513dbe6f9d0aaacc81868f014dca30271", "name": "dd8010f75fb363f9_shfs1.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\shfs1.gif", "type": "GIF image data, version 89a, 13 x 10", "sha256": "dd8010f75fb363f9363c2ca5245d4b20d54ca1619bb7aac22f8f1a3234a6360a", "urls": [], "crc32": "64D56731", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/dd8010f75fb363f9_shfs1.gif", "ssdeep": null, "size": 65, "sha512": "d77c99f154c88554cac531340804bfeb8cb6ca3a81becb55e54d0af896bcf9e8ec4d3b550893af66c3430336f91d68ac33b2ef8ff7d4e8633d6b47c6f0735b25", "pids": [ 2740 ], "md5": "15ed20954fa67d8d5f7e6ee4d4045795" }, { "yara": [], "sha1": "71d4180327373c4898726a1bfa83ae86f8737641", "name": "098306ec0d3d991e_summarylocaldriveitemlinux.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylocaldriveitemlinux.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "098306ec0d3d991e9c29908187293c38418dbe91268cc175bae187042d341b86", "urls": [], "crc32": "CD466710", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/098306ec0d3d991e_summarylocaldriveitemlinux.html", "ssdeep": null, "size": 228, "sha512": "b573a5b098e108ec16e5474f739a02b5b582fc6a869d7000c6241fef1872e64163e4d8d1c161327f75556c6bc913cf53d59ac7b1733976f1d79eb43d4a8ba059", "pids": [ 2740 ], "md5": "b1bef50ac4a7291d62f842cedecbd142" }, { "yara": [ { "meta": { "description": "(no description)" }, "name": "LnkHeader", "offsets": { "guid": [ [ 4, 0 ] ], "signature": [ [ 0, 1 ] ] }, "strings": [ "ARQCAAAAAADAAAAAAAAARg==", "TAAAAA==" ] } ], "sha1": "4ed4b4ab15e42381f562d095f550662803dc1f33", "name": "2a2ae1e30de432c0_belarc advisor.lnk", "filepath": "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk", "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Sat Nov 23 19:53:15 2019, mtime=Sat Nov 23 19:53:15 2019, atime=Sat Jan 26 02:04:36 2019, length=134824, window=hide", "sha256": "2a2ae1e30de432c00167fad9313803ff66db4592d523d8349ff50869d4b8dee4", "urls": [], "crc32": "82296D0C", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/2a2ae1e30de432c0_belarc advisor.lnk", "ssdeep": null, "size": 2120, "sha512": "3599d1867c13ccaa950b2bdd824400cbface6b9dd8eefcf9ca3ae2e0ca9fdf35476bea64aa1774ba93597f8a05ba0e162d0e60ed15a0eeec1456c9a08abec5a7", "pids": [ 2740 ], "md5": "6d6513d2c2213147752ec69b63429152" }, { "yara": [], "sha1": "597aa7508e98d33b1b6d50d723adb2bd331ac22c", "name": "03c50e238bd50683_securitypanelav_alert.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelav_alert.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "03c50e238bd5068366375a065f1802721df6f7584cd994c680741c23f806a554", "urls": [], "crc32": "F27B3BAB", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/03c50e238bd50683_securitypanelav_alert.html", "ssdeep": null, "size": 405, "sha512": "d03e2f464e008b0833e67a9a72c5d51649e48e52e8bb72fe56c2813ca85b47f84c904a6447568cb2e4b15367a2bdf0e0e892fc8c5efbc96132a4d85ef2d58ac1", "pids": [ 2740 ], "md5": "edb9507c8e42b8dc0a145f55ebb4525b" }, { "yara": [], "sha1": "7231268c5c15823b7b8dc3e8183201f47eeb12c4", "name": "5b73822f2281e665_sp_s10.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s10.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "5b73822f2281e6654911cc2d801e4c9decfb3f7c6deef3d2150e486fddc9732b", "urls": [], "crc32": "CEEDF483", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/5b73822f2281e665_sp_s10.gif", "ssdeep": null, "size": 1197, "sha512": "81096d032d498e6774dfc93d6e5787462e80c779148e1fa2c6d15372d65a5012a324f3499fd76001ca7b50635b1ed5baabce8b3b6bc9642e400e82f6bd71cbb8", "pids": [ 2740 ], "md5": "36f62ab24c67539041e5e537cb762590" }, { "yara": [], "sha1": "2daeaa8b5f19f0bc209d976c02bd6acb51b00b0a", "name": "b1442e85b03bdcaf_trans.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\trans.gif", "type": "GIF image data, version 89a, 1 x 1", "sha256": "b1442e85b03bdcaf66dc58c7abb98745dd2687d86350be9a298a1d9382ac849b", "urls": [], "crc32": "9ACCEAB1", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/b1442e85b03bdcaf_trans.gif", "ssdeep": null, "size": 43, "sha512": "717ea0ff7f3f624c268eccb244e24ec1305ab21557abb3d6f1a7e183ff68a2d28f13d1d2af926c9ef6d1fb16dd8cbe34cd98cacf79091dddc7874dcee21ecfdc", "pids": [ 2740 ], "md5": "325472601571f31e1bf00674c368d335" }, { "yara": [], "sha1": "92035556c43da7f4428c824f7602063a722ededf", "name": "319ddac0f4933181_summarygrouppolicy.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarygrouppolicy.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "319ddac0f49331815ea38cb95a78c76d2c6e2eb1e54e49a5b105a8a9051063c1", "urls": [], "crc32": "78649D4E", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/319ddac0f4933181_summarygrouppolicy.html", "ssdeep": null, "size": 382, "sha512": "04213771d22a74df70d75315f176b2fa9b1806a19ccab193b003bf382a2cbe6858343daf328d7046926e3a177dc3945815b7c489bd5ab2b772c5e04480e99fda", "pids": [ 2740 ], "md5": "489442fb0cac204ca954386d6f211ac6" }, { "yara": [], "sha1": "0419cb772116d54accd4d27f428ceb13da2d5142", "name": "f10019cf9c392c09_~GLH0005.TMP", "filepath": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP", "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows", "sha256": "f10019cf9c392c093f4d65e82da323285c1ca14aef6ea80054ab93af65a5d661", "urls": [ "http:\/\/www.usertrust.com1", "http:\/\/ocsp.comodoca.com0", "http:\/\/crl.usertrust.com\/UTN-USERFirst-Object.crl05", "http:\/\/crl.comodoca.com\/COMODORSACertificationAuthority.crl0q", "http:\/\/crl.comodoca.com\/COMODORSACodeSigningCA.crl0t", "https:\/\/secure.comodo.net\/CPS0C", "http:\/\/ocsp.usertrust.com0", "http:\/\/crt.comodoca.com\/COMODORSACodeSigningCA.crt0", "http:\/\/crt.comodoca.com\/COMODORSAAddTrustCA.crt0" ], "crc32": "E0884AEE", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f10019cf9c392c09_~GLH0005.TMP", "ssdeep": null, "size": 129720, "sha512": "7a4862ac704072336e188882f7d139f01095e27c71a9229ccf7ced0668d768767d5979d152ec12076634411abe80b1d1292c7485389de39d079581fc557ea126", "pids": [ 2740 ], "md5": "4d11999a3fd88be4728727606a233950" }, { "yara": [], "sha1": "3a36aef3671bc1fcd812c121522680ed6d689e94", "name": "b8347d509eafa5a6_sp_s7.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s7.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "b8347d509eafa5a627e90510d3ddcf2bbd1b33294d2017d39ea7ae3f34cf3fdf", "urls": [], "crc32": "F86010D2", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/b8347d509eafa5a6_sp_s7.gif", "ssdeep": null, "size": 1195, "sha512": "31e7b0b2f1b6b91e419db304924e30a5bbcbf50037ac1b9d97755701fe364e655752dccbc97534265ebf0dbaccd4e5635af8609c8db5c37cabdf1eb519d0cb48", "pids": [ 2740 ], "md5": "a6c4055a9bf36f69055f49c12325de38" }, { "yara": [], "sha1": "02ca3280439853b4c5f871f17d2863d9b41b69a9", "name": "f3dbd3415d10df60_securitypanelav_unknown.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanelav_unknown.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "f3dbd3415d10df60e78a7128f8d2a935642fa9da9503875af8718d5a549a46fd", "urls": [], "crc32": "5333768C", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f3dbd3415d10df60_securitypanelav_unknown.html", "ssdeep": null, "size": 373, "sha512": "d53f71d171c77d6dc310264473e5f4b7d60f8686c3dae4b6a2a07b8d2883870bc48e163f3fec648ac5e1c9b8c04025f73308ff059f75ca63363d66941c11a6d6", "pids": [ 2740 ], "md5": "f4814f41b14ed480a7c5c91cba4fb7c9" }, { "yara": [], "sha1": "bd2c2c82175e24c73735144de4be3d312dec2f47", "name": "0e4e080bfead99c6_summarylicenses.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylicenses.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "0e4e080bfead99c6f54eb065b695d0b0e9aa20dc8f30b59c7dc447c9547ece3f", "urls": [], "crc32": "5EF02942", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/0e4e080bfead99c6_summarylicenses.html", "ssdeep": null, "size": 178, "sha512": "aa45c6aaa49346b29d1a58461eea26a4414fe0f583dc9564b07247580db23f997706fbe31fbb6f3e31110dfda8f106e81e47e4f5f63758ec59e7765400e488d9", "pids": [ 2740 ], "md5": "02b4908c863167a7a0585caec236d6af" }, { "yara": [], "sha1": "d2223598861d59e06b053723207c806f96671bf4", "name": "7997c13bb6f36f5f_summarylicenseformats.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylicenseformats.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "7997c13bb6f36f5f03e1ffe0af7133958d0e0a71e2a45d30060ea7e516819254", "urls": [], "crc32": "29C344D1", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/7997c13bb6f36f5f_summarylicenseformats.html", "ssdeep": null, "size": 256, "sha512": "4390411fc86f0121c7135f442041ffc33892fe42279c84f98feadf0329ec0111b5a285618e1342e3aae84fd47cae29aa1d5e630c1afacc474e43597619b3bac7", "pids": [ 2740 ], "md5": "15bf16411783351c833a138afac93eb1" }, { "yara": [], "sha1": "4e4095ea14e1a29728f909164c25b9e1aa96b57a", "name": "864e419cc10c3198_summaryoupath.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryoupath.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "864e419cc10c3198851fc5afb914830e609420646d5e69ceb9381b73d850700a", "urls": [], "crc32": "ACA3EEA8", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/864e419cc10c3198_summaryoupath.html", "ssdeep": null, "size": 97, "sha512": "df7b8786b9e4a737b446053c8515606947644db40540438ee8baa8b3255932cc6971468c0583a2b80651222797668fc902ba4451c95f0cdc29cb2b460cf4f41f", "pids": [ 2740 ], "md5": "dd9aed1fc65764dfe1a7e0fc5f8a50ca" }, { "yara": [], "sha1": "43a33ae14d760042f9429ca2eb97dff02aed0de3", "name": "049cb66277802812_GLG63F1.tmp", "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp", "type": "diff output, ASCII text, with CRLF line terminators", "sha256": "049cb662778028121282078130a4a1efe2a1b19cc88613062114cba69f2093e1", "urls": [ "http:\/\/www.belarc.com", "http:\/\/www.belarc.com\/download.html" ], "crc32": "6512FF82", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/049cb66277802812_GLG63F1.tmp", "ssdeep": null, "size": 22542, "sha512": "d0b7321d5efeac6226028cc6882194fa089f31234813b12f9d0eb88cbbb6391f5edd9d40cefbd4d187735784d35b5427bf405ca14be7da4ece8120550cf1ecbf", "pids": [ 2740 ], "md5": "915e24ce22b13d439f217a0f67a6808c" }, { "yara": [], "sha1": "afb7b81da96f372a22428d679b4314e345f9ae02", "name": "47f389de70e6277c_fdcc - windows xp,v1.2.1.0.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarks\\fdcc - windows xp,v1.2.1.0.html", "type": "HTML document, ISO-8859 text, with very long lines, with CRLF line terminators", "sha256": "47f389de70e6277c590c95a0402cc5cae5b66e606b9f60cf0acdbc9c76e11382", "urls": [ "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2147", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2145", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3084", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3085", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3088", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2220", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2688", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3035", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3034", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3036", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2683", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3888", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3929", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3081", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2455", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4564", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?1937", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4047", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4040", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4043", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2855", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3518", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2851", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3696", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2915", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2916", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2910", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2913", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3100", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3103", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4215", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3107", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3106", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3038", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3216", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3213", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2259", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2684", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2674", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2675", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2672", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2777", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2776", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4139", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3601", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3996", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3993", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3855", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3853", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3998", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3284", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5200", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2807", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?1978", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2178", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2176", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2175", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2710", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2173", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2559", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4001", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3976", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5025", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5022", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4791", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4793", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3553", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4707", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4160", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4098", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4099", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?1909", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4997", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2958", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2894", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2896", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2898", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2950", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2955", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2954", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2957", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2956", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2731", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2735", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2828", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2737", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2824", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2826", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4175", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4174", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2791", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3258", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3150", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3151", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3156", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3157", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3154", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3155", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3124", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2239", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2609", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2692", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2693", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3026", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3027", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3025", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2699", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3744", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3933", "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/WinXP-FDCC-V1.2.1.0.htm", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2344", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2466", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2198", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4513", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4053", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4050", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4581", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5055", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5054", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5053", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2994", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2996", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2991", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2993", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2906", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2904", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3564", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3116", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4224", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4732", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3110", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3111", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3118", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3162", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2860", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2864", "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/WinXP-FDCC-Firewall-V1.2.1.0.htm", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2767", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4122", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4643", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4641", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3201", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3207", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3204", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2797", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3706", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2247", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2792", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4079", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3058", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2799", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?1969", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3338", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2494", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2167", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3061", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3018", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2546", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2547", