What is iron25072014.exe?

iron25072014.exe is part of and developed by according to the iron25072014.exe version information.

iron25072014.exe's description is " "

iron25072014.exe is digitally signed by STMSetup.

iron25072014.exe is usually located in the 'c:\downloads\' folder.

Some of the anti-virus scanners at VirusTotal detected iron25072014.exe.

If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.

Vendor and version information [?]

The following is the available information on iron25072014.exe:

PropertyValue
Product name
Company name
File description
CommentsThis installation was built with Inno Setup.
Legal copyright
Product version
File version

Here's a screenshot of the file properties when displayed by Windows Explorer:

Product name ..
Company name ..
File description ..
CommentsThis installation was built with Inn..
Legal copyright ..
Product version
File version

Digital signatures [?]

iron25072014.exe has a valid digital signature.

PropertyValue
Signer nameSTMSetup
Certificate issuer nameCOMODO Code Signing CA 2
Certificate serial number4cc8af2c057fc32a3fa7f44eaadd7eea

VirusTotal report

49 of the 73 anti-virus programs at VirusTotal detected the iron25072014.exe file. That's a 67% detection rate.

ScannerDetection Name
Alibaba AdWare:Win32/InstallCore.9d3073f2
Antiy-AVL GrayWare[Adware]/Win32.InstallCore.genb
APEX Malicious
Avast Win32:Adware-gen [Adw]
AVG Win32:Adware-gen [Adw]
Avira PUA/InstallCore.Gen9
Bkav W32.HfsAdware.F829
CAT-QuickHeal PUA.Stmsetup.Gen
Comodo Application.Win32.InstallCore.DIS@5j5psu
CrowdStrike win/malicious_confidence_100% (D)
Cylance Unsafe
Cyren W32/A-6c5f2e7b!Eldorado
DrWeb Trojan.InstallCore.1903
Emsisoft Application.InstallCore (A)
Endgame malicious (high confidence)
ESET-NOD32 Win32/InstallCore.Gen.A potentially unwanted
F-Prot W32/A-6c5f2e7b!Eldorado
F-Secure PotentialRisk.PUA/InstallCore.Gen9
FireEye Generic.mg.8a8092df66056fb7
Fortinet Riskware/InstallCore
GData Win32.Adware.InstallCore.FQ
Ikarus PUA.InstallCore
Invincea heuristic
Jiangmin Trojan.Heur2.ce
K7AntiVirus Unwanted-Program ( 004a9d551 )
K7GW Unwanted-Program ( 004a9d551 )
Kaspersky not-a-virus:HEUR:AdWare.Win32.DealPly.gen
Malwarebytes PUP.Optional.InstallCore
MAX malware (ai score=99)
MaxSecure Trojan.Malware.4653826.susgen
McAfee Artemis!8A8092DF6605
McAfee-GW-Edition Artemis
Microsoft PUA:Win32/InstallCore
NANO-Antivirus Virus.Win32.Gen.ccmw
Qihoo-360 Win32/Virus.Adware.f22
Rising PUF.InstallCore!1.AB2C (CLASSIC)
SentinelOne DFI - Malicious PE
Sophos Install Core Click run software (PUA)
Symantec PUA.InstallCore
Tencent Win32.Adware.Vosteran.Ecke
TrendMicro ADW_InstaCore
TrendMicro-HouseCall ADW_InstaCore
VBA32 Malware-Cryptor.InstallCore.gen
VIPRE InstallCore (fs)
ViRobot Adware.Installcore.718888
Webroot Pua.Adware.Gen
Yandex PUA.InstallCore!
Zillya Adware.AddLyricsCRT.Win32.618
ZoneAlarm not-a-virus:AdWare.Win32.DealPly.heur
49 of the 73 anti-virus programs detected the iron25072014.exe file.

Sandbox Report

The following information was gathered by executing the file inside Cuckoo Sandbox.

Summary

Successfully executed process in sandbox.