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2891", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3012", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3014", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5136", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4017", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4013", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3945", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3941", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5014", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4018", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2899", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2335", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2336", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3751", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4262", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3400", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4062", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4066", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?1916", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2829", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4068", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5160", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2948", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2944", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2942", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2726", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2833", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2830", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2933", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2930", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4162", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4163", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2935", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4161", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3247", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3128", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4763", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3122", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3236", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3235", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3623", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3584", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4119", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4118", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4110", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3337", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3053", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2299", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4953", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3754", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4952", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4849", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4845", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2052", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2472", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2476", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2573", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3909", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2184", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5194", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3902", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3905", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3906", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5121", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4026", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2379", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2989", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2983", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2980", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2981", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2986", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2987", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2974", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2973", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2972", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2971", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3576", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3570", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3172", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3198", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3176", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3179", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2878", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2873", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2657", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2652", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2718", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2802", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2713", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2806", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2804", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4153", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4150", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4652", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3273", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3378", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4158", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2784", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2786", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3875", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3304", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2788", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2789", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3090", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3097", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3094", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2021", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3000", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3004", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3005", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3006", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3007", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5099", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3891", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3894", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2439", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2436", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2326", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2446", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4270", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?5072", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2928", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2846", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4196", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2841", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2920", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2923", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2926", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4202", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3139", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3134", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3135", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3131", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3132", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3133", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3590", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3183", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4132", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2700", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2661", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3619", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4109", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2213", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4101", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4104", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3040", "http:\/\/www.belarc.com\/Advisor2\/CISWebDocs\/IE7-FDCC-V1.2.1.0.htm", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3043", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3048", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3049", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3291", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2847", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4192", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2100", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2842", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3914", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3963", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2849", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2366", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2313", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2312", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2965", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2960", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2961", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4242", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4084", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3141", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2882", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2880", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2886", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2889", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2888", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2818", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2810", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2814", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2701", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?2816", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4147", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4887", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4143", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3265", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?4149", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3262", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3866", "http:\/\/www.belarc.com\/cgi-bin\/ccerefer?3867" ], "crc32": "93F24FC5", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/47f389de70e6277c_fdcc - windows xp,v1.2.1.0.html", "ssdeep": null, "size": 202571, "sha512": "ed0973460ef305d4093d8cdbfab0d04883ab7a45d1d71113818e46026bae880c52ac026e5a73b054a87ceb2018196da65a5b8360387d4f5b190eb413b88a3064", "pids": [ 2740 ], "md5": "4f2ef98fb1d70a188de381c48a04896f" }, { "yara": [], "sha1": "c0125e31480a303f3f0b53e6f576d0141ded6cff", "name": "11fd457a46f566fd_benchmarkhelp.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\benchmarkhelp.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "11fd457a46f566fdbde209fc4cb3f257e3e424bba72a2e15503c770a44b30c94", "urls": [ "http:\/\/usgcb.nist.gov", "https:\/\/www.csiac.org\/journal\/security-benchmarks-gold-standard", "http:\/\/fdcc.nist.gov", "http:\/\/www.belarc.com\/whitepapers.html" ], "crc32": "60BED9F7", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/11fd457a46f566fd_benchmarkhelp.html", "ssdeep": null, "size": 3521, "sha512": "3acd441db002a937e57027e6a5d9617cf54a56284cd3538d8545f7b6d390d43276f648d5478645b8121ed1fc89fca683232b9a75849f475ee42bbac88d065295", "pids": [ 2740 ], "md5": "360733cbe3db7d8ab08aa98f270a3137" }, { "yara": [], "sha1": "9aaa6ed98726e657252a098f2bf06066a8604d27", "name": "e362a9815527869e_GLF63F2.tmp", "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows", "sha256": "e362a9815527869e0f71fdf766a1c3648e307145defda7a5279914e522bcb57c", "urls": [], "crc32": "5460133E", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e362a9815527869e_GLF63F2.tmp", "ssdeep": null, "size": 10752, "sha512": "f8b4129dc4ab30e009cb4db8a80f06b16306c1a90a49e534befb925d6ce4d5713b98553a2107b40efa8b5abd025ff0556976cf46c3642ce8e372c34d105e36cb", "pids": [ 2740 ], "md5": "9da8f742593d4bbca708b90725282ae2" }, { "yara": [], "sha1": "45655d80806e4cff3b438f5b9ef792b25bda8aed", "name": "ff09243c8f562219_summaryloginsfooter.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryloginsfooter.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "ff09243c8f562219e55eea7a12e94851c6ee05e1720079f7dbe48112e23bdd2c", "urls": [], "crc32": "E2B5EB7B", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ff09243c8f562219_summaryloginsfooter.html", "ssdeep": null, "size": 309, "sha512": "69dfb0b6b657646bec9554c241835448004e4f1bf7ffb4e2ec61f041eb07d10f410437b716bb2c0da88de62774657a49dab6a99f3b4c6fd860979fd22a1deb9b", "pids": [ 2740 ], "md5": "57be666b8d03cda7a5cdba7ba8d3545c" }, { "yara": [], "sha1": "b6b948aeaa726d238e5a294143777145a4b55720", "name": "2c55145e4c2382cd_sp_s16.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s16.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "2c55145e4c2382cdaff56fe35207988b34eafcd5c01b209d099b61fee22c95eb", "urls": [], "crc32": "7897EFE1", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/2c55145e4c2382cd_sp_s16.gif", "ssdeep": null, "size": 1131, "sha512": "fb518cb04dd7bed969d08c2a5b105ff7c481006d8ed39bae3af3db00ccd68f9b4c96d322e75bc6cb27954b6ecaf25e6f931d77756699b6cd379d7b528b09deca", "pids": [ 2740 ], "md5": "3e060efed86cd4c9db67badcf21f769d" }, { "yara": [], "sha1": "99170bbcf46d8561027f199b2385c5f14458f033", "name": "2b53a98c0c179125_sitedefaultsummary.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\sitedefaultsummary.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "2b53a98c0c179125f43d9b9c8758b5506ef3c0bf848ea73d6ef8eca23caf8ddb", "urls": [], "crc32": "115BFB3E", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/2b53a98c0c179125_sitedefaultsummary.html", "ssdeep": null, "size": 1394, "sha512": "daee136393f9f21bd4be436021114f695c0712f36ddb765866a03f739e8998c22e1fd77310543cd38b08ada964afa3356633400a26408f6aee2416806bca7e1b", "pids": [ 2740 ], "md5": "cf1284372fb8bcfbac599340da5fb339" }, { "yara": [], "sha1": "2bc5e975796de5d0df3db69aa3c95491eac4349f", "name": "d111a95011c775ea_sp_s8.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s8.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "d111a95011c775eab620f4d49fd01726986cad8839a917103818d8454f9c0ead", "urls": [], "crc32": "A03271DD", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d111a95011c775ea_sp_s8.gif", "ssdeep": null, "size": 1162, "sha512": "fb3bfb4e7fa19d5bb704a5da4c9c9ac581528ebfd58ad566f7206fb8d89dc2e9c2244551cc4217c520cf95e2af3e8099e6a8d96cf533c23066ec8c798b319a09", "pids": [ 2740 ], "md5": "37729a73d97c3d2aa97b18cf76b6271a" }, { "yara": [], "sha1": "8c70a89b480fac71d554ac790cef9b133a783850", "name": "ce76f733876eb633_summarycopyright.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarycopyright.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "ce76f733876eb633ac352b90e3cb85da877c31dcb6887220850a31779166de2f", "urls": [ "http:\/\/www.belarc.com\/Advisor2\/legal_notice.html" ], "crc32": "118BFA7F", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ce76f733876eb633_summarycopyright.html", "ssdeep": null, "size": 297, "sha512": "fd1a3dfa1eb9e36d7b807af9bf9a7f34c9b68be16a436f00b006a05d9d2617568d4d0ebf68a3c56b1b534f3d8968a10465a1db3fe07466f72c92dab5db1429a7", "pids": [ 2740 ], "md5": "a8cb97667d146f8c394d195a248d3898" }, { "yara": [], "sha1": "abd3e9908da42748876a0f0ccec2e4d3a5a0d150", "name": "cb3621f7599cbbe7_brandname.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\brandname.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "cb3621f7599cbbe7f5ee57b26319fe911cb584c5adcb9e728ce8a38686926b6b", "urls": [], "crc32": "F0CD7E37", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/cb3621f7599cbbe7_brandname.html", "ssdeep": null, "size": 102, "sha512": "efcbfd0e7da441c5a1f4226e4a905c7e67e7dd3b713815d25a0eccfac335c264371d8378fad929e487cd5088eb73e9a56bc45b7a27548e2e03ade105a9b47a1c", "pids": [ 2740 ], "md5": "5c3d0f639b7e125c187f9b0cf9d29ef6" }, { "yara": [], "sha1": "204840f2d86c8f5b3121fea7e5e06b0363cfbee7", "name": "4c218056669668a0_summaryqfemissingitems.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfemissingitems.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "4c218056669668a01f33abb59bd1208c77f01de5fede27b0983e8d67811e0acb", "urls": [ "http:\/\/www.belarc.com\/cgi-bin\/qferefer?%1" ], "crc32": "3F21A964", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/4c218056669668a0_summaryqfemissingitems.html", "ssdeep": null, "size": 1058, "sha512": "0a87cb4c9e687e52978628ae6f1d61142acca5a435803404ea4689f8d11f537a9f20da9d8bc83b0e6818dc8e06ed2f8bdaff0631ac81e00ef96995ebc287514d", "pids": [ 2740 ], "md5": "2c064be20d323bf99f6c6146fc01d63a" }, { "yara": [], "sha1": "f4f7db1397a3eea8d09d5350a2cb7ccf2a310ccb", "name": "d08d9a1438bbe5fb_securitypanel.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\securitypanel.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "d08d9a1438bbe5fb9f8b3a444bb9b922d280f11bfce2080ccbaa104fdead574b", "urls": [], "crc32": "22042120", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d08d9a1438bbe5fb_securitypanel.html", "ssdeep": null, "size": 940, "sha512": "a979170dcd556269a62be40247cb9dce045aa599bc913dfb561509da03b56fae16d612381ceed488f1ee9b3702022f1449f4293efb85e14c2b63d438e351e7e8", "pids": [ 2740 ], "md5": "4add6701e4bcd7bd139e16258edd4ceb" }, { "yara": [], "sha1": "5da963ffede5619ff8e20e6fc3947b66396609ba", "name": "e7686cf33ecf77a3_summarylan.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylan.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "e7686cf33ecf77a395b929c4664dad41a07602f1f7d172b382ba725bc8d0afa2", "urls": [], "crc32": "FDCD8645", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/e7686cf33ecf77a3_summarylan.html", "ssdeep": null, "size": 255, "sha512": "f2d2054f88fd603d2e730edca739221686e4c60ba1918c54589da82ae73cf655b0d5475cb8bae46d488caa0b966d38a71696a4f2548bd85826031004d9d96bab", "pids": [ 2740 ], "md5": "6c5480c777f7d1c66d7c7fd2fd3b92ed" }, { "yara": [ { "meta": { "description": "(no description)" }, "name": "LnkHeader", "offsets": { "guid": [ [ 4, 0 ] ], "signature": [ [ 0, 1 ] ] }, "strings": [ "ARQCAAAAAADAAAAAAAAARg==", "TAAAAA==" ] } ], "sha1": "f41e92e183bcb4a3a00497f30975778fa4c7a142", "name": "22ebcb8de89a0d00_belarc advisor.lnk", "filepath": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Sat Nov 23 19:53:15 2019, mtime=Sat Nov 23 19:53:15 2019, atime=Sat Jan 26 02:04:36 2019, length=134824, window=hide", "sha256": "22ebcb8de89a0d00863bc22f3140fcbcbe2d8b02dfed16018e2b2c03d4b72088", "urls": [], "crc32": "D54B0125", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/22ebcb8de89a0d00_belarc advisor.lnk", "ssdeep": null, "size": 2132, "sha512": "8ce361e11aa591be2769ae0bde4f98c7cf329f1b799385467223d30156cb89d17cec233b064bf0599c50f29729a7195913462e3bf260475f7175ece4957c79a5", "pids": [ 2740 ], "md5": "3949cd4c5c9c9d720417a4e8ca6b4578" }, { "yara": [ { "meta": { "description": "(no description)" }, "name": "LnkHeader", "offsets": { "guid": [ [ 4, 0 ] ], "signature": [ [ 0, 1 ] ] }, "strings": [ "ARQCAAAAAADAAAAAAAAARg==", "TAAAAA==" ] } ], "sha1": "eca9d479f7eeb179ae68694f8558bb2a21a7a2a6", "name": "61d77930ad503687_belarc advisor.lnk", "filepath": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk", "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Sat Nov 23 19:53:15 2019, mtime=Sat Nov 23 19:53:15 2019, atime=Sat Jan 26 02:04:36 2019, length=134824, window=hide", "sha256": "61d77930ad503687f7fa66e5ded7dea006cbbd76c8e2abf023692bcc063eb059", "urls": [], "crc32": "25A55DA1", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/61d77930ad503687_belarc advisor.lnk", "ssdeep": null, "size": 2144, "sha512": "47ff14adb623269ff33eef32bc6876f6e179621be1786c91f0f1f424c1c7a136f3948205a25d0e15d0aac2cffd8c2a9a801fa8b9a595d2de774b6d38ecb2f292", "pids": [ 2740 ], "md5": "d22b5342721c0339615618e77a598221" }, { "yara": [], "sha1": "26124f69a47aa7efcce20c498be302ccdd7ec365", "name": "3b9c326820af42b7_summaryqferecent.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqferecent.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "3b9c326820af42b77dad54efd89bf6e53c2972c477962623f100f0dd3ab84f94", "urls": [], "crc32": "7ED0ABD9", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/3b9c326820af42b7_summaryqferecent.html", "ssdeep": null, "size": 386, "sha512": "b2e70b509cf62165be9d549df1846146ead9cdd8276060996faa021d6fca9d4529837529b553b94c382c429096627fdc15ae3526c34e73fc57ce4beed85ddab0", "pids": [ 2740 ], "md5": "1a06d6483beebb76b5db5d5f1b0d2444" }, { "yara": [], "sha1": "88e365bc395f6cf7cea65cdd937d35391432ddae", "name": "ab44800765487575_black.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\black.gif", "type": "GIF image data, version 87a, 1 x 1", "sha256": "ab44800765487575508351c488398646a5c7b5d01e121cfbd70b37bfeba93a0d", "urls": [], "crc32": "62EEB30C", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/ab44800765487575_black.gif", "ssdeep": null, "size": 35, "sha512": "328e58854ab8a1a30230f711fca584f7ff6ecf23b77627e3f5e4da27be573def6da42e2047781aea47132c6d83d95cd28456e82a837145d6173720d4e9cbf746", "pids": [ 2740 ], "md5": "54bcf265c60042adbbc35215aaf86bf6" }, { "yara": [], "sha1": "1638721af45e01d3506bfb77ff00ce2f6638c090", "name": "d7101488ce0dfaa8_summarynet.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarynet.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "d7101488ce0dfaa885e71204f3d480f868e83dc5cb953d4c42e50709505b3d22", "urls": [], "crc32": "6A2F4724", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/d7101488ce0dfaa8_summarynet.html", "ssdeep": null, "size": 194, "sha512": "18ff6ee5927928edc968352b0adf14580b776081f1e62364a1e4f3ccd7db85e2e8984f4befcc7b378794c7132038a0709c49dd582f8a09ab746e37e321939bb6", "pids": [ 2740 ], "md5": "85f7a4aed1bbec6b382069ed170e7da3" }, { "yara": [], "sha1": "371d19942006bf5ae2b1c0eb6f8f9386a34563b0", "name": "f9982fa41942dd67_BAlicense.txt", "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt", "type": "ASCII text, with CRLF line terminators", "sha256": "f9982fa41942dd67d8be1f6fce9aa4b1e6fc2dfc6e2ad7e23b073d3fe9420e6d", "urls": [ "http:\/\/www.belarc.com" ], "crc32": "4DD6F4F1", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f9982fa41942dd67_BAlicense.txt", "ssdeep": null, "size": 4485, "sha512": "567a8944b3476e25b66159070a07c49ca3e4100bd51a40073cdf68a7c2c612fb2050d1586752ee3302bbd8447220e9dc24033c9040d009d42d3d5d7253a97d9e", "pids": [ 2740 ], "md5": "df8145a6613a01542696625ccc502898" }, { "yara": [], "sha1": "9411764e3d85035c3fc14a1d4b64f594ae969416", "name": "953f7968829ded7c_summarylocaldriveitem.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarylocaldriveitem.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "953f7968829ded7c549d60739e6048b32bc47fc4ea3e76562137c05f265f1407", "urls": [], "crc32": "D3F4D13E", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/953f7968829ded7c_summarylocaldriveitem.html", "ssdeep": null, "size": 241, "sha512": "61c685749d0daee3f5b2a89d6e2182bb507c268b8396bbe34011421f51d03f5708f9cabed23ed009b917102fbada66c6ad5dfd99d0854057e56d8db6074973d1", "pids": [ 2740 ], "md5": "df11aecb3f919eb9afdf4c39b355bd43" }, { "yara": [], "sha1": "0f1405c1a4669fae9f361630cc6850b640d6ede5", "name": "cf3ab6c2a33dba1c_summarynetworkdrivehdr.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summarynetworkdrivehdr.html", "type": "exported SGML document, ASCII text, with CRLF line terminators", "sha256": "cf3ab6c2a33dba1cf8028b1d097d286de0331324765bd7cfbe6f2b7ece9972f1", "urls": [], "crc32": "563D9E22", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/cf3ab6c2a33dba1c_summarynetworkdrivehdr.html", "ssdeep": null, "size": 135, "sha512": "4a51a992e4a5034795ea499111457e4d8e3109833ecf41c04b385fc5f77e61a579f7d8086af2b2388818bc0ce9b443cb62640bffb7ade7aadbb07253aae051cd", "pids": [ 2740 ], "md5": "01fcfcb33c29eb9b19eb8ebb7477ff30" }, { "yara": [], "sha1": "79cb27bfa9f36574805cb6461b950e354ed84221", "name": "2ae18b89fc5c51bf_summaryqfe.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfe.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "2ae18b89fc5c51bfeb44cd3d3fb73bd86d115a82fd3e716e1027bc6d2b700964", "urls": [], "crc32": "7EBEB938", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/2ae18b89fc5c51bf_summaryqfe.html", "ssdeep": null, "size": 515, "sha512": "d4fa145822ec722bbab1becd3f7fbe4836c0672fa4ab4a5f304518c7e846f7cf178cc9d6c716a48b279137b2cb16b57ebf45da9423fb9e52a9e961eba410a624", "pids": [ 2740 ], "md5": "690dce20db563a7f2e3ce92ba9706842" }, { "yara": [], "sha1": "8183178b535a2b6e94a97aa8d8a0440047fe1e0b", "name": "1c328e592e9b7e6f_summaryqfeitems.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryqfeitems.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "1c328e592e9b7e6fc823b1f44da20e53833090335764d939fae54d3286a9c5c8", "urls": [ "http:\/\/www.belarc.com\/cgi-bin\/qferefer?%7" ], "crc32": "4A4C1038", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/1c328e592e9b7e6f_summaryqfeitems.html", "ssdeep": null, "size": 939, "sha512": "30877a552b692a9ac77f7adbbaf905b2fbd0c4712ecea126ef56326c4ba86c412e88c0327fbc9f25284dbec38298c42749701bcedcd07cb4274c7523a648dbeb", "pids": [ 2740 ], "md5": "f488e20f0a076ef8ef945f57d1e0c9de" }, { "yara": [], "sha1": "80cf0399b7584de9ca760e2eefb055d9fab50bdc", "name": "379e1070c78bff65_summaryantivirus.html", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\tpl\\summaryantivirus.html", "type": "HTML document, ASCII text, with CRLF line terminators", "sha256": "379e1070c78bff65428a48b768e77801045765de5fe0a96113af061dedb7b015", "urls": [], "crc32": "26BF2710", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/379e1070c78bff65_summaryantivirus.html", "ssdeep": null, "size": 98, "sha512": "ad82d35599bba939a129062306280d23869337509de2ca0db8f0bc2cbed003a49c4b609599670622c8976305eeb46a7e903eba5f411a7619c7bbe07e5388b2c0", "pids": [ 2740 ], "md5": "88ca4580bc39c745d949aac8640027a9" }, { "yara": [], "sha1": "e08d4f3aba109bb29273dc0183cafa053631f062", "name": "f9df7b68baab06cd_sp_s9.gif", "filepath": "c:\\program files (x86)\\belarc\\belarcadvisor\\system\\local\\images\\sp_s9.gif", "type": "GIF image data, version 89a, 24 x 24", "sha256": "f9df7b68baab06cd19a213cc8bc604fa608577d906e336097bdd1e3a8f19485a", "urls": [], "crc32": "9763B2E3", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/3773\/files\/f9df7b68baab06cd_sp_s9.gif", "ssdeep": null, "size": 1194, "sha512": "fd91150cbb44f3bb9d5126a4e763f9095f6ccc995cf717d48da31c6ca7d1a42516e54da217d254cc7395e67540b6fbdd7b1e88422412ac1c4ec83750bf7c3772", "pids": [ 2740 ], "md5": "125dcb9a29a2c474bb7441f5a3ec6a0a" } ]
[ { "process_path": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "process_name": "BelarcAdvisor.exe", "pid": 2648, "summary": { "regkey_written": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\UuidMethod", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileDirectory", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableFileTracing", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionReason", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\ConsoleTracingMask", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\MaxFileSize", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecision", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadNetworkName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionTime", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Serial Number", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableConsoleTracing", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileTracingMask" ], "dll_loaded": [ "C:\\Windows\\system32\\wininet.dll", "C:\\Windows\\System32\\mswsock.dll", "CRYPT32.dll", "DNSAPI.dll", "DHCPCSVC.DLL", "kernel32.dll", "C:\\Windows\\system32\\ole32.dll", "dwmapi.dll", "C:\\Windows\\system32\\napinsp.dll", "imm32.dll", "schannel", "API-MS-WIN-Service-Management-L1-1-0.dll", "PROPSYS.dll", "C:\\Windows\\syswow64\\MSCTF.dll", "WININET.dll", "OLEAUT32.DLL", "RASMAN.DLL", "ole32.dll", "C:\\Windows\\system32\\uxtheme.dll", "USER32.dll", "Comctl32.dll", "API-MS-Win-Security-SDDL-L1-1-0.dll", "API-MS-WIN-Service-winsvc-L1-1-0.dll", "wintrust.dll", "rtutils.dll", "IPHLPAPI.DLL", "C:\\PROGRA~2\\Belarc\\BELARC~1\\System\\NPBelv32.dll", "wininet.dll", "OLEAUT32.dll", "C:\\Windows\\system32\\pnrpnsp.dll", "SHELL32.dll", "RPCRT4.dll", "C:\\Windows\\System32\\winrnr.dll", "SHLWAPI.dll", "C:\\Windows\\system32\\NLAapi.dll", "C:\\Windows\\SysWOW64\\oleaut32.dll", "ADVAPI32.dll", "WS2_32.dll" ], "file_opened": [ "C:\\Windows\\System32\\oleaccrc.dll", "C:\\", "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax", "C:\\Windows\\System32\\en-US\\wininet.dll.mui", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\" ], "regkey_opened": [ "HKEY_CLASSES_ROOT\\.html\\OpenWithProgids", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\DnsClient", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\BELARC~1.EXE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList", "HKEY_CLASSES_ROOT\\FirefoxHTML-E7CF176E110C211B", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\OpenWithProgids", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\BELARC~1_RASMANCS", "HKEY_CLASSES_ROOT\\.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\msasn1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\MS Shell Dlg 2", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\DnsCache\\Parameters", "HKEY_CURRENT_USER\\Software\\Belarc", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE\\Tracing", "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\shell\\open", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}", "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Connections", "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts", "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Wpad", "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32", "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\System\\DNSClient", "HKEY_CURRENT_USER\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}", "HKEY_CURRENT_USER\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\TreatAs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings", "HKEY_CURRENT_USER\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\", "HKEY_CURRENT_USER\\software", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler32", "HKEY_CURRENT_USER\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}", "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\shell\\open\\command", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap", "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Belarc\\Advisor", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing", "HKEY_CURRENT_USER\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32", "HKEY_CLASSES_ROOT\\htmlfile", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts", "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Network\\Location Awareness", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\(Default)", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32", "HKEY_CURRENT_USER\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OleAut", "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLEAUT", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\CurVer", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_INCLUDE_PORT_IN_SPN_KB908209" ], "resolves_host": [ "wpad", "cuckpc", "www.belarc.com" ], "connects_ip": [ "127.0.0.1" ], "file_exists": [ "C:\\Windows\\SysWOW64\\propsys.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx", "C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\", "C:\\Windows\\System32\\propsys.dll" ], "mutex": [ "IESQMMUTEX_0_208" ], "fetches_url": [ "https:\/\/www.belarc.com\/Programs\/defs.xml?dv=2019.11.14.2&av=9.0&df=B&au=1.0.0" ], "file_failed": [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System" ], "guid": [ "{dcb00c01-570f-4a9b-8d69-199fdba5723b}", "{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}", "{a47979d2-c419-11d9-a5b4-001185ad2b89}", "{d0074ffd-570f-4a9b-8d69-199fdba5723b}", "{dcb00000-570f-4a9b-8d69-199fdba5723b}", "{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}" ], "file_read": [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax" ], "regkey_read": [ "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\UuidMethod", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA", "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\ConsoleTracingMask", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorUseSystemHeap", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\HfdefsUrl", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\FileTracingMask", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\MSBulletinVersion", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\EnableConsoleTracing", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\LastDefsCheck", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap\\.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\EnableFileTracing", "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\shell\\open\\command\\(Default)", "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\IsShortcut", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\WMI Timeout", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\BELARC~1.EXE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileDirectory", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\InprocServer32", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugHeapFlags", "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts\\AutoDownloadDefs", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice\\Progid", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\*", "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\*", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Hostname", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Serial Number", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\ThreadingModel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableConsoleTracing", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\ProgramData", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\MaxFileSize", "HKEY_CURRENT_USER\\.html\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASAPI32\\FileDirectory", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoProxyDetectType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\ConsoleTracingMask", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Domain", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableImprovedZoneCheck", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorSystemHeapIsPrivate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\EnableFileTracing", "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts\\AutoCheckDefs", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\FileTracingMask", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\BELARC~1_RASMANCS\\MaxFileSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Downloaded From", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\BELARC~1.EXE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Security_HKLM_only", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Home" ], "directory_enumerated": [ "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk", "C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk", "C:\\Windows\\System32\\ras\\*.pbk", "C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\*.pbk", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\*.pbk" ] }, "first_seen": 1574546003.62475, "ppid": 2740 }, { "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp", "process_name": "GLJ5837.tmp", "pid": 1504, "summary": { "regkey_written": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\InprocServer32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CurVer\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\InprocServer32\\ThreadingModel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Version\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CLSID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\HELPDIR\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ToolboxBitmap32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\CLSID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\VersionIndependentProgID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ProgID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\belarc\\CLSID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0\\win32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\FLAGS\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus\\1\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\belarc\\(Default)" ], "dll_loaded": [ "SETUPAPI.dll", "kernel32.dll", "DEVRTL.dll", "ADVAPI32.dll", "OLE32.DLL", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll" ], "file_opened": [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System", "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls" ], "regkey_opened": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Control", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\Insertable", "HKEY_CLASSES_ROOT\\PROTOCOLS", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}", "HKEY_CLASSES_ROOT\\VoilaXctl.VoilaXctl.1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\VersionIndependentProgID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ProgID", "HKEY_CURRENT_USER\\TypeLib", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib", "HKEY_LOCAL_MACHINE\\System\\Setup", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CurVer", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0\\win32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\FLAGS", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus", "HKEY_LOCAL_MACHINE\\software\\microsoft\\windows\\currentversion\\setup\\PnpLockdownFiles", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLEAUT", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\belarc", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}", "HKEY_CLASSES_ROOT\\VoilaXctl.VoilaXctl", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\MiscStatus\\1", "HKEY_CLASSES_ROOT\\CLSID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\InprocServer32", "HKEY_CURRENT_USER\\Interface", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Version", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\ToolboxBitmap32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\HELPDIR", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl\\CLSID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VoilaXctl.VoilaXctl.1\\CLSID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{6318E0AB-2E93-11D1-B8ED-00608CC9A71F}\\Programmable" ], "file_failed": [ "C:\\Windows\\winsxs\\FileMaps\\program_files_x86_belarc_belarcadvisor_system_2911269189da9f55.cdf-ms" ], "file_read": [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll" ], "regkey_read": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\HELPDIR\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemDrive%\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\0\\win32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{6318E0A8-2E93-11D1-B8ED-00608CC9A71F}\\1.0\\FLAGS\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\TypeLib\\Version", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{6318E0AA-2E93-11D1-B8ED-00608CC9A71F}\\ProxyStubClsid32\\(Default)" ] }, "first_seen": 1574546002.265375, "ppid": 2740 }, { "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "process_name": "c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "pid": 2740, "summary": { "file_created": [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP", "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLB63F0.