Summary

{
    "file_created": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\ie6_main.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close_Hover.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\button-bg.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg2.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Icon_Generic.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\checkbox.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg-corner.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\form.bmp.Mask",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\csshover3.htc",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\TR.locale",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button_Hover.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button_Hover.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\button.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\browse.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
    ],
    "directory_created": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\"
    ],
    "dll_loaded": [
        "IEFRAME.dll",
        "C:\\Windows\\System32\\mswsock.dll",
        "urlmon.dll",
        "mshtml.dll",
        "apphelp.dll",
        "gdi32.dll",
        "DNSAPI.dll",
        "SHELL32.dll",
        "kernel32.dll",
        "UxTheme.dll",
        "oleaut32.dll",
        "C:\\Windows\\system32\\ole32.dll",
        "dwmapi.dll",
        "C:\\Windows\\system32\\napinsp.dll",
        "ImgUtil.dll",
        "ntmarta.dll",
        "URLMON.DLL",
        "C:\\Windows\\system32\\Msimtf.dll",
        "API-MS-WIN-Service-Management-L1-1-0.dll",
        "VERSION.dll",
        "C:\\Windows\\syswow64\\MSCTF.dll",
        "KERNEL32.DLL",
        "API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
        "OLEAUT32.DLL",
        "RASMAN.DLL",
        "IPHLPAPI.DLL",
        "advapi32.dll",
        "comctl32",
        "ole32.dll",
        "comdlg32.dll",
        "API-MS-WIN-Service-winsvc-L1-1-0.dll",
        "olepro32.dll",
        "rtutils.dll",
        "version.dll",
        "C:\\Windows\\SysWOW64\\oleaut32.dll",
        "wininet.dll",
        "ADVAPI32.dll",
        "OLEAUT32.dll",
        "C:\\Windows\\system32\\pnrpnsp.dll",
        "DHCPCSVC.DLL",
        "C:\\Windows\\System32\\winrnr.dll",
        "API-MS-Win-Security-SDDL-L1-1-0.dll",
        "comctl32.dll",
        "WININET.dll",
        "Kernel32",
        "SXS.DLL",
        "MLANG.dll",
        "Kernel32.dll",
        "powrprof.dll",
        "shell32.dll",
        "rpcrt4.dll",
        "SETUPAPI.dll",
        "WS2_32.dll",
        "user32.dll"
    ],
    "file_opened": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
        "C:\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Internet Explorer\\MSIMGSIZ.DAT",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\ie6_main.css",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db",
        "C:\\Users\\cuck\\AppData\\Local\\Temp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
        "C:\\Users\\cuck\\AppData",
        "C:\\Windows\\SysWOW64\\ieframe.dll",
        "C:\\Users\\cuck\\AppData\\Local",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close_Hover.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
        "C:\\Users",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\button-bg.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg2.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Icon_Generic.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
        "\\\\?\\pipe\\0K1C1T1I1E1C1F1N1C1T1H_TEST",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\checkbox.css",
        "C:\\Users\\desktop.ini",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg-corner.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\form.bmp.Mask",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\csshover3.htc",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\TR.locale",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button_Hover.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button_Hover.png",
        "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\button.css",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db",
        "C:\\Users\\cuck",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\browse.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
    ],
    "command_line": [
        "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin\" \/_ShowProgress \/PrTxt:TG9hZGluZy4uLg=="
    ],
    "connects_host": [
        "rp.kralprogramcdn.com",
        "info.kralprogramcdn.com"
    ],
    "regkey_opened": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/pjpeg\\Bits",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\DnsClient",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/tiff\\Bits",
        "HKEY_CLASSES_ROOT\\Directory",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Main",
        "HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\about\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IEDDE_REGISTER_URLECHO",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Settings",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\DxTrans",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BROWSER_EMULATION",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\about",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced",
        "HKEY_CURRENT_USER\\SOFTWARE\\Classes\\PROTOCOLS\\Filter\\text\/html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IPERSISTMONIKER_LOAD_REDIRECTED_URL_KB976425",
        "HKEY_CURRENT_USER\\Software\\Policies",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\PageSetup",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\Rpc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Styles",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\ShellEx\\IconHandler",
        "HKEY_CLASSES_ROOT\\MIME\\Database\\Content Type",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001",
        "HKEY_CURRENT_USER\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\Clsid",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\TravelLog",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Ftp",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
        "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IEDDE_REGISTER_PROTOCOL",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Ftp",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\LSA\\AccessProviders",
        "HKEY_CLASSES_ROOT\\.png",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/jpeg\\Bits",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_ZONE_ELEVATION",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International",
        "HKEY_CURRENT_USER\\Software\\Borland\\Delphi\\Locales",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights",
        "HKEY_CLASSES_ROOT\\.css",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Services",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\MediaTypeClass",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ACTIVEX_INACTIVATE_MODE_REMOVAL_REVERT",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Services",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Zoom",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_MIME_SNIFFING",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Zones",
        "HKEY_CURRENT_USER\\Software\\Borland\\Locales",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\ActiveDesktop",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Recovery",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer",
        "HKEY_LOCAL_MACHINE\\Software",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1\\0",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\Clsid",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\ActiveX Compatibility",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1\\0\\win32",