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP", "C:\\Windows\\System32\\GLBSINST.%$D" ], "file_recreated": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp" ], "directory_created": [ "C:\\ProgramData", "C:\\Users\\cuck\\AppData", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System", "C:\\Users\\cuck\\AppData\\Local\\Temp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks", "C:\\Users\\Public", "C:\\Users\\cuck\\AppData\\Roaming", "C:\\ProgramData\\Microsoft", "C:\\Users", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer", "C:\\Users\\cuck", "C:\\Program Files (x86)", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu", "C:\\ProgramData\\Microsoft\\Windows", "C:\\Users\\cuck\\AppData\\Local", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft", "C:\\Users\\Public\\Desktop", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs", "C:\\Program Files (x86)\\Belarc" ], "dll_loaded": [ "C:\\Windows\\system32\\sfc.dll", "netutils.dll", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "API-MS-Win-Core-LocalRegistry-L1-1-0.dll", "C:\\Windows\\system32\\advapi32.dll", "srvcli.dll", "apphelp.dll", "LINKINFO.dll", "kernel32.dll", "UxTheme.dll", "C:\\Windows\\system32\\ole32.dll", "dwmapi.dll", "CABINET.DLL", "C:\\Windows\\system32\\uxtheme.dll", "ntmarta.dll", "PROPSYS.dll", "C:\\Windows\\syswow64\\MSCTF.dll", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp", "slc.dll", "KERNEL32.DLL", "OLEAUT32.DLL", "comctl32", "SHLWAPI.dll", "USER32.dll", "MPR.dll", "API-MS-Win-Security-SDDL-L1-1-0.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "SHELL32.DLL", "profapi.dll", "SHELL32.dll", "RPCRT4.dll", "RICHED32.DLL", "DEVRTL.dll", "ADVAPI32.dll", "SETUPAPI.dll", "ntshrui.dll" ], "file_opened": [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP", "C:\\", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif", "C:\\Windows\\System32\\oleaccrc.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP", "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif", "C:\\Program Files (x86)", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP", "C:\\Windows\\AppPatch\\pcamain.sdb", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0006.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP", "C:\\Program Files (x86)\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP", "C:\\Program Files (x86)\\Belarc", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP" ], "command_line": [ "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp\" C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll", "\"C:\\PROGRA~2\\Belarc\\BELARC~1\\BELARC~1.EXE\" ", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe" ], "regkey_opened": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PropertyBag", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\BELARC~1.EXE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\ShellEx\\IconHandler", "HKEY_CLASSES_ROOT\\.cmd", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\AppCompat", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions", "HKEY_CLASSES_ROOT\\.bas", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Logins\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\Clsid", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PropertyBag", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\", "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\LSA\\AccessProviders", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PropertyBag", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "HKEY_CLASSES_ROOT\\Belarc.Computer.Inventory\\DefaultIcon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\ProductOptions", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_CLASSES_ROOT\\.com", "HKEY_CLASSES_ROOT\\MIME\\Database\\Content Type\\application\/vnd.belarc-bci", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE\\Tracing", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610", "HKEY_CLASSES_ROOT\\.cpl", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\ddeexec", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}", "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security", "HKEY_LOCAL_MACHINE\\System\\Setup", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\Clsid", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PropertyBag", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PropertyBag", "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d", "HKEY_CLASSES_ROOT\\.EXE", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LanmanWorkstation\\Parameters", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3", "HKEY_CLASSES_ROOT\\Belarc.Computer.Inventory\\shell\\open\\command", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\(Default)", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}", "HKEY_CLASSES_ROOT\\.crt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion", "HKEY_CLASSES_ROOT\\SystemFileAssociations\\.EXE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1\\KnownFolders", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppCompat", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PropertyBag", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup", "HKEY_LOCAL_MACHINE\\software\\microsoft\\windows\\currentversion\\setup\\PnpLockdownFiles", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PropertyBag", "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PropertyBag", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\BELARC~1.EXE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Associations", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN", "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\ShellEx\\IconHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\1.0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\(Default)", "HKEY_CLASSES_ROOT\\.chm", "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Associations", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\DropTarget", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "HKEY_CLASSES_ROOT\\.cer", "HKEY_CLASSES_ROOT\\.ade", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LDAP", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\ProgIDs\\exefile", "HKEY_CLASSES_ROOT\\.adp", "HKEY_LOCAL_MACHINE\\NOT_FOUND", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant", "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\Memory Management\\PrefetchParameters", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PropertyBag", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders", "HKEY_CURRENT_USER\\SOFTWARE\\Belarc\\Advisor\\Settings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}", "HKEY_CLASSES_ROOT\\.app", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\Progid", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.EXE\\OpenWithProgids", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}", "HKEY_CURRENT_USER\\SOFTWARE\\Belarc\\Advisor\\Prompts", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PropertyBag", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\2.0", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\CurVer", "HKEY_CLASSES_ROOT\\.bat", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.EXE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PropertyBag", "HKEY_CLASSES_ROOT\\.bci", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\Logins", "HKEY_CLASSES_ROOT\\.asp", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLEAUT", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PropertyBag", "HKEY_CLASSES_ROOT\\.csh", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\UserChoice", "HKEY_CLASSES_ROOT\\Belarc.Computer.Inventory", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings", "HKEY_CLASSES_ROOT\\exefile", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}", "HKEY_CLASSES_ROOT\\.EXE\\OpenWithProgids", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PropertyBag", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}" ], "file_moved": [ [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0006.TMP" ] ], "file_written": [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP", "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP" ], "regkey_deleted": [ "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Belarc\\Advisor\\2.0" ], "file_deleted": [ "", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLB63F0.tmp", "C:\\Windows\\System32\\GLBSINST.%$D" ], "file_exists": [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0002.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0073.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0079.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002e.TMP", "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0024.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0035.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0054.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0021.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0028.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\temp.000", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0043.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0072.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0023.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0051.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0060.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0046.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0074.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0004.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0033.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0015.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0066.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif", "C:\\Windows\\SysWOW64\\propsys.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BELARC~1.EXE:Zone.Identifier", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0032.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0034.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0049.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0061.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0058.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH0078.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0044.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0029.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0053.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0036.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0048.TMP", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0065.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0052.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0007.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0019.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0030.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH000e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0018.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0006.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\~GLH007a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0069.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\~GLH0009.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0068.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0038.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\~GLH0003.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0025.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0039.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0055.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0020.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0013.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0027.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0001.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH0008.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0041.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006b.TMP", "C:\\Windows\\System32\\propsys.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0075.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0071.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0040.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0010.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0067.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004e.TMP", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~GLH0000.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0012.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0059.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0022.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0017.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0047.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0042.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH004d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0062.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0076.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0063.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH002a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005a.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH006c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\~GLH000c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001b.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0031.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0037.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0016.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0057.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0077.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0056.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0026.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH003f.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\~GLH007d.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH005c.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0014.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH001e.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\~GLH0011.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0045.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0070.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html", "C:\\ProgramData\\Microsoft\\Internet Explorer\\Quick Launch", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0050.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\~GLH0064.TMP" ], "mutex": [ "Local\\ZonesCacheCounterMutex", "Local\\ZoneAttributeCacheCounterMutex", "Local\\ZonesLockedCacheCounterMutex" ], "file_failed": [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html", "C:\\Windows\\BAVoilaX.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif", "C:\\Windows\\System32\\BAVoilaX.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif", "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAVoilaX.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif", "C:\\Windows\\winsxs\\FileMaps\\progra_2_belarc_belarc_1_8c5c07b07cc16182.cdf-ms", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll" ], "guid": [ "{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}", "{00021401-0000-0000-c000-000000000046}", "{79eac9ee-baf9-11ce-8c82-00aa004ba90b}", "{000214ee-0000-0000-c000-000000000046}", "{7b8a2d94-0ac9-11d1-896c-00c04fb6bfc4}", "{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}" ], "file_read": [ "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif", "C:\\Program Files (x86)\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll" ], "regkey_read": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\RelativePath", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\Flags", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PreCreate", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Favorites", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bat\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Icon", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\AppData", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\Content Type", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\HelpLink", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\Flags", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLUpdateInfo", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\RelativePath", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\MEMORY MANAGEMENT\\PrefetchParameters\\EnablePrefetcher", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\Shell Folders\\Common AppData", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SharedDir", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\CommonFilesDir", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Parameters\\RpcCacheTimeout", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Personal", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Downloaded From", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\AlwaysShowExt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\ProfilesDirectory", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResource", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Pictures", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap\\.exe", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DisallowRun", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Name", "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bci\\Content Type", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalRedirectOnly", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{374DE290-123F-4565-9164-39C4925E467B}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Description", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NeverShowExt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Computer ID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayVersion", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.cer\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\UuidMethod", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ProductOptions\\ProductType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\GlobalSession", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonVideo", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Description", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Name", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Programs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\GetIpAddress", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\MachineThrottling", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Attributes", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Music", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\RelativePath", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Video", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonMusic", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.com\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\*", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PreCreate", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Startup", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InfoTip", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NoStaticDefaultVerb", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.chm\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Desktop", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Security", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\Flags", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\UninstallString", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\ProgramFilesDir", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InfoTip", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{56784854-C6CB-462B-8169-88E350ACB882}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\DelegateExecute", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\Publisher", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\*", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Test2", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Stream", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayIcon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.crt\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\InstallLocation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN\\*", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalRedirectOnly", "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Roamable", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Home", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PublishExpandedPath", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\Flags", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bas\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant\\AllowNetworkPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Attributes", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\TurnOffSPIAnimations", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.cpl\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorUseSystemHeap", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Icon", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\IsShortcut", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\AlwaysShowExt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonPictures", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalizedName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1806", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalizedName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalizedName", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResourceType", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Cache", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalizedName", "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalizedName", "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\command", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\NoWorkingDirectory", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\safer\\codeidentifiers\\TransparentEnabled", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\NeverDefault", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.cmd\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\InheritConsoleHandles", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\DevicePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\Public", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\Flags", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemDrive%\\PROGRA~2\\Belarc\\BELARC~1\\BELARC~1.EXE", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Startup", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Description", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorSystemHeapIsPrivate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Documents", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.asp\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\SetWorkingDirectoryFromTarget", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1806", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLInfoAbout", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\ShowNtAdminMessage", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledProcesses\\7914760B", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\RestrictRun", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\NeverShowExt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs\\C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Category" ], "directory_enumerated": [ "", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html", "C:\\Users\\cuck\\AppData\\Local\\Temp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\*.*", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s14.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor2_startup.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Summary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_alert.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecent.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tl.gif", "C:\\Program Files (x86)", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Cux.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\INSTALL.LOG", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingEmpty.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorage.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s9.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelTextItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s2.gif", "C:\\Windows", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineItem.html", "C:\\Program Files (x86)\\Belarc", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenses.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_br.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinters.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanel.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_alert.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItemLinux.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPrinterItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\AntiVirusItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkScoreWarning.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s7.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachines.html", "C:\\Users", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeItems.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\AdvisorBrand.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box-.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDriveItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryOuPath.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkNoDetails.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryPageHeader.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s4.gif", "C:\\Users\\cuck", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html", "C:\\Users\\cuck\\AppData\\Local", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\Advisor.css", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Advisor.bcx", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SoftwareLinkFormats.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_alert.html", "C:\\Windows\\System32\\rundll32.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\license.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\yes.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\box+.gif", "C:\\Users\\cuck\\AppData", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUsbStorageItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryCopyright.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrives.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryGroupPolicyItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\trans.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\HotfixDefs.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security\\Benchmarks.cax", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs3.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\Uninstall.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s8.gif", "C:\\Windows\\System32", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s10.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BrandLinks.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\OsAutoUpdateFormats.html", "C:\\Users\\cuck\\AppData\\Local\\Temp\\BAlicense.txt", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\siteDefaultSummary.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\belarc-logo-small.png", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLogins.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs0.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseItem.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_ok.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s15.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s13.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs2.gif", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserEntry.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\Scoring.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\privacy.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\Security", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserName.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLocalDrivesFootnotes.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_unknown.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tmp\\license.html", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\BAVoilaX.dll" ], "regkey_written": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\UuidMethod", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\UninstallString", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Logins\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\DefaultIcon\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayName", "HKEY_CURRENT_USER\\Software\\Belarc\\Advisor\\Prompts\\License Agreement", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\InstallLocation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\application\/vnd.belarc-bci\\Extension", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\shell\\open\\command\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\Publisher", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Test2", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLInfoAbout", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Belarc.Computer.Inventory\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bci\\Content Type", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\HelpLink", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\GetIpAddress", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Home", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\URLUpdateInfo", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bci\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Computer ID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayIcon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor\\DisplayVersion", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\Downloaded From", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Belarc\\Advisor\\ShowNtAdminMessage" ] }, "first_seen": 1574545988.640625, "ppid": 1564 }, { "process_path": "C:\\Windows\\explorer.exe", "process_name": "explorer.exe", "pid": 1788, "summary": { "directory_created": [ "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer" ], "dll_loaded": [ "C:\\Windows\\system32\\xmllite.dll", "POWRPROF.DLL" ], "file_opened": [ "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories", "C:\\ProgramData", "C:\\", "C:\\Users\\cuck\\AppData", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC", "C:\\Users\\cuck\\Desktop", "C:\\Users\\Public\\Desktop", "C:\\ProgramData\\Microsoft", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\ProgramData\\Microsoft\\Windows", "C:\\Users\\Public\\Desktop\\desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC\\Desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\desktop.ini", "C:\\Windows\\AppPatch\\sysmain.sdb", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance", "C:\\Users", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup", "C:\\Users\\", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\Desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\", "C:\\Users\\Public", "C:\\Users\\cuck\\AppData\\Roaming", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_96.db", "C:\\Users\\cuck\\Desktop\\desktop.ini", "C:\\Program Files (x86)\\", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\desktop.ini", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_1024.db", "C:\\Users\\desktop.ini", "C:\\Windows\\win.ini", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility\\Desktop.ini", "C:\\Users\\cuck", "C:\\Users\\cuck\\AppData\\Local\\", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu", "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_256.db", "C:\\Users\\cuck\\", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_sr.db", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_idx.db", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Python 2.7", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games\\desktop.ini", "C:\\Users\\Public\\desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs", "c:\\program files (x86)\\Belarc\\belarcadvisor\\belarcadvisor.exe", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools\\Desktop.ini", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db", "C:\\Program Files (x86)\\desktop.ini", "C:\\Users\\cuck\\AppData\\", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools" ], "regkey_opened": [ "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F05C8358C56DAD54BB81D0A11DD52F41", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D0CBB37A94C46943A90AC5008CF1CC9", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0F4DC93AAA8AD1D448BC4E6A207F4FE0", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\895805CC90C04694887EF6BD140A622D", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\BE0BD5097A638224EB0DAAE870267F03", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B06071FE021ECB04E8B3BF1E39AD5BB3", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CDBF699A8F2EAC2438564C3D50E9E638", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B5C8B2FB95B57147954C18085D53ACE", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\040E2A370D6DB2F45AE45A0032BC2179", "HKEY_CLASSES_ROOT\\Outlook.Application.12", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\30FAECE2400494D4FB69207288EB5B73", "HKEY_CLASSES_ROOT\\Outlook.Application.10", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0EF52818FCE3E7B488427C1F8266654E", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\669C9DC1419C0F240B35B36B99AAB50C", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1E82F31DC0D05AA4CB291B7BAA23FC8E", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FBEAAA6C37E8AF24B87AAEA0047433BD", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\103857F24A2EDA54A800A41FA570861F", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D3541DFF9B79C584284E8981624C04CB", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F356843B045CC0A4BA0D83C1D85AAAFD", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A7E9995902A24964C9C5D461E1C86F19", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\87C48B95924E3294FBC1766C9225DD0C", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E85E64F0A7FC58E47A87E5AB98A6F2DD", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\958C4A0DE6C8D5C428C6E9D875BC33B6", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4486F7CE8F022FB4EB0154C5226C27A0", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B1D5EA6004F809D48B117CE563261011", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\33AB3CD4D27277545B5A93CD4ECB96B4", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E429E5BC27530F4786481EC687D9EC9", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FE547D6F0D72534A80F89C4AB727618", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AE5A0040C41ACA642AF6DB16F4D2F638", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0411990C889EE9B47BB0B5D356564877", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\2FA90A429E82313489DAA2E2C2F0872C", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\75B368B60C908BA4E87C31F66B02F3F0", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B04950B5EC5C924B8F428B5484A2720", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89DF671CDA74E9D4EB10275B10D5CF3F", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CB2182A03B6B11341A1F09A021991CE1", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\62293D511DB84E5489074C5AFA18E882", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9D22CD4619F5DBC499A083AAD70FE7B3", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FF9FDEA72CD9DDC47A6DAB85F9F76B81", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7BF7ABF4D25C03F4582D4BC3082FB208", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E40FDF839772BEB41AC977860DBB4853", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CE5B971A0DBB8FD4F83AE0DADC348104", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LanmanServer\\DefaultSecurity", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CF65AB832507EDB4BB357F9D8E0431BD", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\63B1AF366905AF641BA514CCBAE803C4", "HKEY_LOCAL_MACHINE\\Software\\Classes\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8691BCC36FF121849A90B085BFAF5E5E", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F591EF48DE97A00428A5BC1AFFFAA868", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-699399860-4089948139-3198924279-1001\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\285499F23409ED14FB4A01230F5DFA91", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9BA984AD4F03E284382FFBB7A68BEE27", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE19F224928A59468049F045950CB08", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84C584688CFC74A4E9D36E5EE2E02FA7", "HKEY_CLASSES_ROOT\\Outlook.Application.11", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9F5ED6B416EF0A1448D94799D0FF20BA", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FEB01D34D0F67E4F9CD810B432C1B91", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4514EC211C8947C4B9BA24F353AFFD50", "HKEY_LOCAL_MACHINE\\Software\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE462B32EFD81040A184ED17E00452B", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7814D91294731FF4DBBB840810BEB3BB", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\67C12EF40671B7342A2F990919031A57", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B4BBDDC88CEE4DD439E8BB261CE222A8", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\296744B7EBFEB2741A47781AE6E32269", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\92F9143E715DEF045A539256438E41FB", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8020CF43278B2644190F51544810251E", "HKEY_CURRENT_USER\\Software\\Microsoft\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B690B72A999998C47B5F93C94A8D43B2", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3D197E722531D614AB40C182904D9A31", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\16AC40BE991DF1643B2800729063B2F9", "HKEY_CURRENT_USER\\Software\\Microsoft\\Installer\\Products\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7C0477DE66D1A6749864FCE02A6DCB6C", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D5FD8239A83FE564F97379EA15CE8CB6", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\04C56B5D827A9194FA2CBFD014EAD0DA", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4626147D107665540A84D43A5908E74D", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A558E619ABC4CE5479C1DA5070EFBF81", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18D84E9490A485948A17A1F02CDAA62A", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\315C767EFC72D8445B1D2D16F72653F0", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\11E2BA15171FE704B98E7505E58D7749", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