        "HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\Explorer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SCRIPTURL_MITIGATION",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\DnsCache\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BINARY_CALLER_SERVICE_PROVIDER",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\ShellEx\\IconHandler",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Ranges\\",
        "HKEY_CLASSES_ROOT\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\InProcServer32",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/png\\Bits",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld",
        "HKEY_LOCAL_MACHINE\\System\\Setup",
        "HKEY_CLASSES_ROOT\\SystemFileAssociations\\.html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SHOW_FAILED_CONNECT_CONTENT_KB942615",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_READ_ZONE_STRINGS_FROM_REGISTRY",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
        "HKEY_CLASSES_ROOT\\FirefoxURL-E7CF176E110C211B\\shell\\open\\command",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ADDITIONAL_IE8_MEMORY_CLEANUP",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\BrowserEmulation",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\Feature_Enable_Compat_Logging",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Activities",
        "HKEY_CURRENT_USER\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}",
        "HKEY_CLASSES_ROOT\\SystemFileAssociations\\document",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD",
        "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler32",
        "HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\*\\",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Nls\\CodePage",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SUBDOWNLOAD_LOCKDOWN",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IGNORE_LEADING_FILE_SEPARATOR_IN_URI_KB933105",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\International\\Scripts",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Accepted Documents",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Ranges\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICTED_ZONE_WHEN_FILE_NOT_FOUND",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Restrictions",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\TravelLog",
        "HKEY_LOCAL_MACHINE\\Software\\Policies",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Control Panel",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\(Default)",
        "HKEY_CURRENT_USER\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OleAut",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Rpc",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProtocolDefaults\\",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Infodelivery\\Restrictions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
        "HKEY_CLASSES_ROOT\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\ShellFolder",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Main",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\BrowserEmulation",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Ratings",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_DOCUMENT_COMPATIBLE_MODE",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
        "HKEY_CLASSES_ROOT\\.html\\OpenWithProgids",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_WEBOC_DOCUMENT_ZOOM",
        "HKEY_CLASSES_ROOT\\FirefoxHTML-E7CF176E110C211B",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\Clsid",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\OpenWithProgids",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\IconHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SSLUX",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\%s",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BLOCK_LMZ_IMG",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Zoom",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_CUSTOM_IMAGE_MIME_TYPES_KB910561",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\Directory",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\DxTrans",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_XSSFILTER",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Zoom",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Wpad",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\System\\DNSClient",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\Adv AddrBar Spoof Detection",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
        "HKEY_CURRENT_USER\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}",
        "HKEY_CURRENT_USER\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\TreatAs",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Services",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap",
        "HKEY_CLASSES_ROOT\\Folder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_CLASSES_ROOT\\.gif",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\Adv AddrBar Spoof Detection",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-jg\\Bits",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LDAP",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\http\\UserChoice",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3050f819-98b5-11cf-bb82-00aa00bdce0b}",
        "HKEY_CURRENT_USER\\Software",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\ShellEx\\IconHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\MAIN",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\COM3",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Filter\\text\/html",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\ShellEx\\IconHandler",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\iexplore.exe",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LEGACY_DLCONTROL_BEHAVIORS",
        "HKEY_CLASSES_ROOT\\AllFilesystemObjects",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3050f4e1-98b5-11cf-bb82-00aa00bdce0b}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_SNIFFING",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Zoom",
        "HKEY_CURRENT_USER\\TypeLib",
        "HKEY_CURRENT_USER\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\about",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\CurVer",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SSLUX",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
        "HKEY_CLASSES_ROOT\\.html",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\Floppy Access",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-icon\\Bits",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\Clsid",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MANAGE_SCRIPT_CIRCULAR_REFS",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Infodelivery\\Restrictions",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\RASMANCS",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\Explorer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3050f4f5-98B5-11CF-BB82-00AA00BDCE0B}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-wmf\\Bits",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Connections",
        "HKEY_CLASSES_ROOT\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Applications\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\CurVer",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png\\Bits",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Low Rights",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Shell\\RegisteredApplications\\UrlAssociations\\Directory\\OpenWithProgids",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\ActiveX Compatibility\\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_Cross_Domain_Redirect_Mitigation",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/bmp\\Bits",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/gif\\Bits",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\Clsid",