D38A6F5FC8262149A9FAAE8C621EE3F", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8ECC347096FA78C4E8291F449F71E16E", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FE056816E41FD2F4CACD03E7A2CA2E6E", "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ThumbnailCache", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89BBBC8A0D32B014696C4BA3C20CDD34", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9DD74C0626DC33C479C1929714AB5295", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95E2C34402A93A14FA8CB3420B85375C", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\53F08364FFD17F14B8FD7CA7F52FAE76", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C1EF68F348457B246A0AD0C18B3079AF", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E116C831A95AB5B4787CE3086FE83631", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\863CA21BBA4DFCE489FDF96EAB898616", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A0256FF64030E0746A4AA95D3FFD0BE4", "HKEY_CLASSES_ROOT\\Outlook.Application", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1A0857155A8EF604FA5D1648CF382DC7", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D04063BE69797D4D8505462827A0D19", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FFFA6DF7EA9EDFC45A1F02FE6DF8F067", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\73964AA699D5B5140ADC41ED3F7DB38A", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9753E3A35E3BDFB468DF95B5D19C8A04", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Sharing", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-699399860-4089948139-3198924279-1001\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D725CB8E57307E64EB574E04214D8B5F", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1C1ED53B8F25FD248955C15232E46886", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StuckRects2", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18F5DB38C45303843B06B1B5025E4820", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AD21E12039BB3BC47B1938BC4ABDFEE2", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\034A8F8E06031EF46BCB4C10469098E5", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C4040CC509FB0DC4886F590DDF6B6132", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84BBAC70FB00B6046881B55CB3122F0F", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F21868A51A175874BB819DCA5FAA40A3", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0A191B45599EEB74CA305184EA3C2A94", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3C68656E520593A45925ADFB41F821B5", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\90860AAA7BD3DE34EB32330DD29CAD62", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\002F6EFFA8A0A40498F3035BD153685A", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F41A458014D57E54E8DBD0B0CBC361A2", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9E40FDB6330EBA242A4BD5F4FDD0B803", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E3DAE67887931944BCD7171908FA775", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\965742E8F65116F4BB2CB01341464FA7", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\717591555BCB1604BA9777E8A55D0E41", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\335F6F64CD461D9469519574D34757EB", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\17E23EF6C775D324DB90E0E2B7D1CA72", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0FD387D006FD9734FA65B249F36DE42A", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95EE473833000D6409127D1B85882AC9", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\EEF8AA9EB45B5DB4BBE46B8634C910CD", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7636A94AA21EDBB48B6AFFB17E5907B8" ], "regkey_deleted": [ "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupCollapseState", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ItemOrder", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ItemPos800x600x96(1)" ], "file_exists": [ "C:\\Users\\cuck\\Desktop", "C:\\Python27\\pythonw.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Program Files\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor", "C:\\Python27\\python.exe", "C:\\cuckoo_1788.ini", "C:\\Users\\Public", "C:\\Users", "C:\\Users\\cuck\\AppData\\Local\\Temp\\c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3.bin", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "C:\\Users\\cuck", "C:\\Program Files (x86)", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu", "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\ThumbCacheToDelete", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu", "C:\\Users\\Public\\Desktop", "C:\\cuckoo_2648.ini", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db", "C:\\cuckoo_1504.ini" ], "mutex": [ "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwReaderRefs", "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer", "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer", "Local\\Shell.CMruPidlList", "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer", "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer", "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit", "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer", "Global\\C::Users:cuck:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex" ], "file_failed": [ "C:\\cuckoo_1504.ini", "C:\\ProgramData\\Microsoft\\desktop.ini", "C:\\cuckoo_2648.ini", "C:\\Users\\cuck\\Desktop\\Belarc Advisor.lnk", "C:\\cuckoo_1788.ini", "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_32.db", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\desktop.ini" ], "guid": [ "{fdada2fa-894d-47d8-ae78-adf1fd7f28df}", "{00000003-0000-0000-c000-000000000046}", "{49f371e1-8c5c-4d9c-9a3b-54a6827f513c}", "{a4341687-7593-47aa-9554-4b0ffc8b2214}", "{688c934d-0c26-40f6-8d29-d56d72c76b48}", "{c0a6c367-c264-4385-a704-9088bdc3640e}", "{b2952b16-0e07-4e5a-b993-58c52cb94cae}", "{660b90c8-73a9-4b58-8cae-355b7f55341b}", "{54410b83-6787-4418-9735-5aaaabe83a9a}", "{42aedc87-2188-41fd-b9a3-0c966feabec1}", "{f6166dad-d3be-4ebd-8419-9b5ead8d0ec7}", "{00000000-0000-0000-c000-000000000046}", "{1c1800c1-3258-44c2-be80-3deadb6c5e39}", "{00000146-0000-0000-c000-000000000046}", "{cef04fdf-fe72-11d2-87a5-00c04f6837cf}", "{427fd3d4-f30a-4033-84ef-cbb1a955d9f7}", "{76765b11-3f95-4af2-ac9d-ea55d8994f1a}", "{6746c347-576b-4f73-9012-cdfeea251bc4}", "{2fb499a3-cfce-480f-a5f3-2453db7a2b7a}", "{00000323-0000-0000-c000-000000000046}", "{6e682784-1eca-4cf2-988d-96b6e89e9a4d}", "{75121952-e0d0-43e5-9380-1d80483acf72}", "{ab8902b4-09ca-4bb6-b78d-a8f59079a8d5}", "{dc8f8556-efbd-4efa-8b64-bba84b4ecd7f}", "{f676c15d-596a-4ce2-8234-33996f445db1}", "{46a6eeff-908e-4dc6-92a6-64be9177b41c}", "{50ef4544-ac9f-4a8e-b21b-8a26180db13f}", "{edb5f444-cb8d-445a-a523-ec5ab6ea33c7}" ], "file_read": [ "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\desktop.ini", "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "C:\\Users\\Public\\Desktop\\desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Tablet PC\\Desktop.ini", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "C:\\Users\\cuck\\Desktop\\desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\desktop.ini", "C:\\Users\\desktop.ini", "C:\\Windows\\win.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Accessibility\\Desktop.ini", "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\Desktop.ini", "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Games\\desktop.ini", "C:\\Users\\Public\\desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\System Tools\\Desktop.ini", "C:\\Program Files (x86)\\desktop.ini" ], "regkey_read": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4626147D107665540A84D43A5908E74D\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0A191B45599EEB74CA305184EA3C2A94\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features\\DefaultFeature", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Fvqrone.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F41A458014D57E54E8DBD0B0CBC361A2\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_MinMFU", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Flfgrz Gbbyf\\Cevingr Punenpgre Rqvgbe.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4486F7CE8F022FB4EB0154C5226C27A0\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\zvc.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\90860AAA7BD3DE34EB32330DD29CAD62\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\FavccvatGbby.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\qsethv.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F05C8358C56DAD54BB81D0A11DD52F41\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\rhqprqvg.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfNalgvzrHctenqrHV.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Erzbgr Qrfxgbc Pbaarpgvba.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{8NOQ94SO-R7Q6-84N6-N997-P918RQQR0NR5}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\StartMenu_Balloon_Time", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\InProcServer32\\ThreadingModel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\\SortOrderIndex", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\63B1AF366905AF641BA514CCBAE803C4\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Rirag Ivrjre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B06071FE021ECB04E8B3BF1E39AD5BB3\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Zbovyvgl Pragre.yax", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\SNTSearch.dll,-505", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CF65AB832507EDB4BB357F9D8E0431BD\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E85E64F0A7FC58E47A87E5AB98A6F2DD\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jbeqcnq.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9D22CD4619F5DBC499A083AAD70FE7B3\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7814D91294731FF4DBBB840810BEB3BB\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9DD74C0626DC33C479C1929714AB5295\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\MenuUserExpanded", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84BBAC70FB00B6046881B55CB3122F0F\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_TrackProgs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\InProcServer32\\InprocServer32", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\FbhaqErpbeqre.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\67C12EF40671B7342A2F990919031A57\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9BA984AD4F03E284382FFBB7A68BEE27\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{QNN168QR-4306-P8OP-8P11-O596240OQQRQ}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\002F6EFFA8A0A40498F3035BD153685A\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\FuncrPbyyrpgbe.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_PowerButtonAction", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragDelay", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\GnoGvc.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Vagrearg Rkcybere.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Jvaqbjf Sverjnyy jvgu Nqinaprq Frphevgl.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Fgvpxl Abgrf.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JSF.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\33AB3CD4D27277545B5A93CD4ECB96B4\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\efgehv.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\040E2A370D6DB2F45AE45A0032BC2179\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Znvagranapr\\Erzbgr Nffvfgnapr.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\SuppressionPolicy", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\mstsc.exe,-4000", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B690B72A999998C47B5F93C94A8D43B2\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\717591555BCB1604BA9777E8A55D0E41\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B04950B5EC5C924B8F428B5484A2720\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\InProcServer32\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\vFPFV Vavgvngbe.yax", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\FXSRESM.dll,-114", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zntavsl.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pzq.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\kcfepuij.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E40FDF839772BEB41AC977860DBB4853\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Cnvag.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{53123611-QN37-S8QN-SNP9-03R76QO9Q64Q}", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\displayswitch.exe,-320", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\ProfileImagePath", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_MinMFU", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Nalgvzr Hctenqr.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\ZqFpurq.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\Auto Update\\UAS\\UpdateCount", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9753E3A35E3BDFB468DF95B5D19C8A04\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Npprffvovyvgl\\Fcrrpu Erpbtavgvba.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_PowerButtonAction", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\VQYR (Clguba THV).yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Znvagranapr\\Perngr Erpbirel Qvfp.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\QIQ Znxre\\QIQZnxre.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Orynep Nqivfbe.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{15067OP1-P5N8-425R-37P6-SN0O891674S9}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\863CA21BBA4DFCE489FDF96EAB898616\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{Q4N262QQ-PR44-Q105-S36O-9Q77N8PO65N4}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1E82F31DC0D05AA4CB291B7BAA23FC8E\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Vagrearg Rkcybere (64-ovg).yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FBEAAA6C37E8AF24B87AAEA0047433BD\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D0CBB37A94C46943A90AC5008CF1CC9\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B4BBDDC88CEE4DD439E8BB261CE222A8\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E3DAE67887931944BCD7171908FA775\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Abgrcnq.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bmp\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pyrnazte.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE462B32EFD81040A184ED17E00452B\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\84C584688CFC74A4E9D36E5EE2E02FA7\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.FgvpxlAbgrf", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D5FD8239A83FE564F97379EA15CE8CB6\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\FavoritesChanges", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfCbjreFuryy\\i1.0\\CbjreFuryy_VFR.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Aneengbe.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0411990C889EE9B47BB0B5D356564877\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\EnableBalloonTips", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3C68656E520593A45925ADFB41F821B5\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pbzrkc.zfp", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollInset", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\bfx.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Cresbeznapr Zbavgbe.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\abgrcnq.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\qsethv.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\KCF Ivrjre.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ZrqvnCynlre32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\53F08364FFD17F14B8FD7CA7F52FAE76\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Gnfx Fpurqhyre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D3541DFF9B79C584284E8981624C04CB\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_NotifyNewApps", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Vagrearg Rkcybere.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\FavoritesRemovedChanges", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Zngu Vachg Cnary.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy VFR.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Zrqvn Cynlre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClearRecentDocsOnExit", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4514EC211C8947C4B9BA24F353AFFD50\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlot", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\SnippingTool.exe,-15051", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\OobeFldr.dll,-33056", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\Segoe UI", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\puneznc.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\285499F23409ED14FB4A01230F5DFA91\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Jvaqbjf AG\\Npprffbevrf\\jbeqcnq.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ErzbgrQrfxgbc", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewShadow", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.VagreargRkcybere.Qrsnhyg", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\UseOutOfProcHandlerCache", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\cevagznantrzrag.zfp", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\\Orynep\\OrynepNqivfbe\\OrynepNqivfbe.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8020CF43278B2644190F51544810251E\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7BF7ABF4D25C03F4582D4BC3082FB208\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Punenpgre Znc.yax", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\DefaultSecurity\\SrvsvcDefaultShareInfo", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Zrqvn Pragre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A7E9995902A24964C9C5D461E1C86F19\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A0256FF64030E0746A4AA95D3FFD0BE4\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C4040CC509FB0DC4886F590DDF6B6132\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf Snk naq Fpna.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8691BCC36FF121849A90B085BFAF5E5E\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy (k86).yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_TrackProgs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\E116C831A95AB5B4787CE3086FE83631\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FFFA6DF7EA9EDFC45A1F02FE6DF8F067\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Sharing\\UsersShareName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\FavoritesChanges", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\3D197E722531D614AB40C182904D9A31\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D38A6F5FC8262149A9FAAE8C621EE3F\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Jvaqbjf Rnfl Genafsre Ercbegf.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AlwaysShowMenus", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\A558E619ABC4CE5479C1DA5070EFBF81\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Fbhaq Erpbeqre.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zvtjvm\\zvtjvm.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\R7PS176R110P211O", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5\\TclTk", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95EE473833000D6409127D1B85882AC9\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0EF52818FCE3E7B488427C1F8266654E\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.TrggvatFgnegrq", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7C0477DE66D1A6749864FCE02A6DCB6C\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\586A8930D8DF3B6489614C37910BFCF5\\Features\\TclTk", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollDelay", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9F5ED6B416EF0A1448D94799D0FF20BA\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Flfgrz Pbasvthengvba.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{35786D3C-B075-49b9-88DD-029876E11C01}\\SuppressionPolicy", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{P1P6S8NP-40N3-0S5P-146S-65N9QP70OOO4}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\04C56B5D827A9194FA2CBFD014EAD0DA\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Paint.Picture\\CLSID\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Zntavsl.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flap Pragre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\965742E8F65116F4BB2CB01341464FA7\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zboflap.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\erpqvfp.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\73964AA699D5B5140ADC41ED3F7DB38A\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\P:\\Clguba27\\clguba.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\ArgCebw.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\EnableShareDenyNone", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0FD387D006FD9734FA65B249F36DE42A\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\D725CB8E57307E64EB574E04214D8B5F\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\DisableProcessIsolation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Paint.Picture\\IsShortcut", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\ArgjbexCebwrpgvba.yax", "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\PromotedIconCache", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\103857F24A2EDA54A800A41FA570861F\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{NN198O3P-PQ8P-7QR1-98Q1-O460S637193O}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewAlphaSelect", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollInterval", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_NotifyNewApps", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Jvaqbjf CbjreFuryy Zbqhyrf.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CE5B971A0DBB8FD4F83AE0DADC348104\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\qvfcynlfjvgpu.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\P:\\Hfref\\Choyvp\\Qrfxgbc\\Orynep Nqivfbe.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\\SuppressionPolicy", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Npprffvovyvgl\\Ba-Fperra Xrlobneq.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Cevag Znantrzrag.yax", "HKEY_CURRENT_USER\\Control Panel\\Desktop\\SmoothScroll", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\034A8F8E06031EF46BCB4C10469098E5\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AE5A0040C41ACA642AF6DB16F4D2F638\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-18\\ProfileImagePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\NoOplock", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\freivprf.zfp", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\FavoritesRemovedChanges", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\StartMenu_Balloon_Time", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\XpsRchVw.exe,-102", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Pbzchgre Znantrzrag.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\qvfcynlfjvgpu.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Favccvat Gbby.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{00021401-0000-0000-C000-000000000046}\\UseInProcHandlerCache", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\EEF8AA9EB45B5DB4BBE46B8634C910CD\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\95E2C34402A93A14FA8CB3420B85375C\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Jvaqbjf Rnfl Genafsre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FEB01D34D0F67E4F9CD810B432C1B91\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\\SuppressionPolicy", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_LargeMFUIcons", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Jvaqbjf Wbheany\\Wbheany.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8D04063BE69797D4D8505462827A0D19\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.VagreargRkcybere.64Ovg", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18F5DB38C45303843B06B1B5025E4820\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FF9FDEA72CD9DDC47A6DAB85F9F76B81\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU Size", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Installer\\Features\\586A8930D8DF3B6489614C37910BFCF5\\DefaultFeature", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\BE0BD5097A638224EB0DAAE870267F03\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfen.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{P804OON7-SN5S-POS7-8O55-2096R5S972PO}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zvtjvm\\cbfgzvt.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Pnyphyngbe.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\freivprf.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\FavoritesRemovedChanges", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Qvfx Pyrnahc.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\296744B7EBFEB2741A47781AE6E32269\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7FE547D6F0D72534A80F89C4AB727618\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Flfgrz Erfgber.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Sversbk.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Qngn Fbheprf (BQOP).yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\315C767EFC72D8445B1D2D16F72653F0\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\bqopnq32.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lnk\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Jvaqbjf Rkcybere.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CDBF699A8F2EAC2438564C3D50E9E638\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{7SR8Q22N-SO1Q-N8OR-01R3-6P8693961R6R}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 6", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\FuncrPbyyrpgbe.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F356843B045CC0A4BA0D83C1D85AAAFD\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\System.NamespaceCLSID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\62293D511DB84E5489074C5AFA18E882\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\C1EF68F348457B246A0AD0C18B3079AF\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lnk\\ShellEx\\{BB2E617C-0920-11D1-9A0B-00C04FC2D6C1}\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Frphevgl Pbasvthengvba Znantrzrag.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\7636A94AA21EDBB48B6AFFB17E5907B8\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{OO044OSQ-25O7-2SNN-22N8-6371N93R0456}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Zrzbel Qvntabfgvpf Gbby.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Jvaqbjf Rkcybere.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\vfpfvpcy.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\958C4A0DE6C8D5C428C6E9D875BC33B6\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\Clguba (pbzznaq yvar).yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Start_LargeMFUIcons", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F591EF48DE97A00428A5BC1AFFFAA868\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\8ECC347096FA78C4E8291F449F71E16E\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\\JvaqbjfCbjreFuryy\\i1.0\\CbjreFuryy_VFR.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jrypbzr Pragre.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Flfgrz Vasbezngvba.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\4FE19F224928A59468049F045950CB08\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\9E40FDB6330EBA242A4BD5F4FDD0B803\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\669C9DC1419C0F240B35B36B99AAB50C\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace\\DelegateFolders\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5E429E5BC27530F4786481EC687D9EC9\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\16AC40BE991DF1643B2800729063B2F9\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\lnkfile\\IsShortcut", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1C1ED53B8F25FD248955C15232E46886\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\ProfileImagePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\2FA90A429E82313489DAA2E2C2F0872C\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\TaskbarAnimations", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\\Npprffbevrf\\Pbzznaq Cebzcg.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\30FAECE2400494D4FB69207288EB5B73\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\0F4DC93AAA8AD1D448BC4E6A207F4FE0\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfpbasvt.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89DF671CDA74E9D4EB10275B10D5CF3F\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfcnvag.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Gnoyrg CP\\Jvaqbjf Wbheany.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\zfvasb32.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Jvaqbjf QIQ Znxre.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JvaqbjfCbjreFuryy\\i1.0\\cbjrefuryy.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\CB2182A03B6B11341A1F09A021991CE1\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\aneengbe.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\F21868A51A175874BB819DCA5FAA40A3\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{8NN47365-O2O3-1961-69RO-S866R376O12S}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\87C48B95924E3294FBC1766C9225DD0C\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\92F9143E715DEF045A539256438E41FB\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\1A0857155A8EF604FA5D1648CF382DC7\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Clguba 2.7\\Zbqhyr Qbpf.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pnyp.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.ZrqvnPragre", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Jvaqbjf CbjreFuryy\\Jvaqbjf CbjreFuryy VFR (k86).yax", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Gnfx Fpurqhyre.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\B1D5EA6004F809D48B117CE563261011\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\75B368B60C908BA4E87C31F66B02F3F0\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.NhgbTrarengrq.{OQ3S924R-55SO-N1ON-9QR6-O50S9S2460NP}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\5B5C8B2FB95B57147954C18085D53ACE\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragMinDist", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\18D84E9490A485948A17A1F02CDAA62A\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\11E2BA15171FE704B98E7505E58D7749\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Npprffbevrf\\Flfgrz Gbbyf\\Erfbhepr Zbavgbe.yax", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\895805CC90C04694887EF6BD140A622D\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\335F6F64CD461D9469519574D34757EB\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\FE056816E41FD2F4CACD03E7A2CA2E6E\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\AD21E12039BB3BC47B1938BC4ABDFEE2\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Sversbk.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\\rkcybere.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AlwaysShowMenus", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\\JvaqbjfCbjreFuryy\\i1.0\\cbjrefuryy.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\\Nqzvavfgengvir Gbbyf\\Pbzcbarag Freivprf.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\\Count\\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\\GnfxOne\\Jvaqbjf Zrqvn Cynlre.yax", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\JS.zfp", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\89BBBC8A0D32B014696C4BA3C20CDD34\\586A8930D8DF3B6489614C37910BFCF5", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Cache", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{6Q809377-6NS0-444O-8957-N3773S02200R}\\Pbzzba Svyrf\\Zvpebfbsg Funerq\\Vax\\GnoGvc.rkr", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\17E23EF6C775D324DB90E0E2B7D1CA72\\586A8930D8DF3B6489614C37910BFCF5" ], "regkey_written": [ "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts\\C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByKey:FMTID", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\IconSize", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\FFlags", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage\\NewShortcuts\\C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\Sort", "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\IconStreams", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ColInfo", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\ProgramsCache", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByDirection", "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\LanguageList", "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\LastAdvertisement", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\ShellBrowser\\ITBar7Layout", "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\PastIconsStream", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupView", "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\UserStartTime", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StuckRects2\\Settings", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByKey:PID", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\LogicalViewMode", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\Mode", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Streams\\Desktop\\TaskbarWinXP" ] }, "first_seen": 1574545996.202875, "ppid": 1740 }, { "process_path": "C:\\Windows\\System32\\lsass.exe", "process_name": "lsass.exe", "pid": 476, "summary": {}, "first_seen": 1574545988.3125, "ppid": 376 } ]
[ { "markcount": 4, "families": [], "description": "Queries for the computername", "severity": 1, "marks": [ { "call": { "category": "misc", "status": 1, "stacktrace": [], "api": "GetComputerNameW", "return_value": 1, "arguments": { "computer_name": "CUCKPC" }, "time": 1574545996.077625, "tid": 2436, "flags": {} }, "pid": 2740, "type": "call", "cid": 2924 }, { "call": { "category": "misc", "status": 1, "stacktrace": [], "api": "GetComputerNameW", "return_value": 1, "arguments": { "computer_name": "CUCKPC" }, "time": 1574545996.187625, "tid": 2436, "flags": {} }, "pid": 2740, "type": "call", "cid": 4135 }, { "call": { "category": "misc", "status": 1, "stacktrace": [], "api": "GetComputerNameW", "return_value": 1, "arguments": { "computer_name": "CUCKPC" }, "time": 1574545996.202625, "tid": 2436, "flags": {} }, "pid": 2740, "type": "call", "cid": 4315 }, { "call": { "category": "misc", "status": 1, "stacktrace": [], "api": "GetComputerNameW", "return_value": 1, "arguments": { "computer_name": "CUCKPC" }, "time": 1574545998.421875, "tid": 2808, "flags": {} }, "pid": 1788, "type": "call", "cid": 1592 } ], "references": [], "name": "antivm_queries_computername" }, { "markcount": 2, "families": [], "description": "Checks if process is being debugged by a debugger", "severity": 1, "marks": [ { "call": { "category": "system", "status": 0, "stacktrace": [], "last_error": 0, "nt_status": -1073741515, "api": "IsDebuggerPresent", "return_value": 0, "arguments": {}, "time": 1574545988.718625, "tid": 2436, "flags": {} }, "pid": 2740, "type": "call", "cid": 31 }, { "call": { "category": "system", "status": 0, "stacktrace": [], "last_error": 0, "nt_status": -1073741511, "api": "IsDebuggerPresent", "return_value": 0, "arguments": {}, "time": 1574546003.71875, "tid": 2508, "flags": {} }, "pid": 2648, "type": "call", "cid": 52 } ], "references": [], "name": "checks_debugger" }, { "markcount": 1, "families": [], "description": "Tries to locate where the browsers are installed", "severity": 1, "marks": [ { "category": "file", "ioc": "C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe", "type": "ioc", "description": null } ], "references": [], "name": "locates_browser" }, { "markcount": 1, "families": [], "description": "One or more processes crashed", "severity": 1, "marks": [ { "call": { "category": "__notification__", "status": 1, "stacktrace": [], "raw": [ "stacktrace" ], "api": "__exception__", "return_value": 0, "arguments": { "stacktrace": "0\nx\n2\nb\n8\n1\n9\n0\n4\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0", "registers": { "r14": 192924704, "r9": 0, "rcx": 48, "rsi": 192924704, "r10": 0, "rbx": 98185776, "rdi": 192924784, "r11": 192930608, "r8": 2006183236, "rdx": 8796092404304, "rbp": 192923472, "r15": 262145, "r12": 262144, "rsp": 192923352, "rax": 45619456, "r13": 237550496 }, "exception": { "instruction_r": "83 3d 8d d1 02 00 00 68 53 12 69 fb c7 44 24 04", "instruction": "cmp dword ptr [rip + 0x2d18d], 0", "exception_code": "0xc0000005", "symbol": "", "address": "0x2b81904" } }, "time": 1574546004.077875, "tid": 1296, "flags": {} }, "pid": 1788, "type": "call", "cid": 13296 } ], "references": [], "name": "raises_exception" }, { "markcount": 2, "families": [], "description": "Allocates read-write-execute memory (usually to unpack itself)", "severity": 2, "marks": [ { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 1504, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x70d85000" }, "time": 1574546002.327375, "tid": 2572, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 1504, "type": "call", "cid": 9 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 1504, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x73721000" }, "time": 1574546002.327375, "tid": 2572, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 1504, "type": "call", "cid": 64 } ], "references": [], "name": "allocates_rwx" }, { "markcount": 1, "families": [], "description": "Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation", "severity": 2, "marks": [ { "call": { "category": "misc", "status": 1, "stacktrace": [], "api": "GetDiskFreeSpaceExW", "return_value": 1, "arguments": { "root_path": "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer", "free_bytes_available": 23508131840, "total_number_of_free_bytes": 0, "total_number_of_bytes": 0 }, "time": 1574546001.171875, "tid": 2808, "flags": {} }, "pid": 1788, "type": "call", "cid": 4648 } ], "references": [], "name": "antivm_disk_size" }, { "markcount": 4, "families": [], "description": "Creates a shortcut to an executable file", "severity": 2, "marks": [ { "category": "file", "ioc": "C:\\Users\\Public\\Desktop\\Belarc Advisor.lnk", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Users\\cuck\\Desktop\\Belarc Advisor.lnk", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\Belarc Advisor.lnk", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Belarc Advisor.lnk", "type": "ioc", "description": null } ], "references": [], "name": "creates_shortcut" }, { "markcount": 3, "families": [], "description": "Drops an executable to the user AppData folder", "severity": 2, "marks": [ { "category": "file", "ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLF63F2.tmp", "type": "ioc", "description": null } ], "references": [], "name": "exe_appdata" }, { "markcount": 1, "families": [], "description": "Checks