        "HKEY_CURRENT_USER\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}",
        "HKEY_CLASSES_ROOT\\htmlfile",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Activities",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Activities",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Ranges\\",
        "HKEY_LOCAL_MACHINE\\Software\\Borland\\Locales",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MSHTML_AUTOLOAD_IEFRAME",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Restrictions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESPECT_OBJECTSAFETY_POLICY_KB905547",
        "HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\file\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_ZONE_ELEVATION",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_MIME_HANDLING"
    ],
    "resolves_host": [
        "wpad",
        "cuckpc"
    ],
    "file_written": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\ie6_main.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close_Hover.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\button-bg.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg2.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Icon_Generic.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\checkbox.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg-corner.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\form.bmp.Mask",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\csshover3.htc",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\TR.locale",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button_Hover.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button_Hover.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\button.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\browse.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
    ],
    "regkey_deleted": [
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
    ],
    "file_deleted": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
    ],
    "file_exists": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\",
        "C:\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft",
        "C:\\Users\\cuck\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css:Zone.Identifier",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\",
        "C:\\Users\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Internet Explorer",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css:Zone.Identifier",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html:Zone.Identifier",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\",
        "C:\\Users\\cuck\\AppData\\"
    ],
    "mutex": [
        "MSIMGSIZECacheMutex",
        "Local\\ZonesCounterMutex",
        "Local\\ZonesLockedCacheCounterMutex",
        "Local\\ZoneAttributeCacheCounterMutex",
        "IESQMMUTEX_0_208",
        "Local\\ZonesCacheCounterMutex"
    ],
    "file_failed": [
        "\\\\?\\pipe\\0K1C1T1I1E1C1F1N1C1T1H",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html"
    ],
    "guid": [
        "{275c23e2-3747-11d0-9fea-00aa003f8646}",
        "{6a01fda0-30df-11d0-b724-00aa006c1a01}",
        "{30c3b080-30fb-11d0-b724-00aa006c1a01}",
        "{dccfc164-2b38-11d2-b7ec-00c04f8f5d9a}",
        "{25336920-03f9-11cf-8fd0-00aa00686f13}",
        "{a3ccedf7-2de2-11d0-86f4-00a0c913f750}",
        "{dcb00c01-570f-4a9b-8d69-199fdba5723b}",
        "{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
        "{4ef17940-30e0-11d0-b724-00aa006c1a01}",
        "{6e89f8e2-9a2a-4797-9b91-41146bdf0e7b}",
        "{00000146-0000-0000-c000-000000000046}",
        "{6c736dc1-ab0d-11d0-a2ad-00a0c90f27e8}",
        "{d0074ffd-570f-4a9b-8d69-199fdba5723b}",
        "{a3ccedf3-2de2-11d0-86f4-00a0c913f750}",
        "{f414c260-6ac0-11cf-b6d1-00aa00bbbb58}",
        "{000214e6-0000-0000-c000-000000000046}",
        "{00000001-0000-0000-c000-000000000046}",
        "{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}",
        "{d9e89500-30fa-11d0-b724-00aa006c1a01}",
        "{00000323-0000-0000-c000-000000000046}",
        "{e7e4bc40-e76a-11ce-a9bb-00aa004ae837}",
        "{8856f961-340a-11d0-a96b-00c04fd705a2}",
        "{dcb00000-570f-4a9b-8d69-199fdba5723b}",
        "{50d5107a-d278-4871-8989-f4ceaaf59cfc}",
        "{bb1a2ae1-a4f9-11cf-8f20-00805f2cd064}",
        "{a47979d2-c419-11d9-a5b4-001185ad2b89}",
        "{00000112-0000-0000-c000-000000000046}",
        "{6c736db1-bd94-11d0-8a23-00aa00b58e10}",
        "{3050f406-98b5-11cf-bb82-00aa00bdce0b}",
        "{08c0e040-62d1-11d1-9326-0060b067b86e}",
        "{e569bde7-a8dc-47f3-893f-fd2b31b3eefd}"
    ],
    "file_read": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
        "C:\\Windows\\SysWOW64\\ieframe.dll",
        "C:\\Users\\desktop.ini",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
    ],
    "regkey_read": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\MaxRpcSize",
        "HKEY_CURRENT_USER\\.html\\Content Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector\\VML",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFileUrl",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEFontSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SUBDOWNLOAD_LOCKDOWN\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\FileDirectory",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoProxyDetectType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Domain",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableImprovedZoneCheck",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\RecommendedLevel",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\MinLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\Icon",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\UrlEncoding",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.gif\\Content Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableConsoleTracing",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableCachingOfSSLPages",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\XDomainRequest",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Display Inline Images",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\MinLevel",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Zoom\\ZoomDisabled",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\Flags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\about\\CLSID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\EnableFileTracing",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\IsTextPlainHonored",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png\\Image Filter CLSID",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEFixedFontName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Show image placeholders",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\InProcServer32\\LoadWithoutCOM",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\InProcServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONE_ELEVATION\\*",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights\\ProtectedModeOffForAllZones",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\AlwaysShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LEGACY_DLCONTROL_BEHAVIORS\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileTracingMask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\SmoothScroll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Use