adapter addresses which can be used to detect virtual network interfaces", "severity": 2, "marks": [ { "call": { "category": "network", "status": 0, "stacktrace": [], "last_error": 0, "nt_status": -1073741772, "api": "GetAdaptersAddresses", "return_value": 111, "arguments": { "flags": 0, "family": 0 }, "time": 1574546005.65575, "tid": 3000, "flags": {} }, "pid": 2648, "type": "call", "cid": 1395 } ], "references": [], "name": "antivm_network_adapters" }, { "markcount": 2, "families": [], "description": "Checks for the Locally Unique Identifier on the system for a suspicious privilege", "severity": 2, "marks": [ { "call": { "category": "system", "status": 1, "stacktrace": [], "api": "LookupPrivilegeValueW", "return_value": 1, "arguments": { "system_name": "", "privilege_name": "SeShutdownPrivilege" }, "time": 1574546003.812875, "tid": 1828, "flags": {} }, "pid": 1788, "type": "call", "cid": 12931 }, { "call": { "category": "system", "status": 1, "stacktrace": [], "api": "LookupPrivilegeValueW", "return_value": 1, "arguments": { "system_name": "", "privilege_name": "SeShutdownPrivilege" }, "time": 1574546003.843875, "tid": 1828, "flags": {} }, "pid": 1788, "type": "call", "cid": 12960 } ], "references": [], "name": "privilege_luid_check" }, { "markcount": 9, "families": [], "description": "Queries for potentially installed applications", "severity": 2, "marks": [ { "call": { "category": "registry", "status": 0, "stacktrace": [], "last_error": 0, "nt_status": -1073741772, "api": "RegOpenKeyExA", "return_value": 2, "arguments": { "access": "0x00000001", "base_handle": "0x80000002", "key_handle": "0x00000000", "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "options": 0 }, "time": 1574545996.046625, "tid": 2436, "flags": {} }, "pid": 2740, "type": "call", "cid": 2704 }, { "call": { "category": "registry", "status": 1, "stacktrace": [], "api": "RegOpenKeyExA", "return_value": 0, "arguments": { "access": "0x00000001", "base_handle": "0x80000002", "key_handle": "0x00000178", "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "options": 0 }, "time": 1574545996.046625, "tid": 2436, "flags": {} }, "pid": 2740, "type": "call", "cid": 2711 }, { "call": { "category": "registry", "status": 1, "stacktrace": [], "api": "RegOpenKeyExA", "return_value": 0, "arguments": { "access": "0x00000001", "base_handle": "0x80000002", "key_handle": "0x00000178", "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "options": 0 }, "time": 1574545996.046625, "tid": 2436, "flags": {} }, "pid": 2740, "type": "call", "cid": 2720 }, { "call": { "category": "registry", "status": 1, "stacktrace": [], "api": "RegOpenKeyExA", "return_value": 0, "arguments": { "access": "0x00000001", "base_handle": "0x80000002", "key_handle": "0x00000178", "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "options": 0 }, "time": 1574545996.046625, "tid": 2436, "flags": {} }, "pid": 2740, "type": "call", "cid": 2729 }, { "call": { "category": "registry", "status": 1, "stacktrace": [], "api": "RegOpenKeyExA", "return_value": 0, "arguments": { "access": "0x00000001", "base_handle": "0x80000002", "key_handle": "0x00000178", "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "options": 0 }, "time": 1574545996.046625, "tid": 2436, "flags": {} }, "pid": 2740, "type": "call", "cid": 2738 }, { "call": { "category": "registry", "status": 1, "stacktrace": [], "api": "RegOpenKeyExA", "return_value": 0, "arguments": { "access": "0x00000001", "base_handle": "0x80000002", "key_handle": "0x00000178", "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "options": 0 }, "time": 1574545996.046625, "tid": 2436, "flags": {} }, "pid": 2740, "type": "call", "cid": 2747 }, { "call": { "category": "registry", "status": 1, "stacktrace": [], "api": "RegOpenKeyExA", "return_value": 0, "arguments": { "access": "0x00000001", "base_handle": "0x80000002", "key_handle": "0x00000178", "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "options": 0 }, "time": 1574545996.046625, "tid": 2436, "flags": {} }, "pid": 2740, "type": "call", "cid": 2756 }, { "call": { "category": "registry", "status": 1, "stacktrace": [], "api": "RegOpenKeyExA", "return_value": 0, "arguments": { "access": "0x00000001", "base_handle": "0x80000002", "key_handle": "0x00000178", "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "options": 0 }, "time": 1574545996.062625, "tid": 2436, "flags": {} }, "pid": 2740, "type": "call", "cid": 2765 }, { "call": { "category": "registry", "status": 1, "stacktrace": [], "api": "RegOpenKeyExA", "return_value": 0, "arguments": { "access": "0x00000001", "base_handle": "0x80000002", "key_handle": "0x00000178", "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Belarc Advisor", "options": 0 }, "time": 1574545996.062625, "tid": 2436, "flags": {} }, "pid": 2740, "type": "call", "cid": 2774 } ], "references": [], "name": "queries_programs" }, { "markcount": 2, "families": [], "description": "Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config", "severity": 3, "marks": [ { "call": { "category": "registry", "status": 1, "stacktrace": [], "api": "NtSetValueKey", "return_value": 0, "arguments": { "index": 0, "key_handle": "0x0000000000000f84", "value": "\u0014\u0000\u0000\u0000\u0005\u0000\u0000\u0000\u0001\u0000\u0001\u0000\u0010\u0000\u0000\u0000\u0014\u0000\u0000\u0000IL \u0006\u0010\u0000$\u0000\u0018\u0000\u0010\u0000\u0010\u0000\u00ff\u00ff\u00ff\u00ff!\u0010\u00ff\u00ff\u00ff\u00ff\u00ff\u00ff\u00ff\u00ffBM6\u0000\u0000\u0000\u0000\u0000\u0000\u00006\u0000\u0000\u0000(\u0000\u0000\u0000\u0010\u0000\u0000\u0000@\u0002\u0000\u0000\u0001\u0000 \u0000\u0000\u0000\u0000\u0000\u0000\u0090\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000", "reg_type": 3, "regkey": "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\PastIconsStream" }, "time": 1574545998.733875, "tid": 1828, "flags": { "reg_type": "REG_BINARY" } }, "pid": 1788, "type": "call", "cid": 1855 }, { "call": { "category": "registry", "status": 1, "stacktrace": [], "api": "NtSetValueKey", "return_value": 0, "arguments": { "index": 0, "key_handle": "0x00000000000001e0", "value": "\u0014\u0000\u0000\u0000\u0007\u0000\u0000\u0000\u0001\u0000\u0001\u0000\u0004\u0000\u0000\u0000\u0014\u0000\u0000\u0000{\u0000S\u00003\u00008\u0000O\u0000S\u00004\u00000\u00004\u0000-\u00001\u0000Q\u00004\u00003\u0000-\u00004\u00002\u0000S\u00002\u0000-\u00009\u00003\u00000\u00005\u0000-\u00006\u00007\u0000Q\u0000R\u00000\u0000O\u00002\u00008\u0000S\u0000P\u00002\u00003\u0000}\u0000\\\u0000r\u0000k\u0000c\u0000y\u0000b\u0000e\u0000r\u0000e\u0000.\u0000r\u0000k\u0000r\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000{\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0002\u0000\u0000\u0000\u00e3\u0007\u000b\u0000F\u0000b\u0000y\u0000i\u0000r\u0000 \u0000C\u0000P\u0000 \u0000v\u0000f\u0000f\u0000h\u0000r\u0000f\u0000:\u0000 \u00001\u0000 \u0000z\u0000r\u0000f\u0000f\u0000n\u0000t\u0000r\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u000e\u0000\u0000\u0000v\u00ae x\u00e3#)B\u0082\u00c1\u00e4\u001c\u00b6}[\u009c\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u00b3\u0086;4\u00e6\u00ee\u00d4\u0001\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\r !\u008f\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000{\u0000S\u00003\u00008\u0000O\u0000S\u00004\u00000\u00004\u0000-\u00001\u0000Q\u00004\u00003\u0000-\u00004\u00002\u0000S\u00002\u0000-\u00009\u00003\u00000\u00005\u0000-\u00006\u00007\u0000Q\u0000R\u00000\u0000O\u00002\u00008\u0000S\u0000P\u00002\u00003\u0000}\u0000\\\u0000r\u0000k\u0000c\u0000y\u0000b\u0000e\u0000r\u0000e\u0000.\u0000r\u0000k\u0000r\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000d\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0002\u0000\u0000\u0000\u00e3\u0007\u000b\u0000F\u0000c\u0000r\u0000n\u0000x\u0000r\u0000e\u0000f\u0000:\u0000 \u00006\u00007\u0000%\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u000f\u0000\u0000\u0000s\u00ae x\u00e3#)B\u0082\u00c1\u00e4\u001c\u00b6}[\u009c\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0086\u00e2\u009e\u00956\u0005\u00d4\u0001\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\r !\u008f\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0002\u0000\u0000\u0000{\u0000S\u00003\u00008\u0000O\u0000S\u00004\u00000\u00004\u0000-\u00001\u0000Q\u00004\u00003\u0000-\u00004\u00002\u0000S\u00002\u0000-\u00009\u00003\u00000\u00005\u0000-\u00006\u00007\u0000Q\u0000R\u00000\u0000O\u00002\u00008\u0000S\u0000P\u00002\u00003\u0000}\u0000\\\u0000r\u0000k\u0000c\u0000y\u0000b\u0000e\u0000r\u0000e\u0000.\u0000r\u0000k\u0000r\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000}\u00c0\u0000\u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u00e3\u0007\u000b\u0000H\u0000a\u0000v\u0000q\u0000r\u0000a\u0000g\u0000v\u0000s\u0000v\u0000r\u0000q\u0000 \u0000a\u0000r\u0000g\u0000j\u0000b\u0000e\u0000x\u0000 \u0000A\u0000b\u0000 \u0000V\u0000a\u0000g\u0000r\u0000e\u0000a\u0000r\u0000g\u0000 \u0000n\u0000p\u0000p\u0000r\u0000f\u0000f\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000", "reg_type": 3, "regkey": "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\IconStreams" }, "time": 1574545998.733875, "tid": 1828, "flags": { "reg_type": "REG_BINARY" } }, "pid": 1788, "type": "call", "cid": 1857 } ], "references": [], "name": "creates_largekey" }, { "markcount": 2, "families": [], "description": "Deletes executed files from disk", "severity": 3, "marks": [ { "category": "file", "ioc": "", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp", "type": "ioc", "description": null } ], "references": [], "name": "deletes_executed_files" }, { "markcount": 5, "families": [], "description": "Sets or modifies WPAD proxy autoconfiguration file for traffic interception", "severity": 3, "marks": [ { "call": { "category": "registry", "status": 1, "stacktrace": [], "api": "RegSetValueExA", "return_value": 0, "arguments": { "key_handle": "0x0000036c", "value": 1, "regkey_r": "WpadDecisionReason", "reg_type": 4, "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionReason" }, "time": 1574546008.20275, "tid": 3000, "flags": { "reg_type": "REG_DWORD" } }, "pid": 2648, "type": "call", "cid": 1408 }, { "call": { "category": "registry", "status": 1, "stacktrace": [], "api": "RegSetValueExA", "return_value": 0, "arguments": { "key_handle": "0x0000036c", "value": "\u00a0\u00be\u00d0`d\u00a2\u00d5\u0001", "regkey_r": "WpadDecisionTime", "reg_type": 3, "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionTime" }, "time": 1574546008.20275, "tid": 3000, "flags": { "reg_type": "REG_BINARY" } }, "pid": 2648, "type": "call", "cid": 1409 }, { "call": { "category": "registry", "status": 1, "stacktrace": [], "api": "RegSetValueExA", "return_value": 0, "arguments": { "key_handle": "0x0000036c", "value": 3, "regkey_r": "WpadDecision", "reg_type": 4, "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecision" }, "time": 1574546008.20275, "tid": 3000, "flags": { "reg_type": "REG_DWORD" } }, "pid": 2648, "type": "call", "cid": 1410 }, { "call": { "category": "registry", "status": 1, "stacktrace": [], "api": "RegSetValueExW", "return_value": 0, "arguments": { "key_handle": "0x0000036c", "value": "Unidentified network", "regkey_r": "WpadNetworkName", "reg_type": 1, "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadNetworkName" }, "time": 1574546008.20275, "tid": 3000, "flags": { "reg_type": "REG_SZ" } }, "pid": 2648, "type": "call", "cid": 1411 }, { "call": { "category": "registry", "status": 1, "stacktrace": [], "api": "RegSetValueExW", "return_value": 0, "arguments": { "key_handle": "0x00000368", "value": "{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}", "regkey_r": "WpadLastNetwork", "reg_type": 1, "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork" }, "time": 1574546008.21875, "tid": 3000, "flags": { "reg_type": "REG_SZ" } }, "pid": 2648, "type": "call", "cid": 1478 } ], "references": [], "name": "modifies_proxy_wpad" }, { "markcount": 133, "families": [], "description": "Deletes a large number of files from the system indicative of ransomware, wiper malware or system destruction", "severity": 3, "marks": [ { "category": "file", "ioc": "", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\USGCB - Windows 7,v2.0.5.1.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkHelp.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryUserNameNotes.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\BelarcAdvisor.exe", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDrives.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryVirtualMachineDetails.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeExternal.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s11.gif", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar1.gif", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\lock.gif", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLoginsFooter.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLC5826.tmp", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_tr.gif", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\black.gif", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLJ5837.tmp", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s16.gif", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\Advisor.ico", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\BenchmarkSummary.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s1.gif", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItemLinux.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s5.gif", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows Vista,v1.2.1.0.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\bar2.gif", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\corner_bl.gif", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s6.gif", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNet.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelAV_ok.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_s12.gif", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\Benchmarks\\FDCC - Windows XP,v1.2.1.0.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLanItem.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\shfs1.gif", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfe.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveHdr.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryDnsSuffix.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLan.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeRecentEmpty.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\~GLH0005.TMP", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryLicenseFormats.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryAntiVirus.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissing.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryNetworkDriveItem.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\no.gif", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\local\\images\\sp_unknown.gif", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeEmpty.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelCIS_ok.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SecurityPanelSU_ok.html", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\NPBelv32.dll", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\GLG63F1.tmp", "type": "ioc", "description": null }, { "category": "file", "ioc": "C:\\Program Files (x86)\\Belarc\\BelarcAdvisor\\System\\tpl\\SummaryQfeMissingItems.html", "type": "ioc", "description": null } ], "references": [], "name": "ransomware_mass_file_delete" }, { "markcount": 2, "families": [], "description": "Resumed a suspended thread in a remote process potentially indicative of process injection", "severity": 3, "marks": [ { "category": "Process injection", "ioc": "Process 2740 resumed a thread in remote process 2648", "type": "ioc", "description": null }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtResumeThread", "return_value": 0, "arguments": { "thread_handle": "0x000002ac", "suspend_count": 1, "process_identifier": 2648 }, "time": 1574546003.515625, "tid": 2184, "flags": {} }, "pid": 2740, "type": "call", "cid": 14742 } ], "references": [ "www.endgame.com\/blog\/technical-blog\/ten-process-injection-techniques-technical-survey-common-and-trending-process" ], "name": "injection_resumethread" } ]
The Yara rules did not detect anything in the file.
{ "tls": [], "udp": [ { "src": "192.168.56.101", "dst": "192.168.56.255", "offset": 662, "time": 6.215332984924316, "dport": 137, "sport": 137 }, { "src": "192.168.56.101", "dst": "192.168.56.255", "offset": 6638, "time": 12.214940071105957, "dport": 138, "sport": 138 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 8482, "time": 6.148574113845825, "dport": 5355, "sport": 51001 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 8810, "time": 4.179225921630859, "dport": 5355, "sport": 53595 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 9138, "time": 6.157196998596191, "dport": 5355, "sport": 53848 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 9466, "time": 4.689358949661255, "dport": 5355, "sport": 54255 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 9794, "time": 3.052528142929077, "dport": 5355, "sport": 55314 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 10122, "time": 22.277297973632812, "dport": 5355, "sport": 55880 }, { "src": "192.168.56.101", "dst": "239.255.255.250", "offset": 10442, "time": 4.683948040008545, "dport": 1900, "sport": 1900 }, { "src": "192.168.56.101", "dst": "239.255.255.250", "offset": 29852, "time": 4.1998131275177, "dport": 3702, "sport": 49152 }, { "src": "192.168.56.101", "dst": "239.255.255.250", "offset": 38236, "time": 6.2619030475616455, "dport": 1900, "sport": 53598 } ], "dns_servers": [], "http": [], "icmp": [], "smtp": [], "tcp": [], "smtp_ex": [], "mitm": [], "hosts": [], "pcap_sha256": "460b6ae10ccdebe4ea17ee75b5432b9543449e8a72450bc47b71a7c390a117b3", "dns": [], "http_ex": [], "domains": [], "dead_hosts": [], "sorted_pcap_sha256": "7e1fa178a2d639f836674b3812a0f2dd69c22d6803f8a955d0b5ccf7b516617a", "irc": [], "https_ex": [] }
advisorinstaller.exe (14 votes)
Property | Value |
---|---|
MD5 | cab5a5e41252cba2f0a736146c8a3504 |
SHA256 | c6b8573c9f0980f9d48dd2e625c726ffbeace4702ea98d53bf510144039f1fc3 |
These are some of the error messages that can appear related to advisorinstaller.exe:
advisorinstaller.exe has encountered a problem and needs to close. We are sorry for the inconvenience.
advisorinstaller.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.
Belarc Advisor Installer has stopped working.
End Program - advisorinstaller.exe. This program is not responding.
advisorinstaller.exe is not a valid Win32 application.
advisorinstaller.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.
To help other users, please let us know what you will do with the file:
If you feel that you need more information to determine if your should keep this file or remove it, please read this guide.
Hi, my name is Roger Karlsson. I've been running this website since 2006. I want to let you know about the FreeFixer program. FreeFixer is a freeware tool that analyzes your system and let you manually identify unwanted programs. Once you've identified some malware files, FreeFixer is pretty good at removing them. You can download FreeFixer here. It runs on Windows 2000/XP/2003/2008/2016/2019/Vista/7/8/8.1/10. Supports both 32- and 64-bit Windows.
If you have questions, feedback on FreeFixer or the freefixer.com website, need help analyzing FreeFixer's scan result or just want to say hello, please contact me. You can find my email address at the contact page.
Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.
I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.
No comments posted yet.