Stylesheets",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\Flags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\950",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\2106",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1201",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\TabProcGrowth",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldDllVersionLow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Always Use My Font Size",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\InprocServer32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/jpeg\\Bits\\0",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Enable AutoImageResize",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldDllVersionHigh",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\2500",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\CurrentLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoWebView",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.css\\Content Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2000",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\AcceptLanguage",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FrameTabWindow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\RecommendedLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/pjpeg\\Bits\\0",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2700",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\ProgramData",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LEGACY_DLCONTROL_BEHAVIORS\\*",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Move System Caret",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1\\0\\win32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\AdminTabProcs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\SessionMerging",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-wmf\\Bits\\0",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\RecommendedLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\ThreadingModel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Anchor Color Visited",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SSLUX\\*",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SeparateProcess",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\SecuritySafe",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_SNIFFING\\*",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldVersionHigh",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\COM+Enabled",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableCachingOfSSLPages",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\DOMStorage",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\2500",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2000",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\UrlEncoding",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\AlwaysShowExt",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\*",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Hostname",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\IEXPLORE.EXE\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\MiscFlags",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Services\\SelectionActivityButtonDisable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\UseHR",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\DOMStorage",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\SmartDithering",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\SessionMerging",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\2500",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Print_Background",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Force Offscreen Composition",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BLOCK_LMZ_IMG\\*",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\UrlEncoding",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\Icon",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Disable Script Debugger",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1400",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\XMLHTTP",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\CurrentLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\CurrentLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT\\*",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\RtfConverterFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileDirectory",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONE_ELEVATION\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\UseClearType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SSLUX\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\2500",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\Flags",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Play_Animations",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BROWSER_EMULATION\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\http\\UserChoice\\Progid",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FrameTabWindow",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Use Anchor Hover Color",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Default_CodePage",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldVersionLow",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\Default_IEFontSizePrivate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\EnableConsoleTracing",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_SNIFFING\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice\\Progid",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEFontSizePrivate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Anchor Color",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png\\Bits\\0",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
        "HKEY_CURRENT_USER\\.html\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\No3DBorder",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Print_Background",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History\\DaysToKeep",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2106",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\XDomainRequest",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugHeapFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\MaxFileSize",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\CurrentLevel",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Disable Visited Hyperlinks",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\*",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\MinLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\MinLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DontShowSuperHidden",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector\\WindowsEdition",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\MaxFileSize",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Expand Alt Text",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Play_Background_Sounds",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Display Inline Videos",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_XSSFILTER\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\ConsoleTracingMask",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableCachingOfSSLPages",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableFileTracing",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD\\*",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetCrawling",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Q300829",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\TabProcGrowth",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\OOBEInProgress",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Display Inline Videos",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\NoProtectedModeBanner",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AutoRecover",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\ConsoleTracingMask",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\No3DBorder",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragDelay",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\AdminTabProcs",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Always Use My Font Face",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.png\\Content Type",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2106",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\NavigationDelay",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Cryptography\\MachineGuid",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\2500",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\2500",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\RecommendedLevel",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MSHTML_AUTOLOAD_IEFRAME\\*",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFileMenu",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\CurrentLevel",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SmartDithering",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_XSSFILTER\\*",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\AutoDetect",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Anchor Underline",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\FileTracingMask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Page_Transitions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WarnOnIntranet",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1",
        "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\DocObject",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Use_DlgBox_Colors",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\*",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector\\IE",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClassicShell",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Allow Programmatic Cut_Copy_Paste",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2700",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\FTP\\Use Web Based FTP",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\2500",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\MachineGuid",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Page_Transitions",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\160A",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\DocObject",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\2500",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\DisableScriptDebuggerIE",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FrameMerging",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\Flags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Always Use My Colors",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Anchor Color Hover",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollInterval",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess",
        "HKEY_CURRENT_USER\\FirefoxURL-E7CF176E110C211B\\shell\\open\\command\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollInset",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\RecommendedLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Cleanup HTCs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SUBDOWNLOAD_LOCKDOWN\\*",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK\\*",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollDelay",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/bmp\\Bits\\0",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WarnOnIntranet",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WarnOnIntranet",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ComputerName\\ActiveComputerName\\ComputerName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\SmoothScroll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BROWSER_EMULATION\\*",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Show image placeholders",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1201",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MSHTML_AUTOLOAD_IEFRAME\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\MinLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/png\\Bits\\0",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FrameMerging",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Security_HKLM_only",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BLOCK_LMZ_IMG\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/gif\\Bits\\0",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\PageSetup\\Print_Background",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\Flags",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\UseThemes",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEPropFontName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSimpleStartMenu",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Enable AutoImageResize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\CSS_Compat",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\160A"
    ],
    "directory_enumerated": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\system.js",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\compatibility.js",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\wizard.js",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\i18n.js",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\package.js",
        "C:\\Windows\\System32\\ras\\*.pbk",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\tray.js",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\script\\main.js",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
        "C:\\Users\\cuck\\AppData",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\form.js",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\installer.js",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\logicBox.js",
        "C:\\Users",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\menu.js",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\webBrowser.js",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
        "C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\libs\\idp.js",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\utils.js",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\ui\\progressBar.js",
        "C:\\Users\\cuck\\AppData\\Local",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\debug.js",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\*.pbk",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\script\\flow.js",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\libs\\json2.js",
        "C:\\Users\\cuck",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\eventListener.js",
        "C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\*.pbk",
        "C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\adManager.js",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\application.js"
    ],
    "regkey_written": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableConsoleTracing",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionReason",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecision",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadNetworkName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableFileTracing",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\MaxFileSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileTracingMask",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionTime",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileDirectory",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\ConsoleTracingMask"
    ]
}

Dropped

[
    {
        "yara": [],
        "sha1": "51eac62cf77a0b88a3e9cb9ee6f85def21fd4bcf",
        "name": "14e064857751b23d_progress.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
        "type": "PNG image data, 4 x 10, 8-bit\/color RGB, non-interlaced",
        "sha256": "14e064857751b23da7bbe40861ef4caf99b2496227507b8e3108fbac6d901f75",
        "urls": [],
        "crc32": "E727EE98",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/14e064857751b23d_progress.png",
        "ssdeep": null,
        "size": 104,
        "sha512": "046ec179571d239bfb2d51be9837f96d9afebf2e5db77bba0f4a25ce8716d37581a3f9753bd2dbb04c47711699a9d93987bceb71df0b8becf8c577d660320069",
        "pids": [
            2436
        ],
        "md5": "35a600a752d3074501de31a516860499"
    },
    {
        "yara": [],
        "sha1": "489ec909c854bc2944413509a930986f1cc0b330",
        "name": "34225cce5a307b69_0294A8B9.log",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
        "type": "ASCII text, with no line terminators",
        "sha256": "34225cce5a307b690e9499ac20e6f2b621a8a95276a89692ccb3bb792970cc3d",
        "urls": [],
        "crc32": "3C5D5EB3",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/34225cce5a307b69_0294A8B9.log",
        "ssdeep": null,
        "size": 8,
        "sha512": "264194d460f12ff484b3296b77e43d60669cd82418d83187cfd74e8e36fc2a839d466613ca4d968de31913c30b130e1b4d8fce55868a8690230d16966c7a2890",
        "pids": [
            2436
        ],
        "md5": "0fbe6ac9c58283dad6a51aa9d21f3c02"
    },
    {
        "yara": [],
        "sha1": "d73b3bc67c9fe124768697cee7eec84c2b1eee4f",
        "name": "b28db98f2a6b06b6_close_hover.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close_Hover.png",
        "type": "PNG image data, 17 x 16, 8-bit\/color RGBA, non-interlaced",
        "sha256": "b28db98f2a6b06b6783b8fca6aabdcb89234d5bd4306fa71711988dba1fc71ea",
        "urls": [],
        "crc32": "4F170BAB",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/b28db98f2a6b06b6_close_hover.png",
        "ssdeep": null,
        "size": 207,
        "sha512": "511de8d97853457a37f89550f4b283ed69c05efdb7ce63657bc53b4e37ddf357577738be92da4bcd736d9c3c181c5ffc50b890c8cd5aa27099a87acf2c600fad",
        "pids": [
            2436
        ],
        "md5": "f5bdb3cabdc15580d97fa94aa3397c08"
    },
    {
        "yara": [],
        "sha1": "8652c46e2c3b32be118f3d9bcf30c3f000e11f0c",
        "name": "a0ff54eac40a24b1_0294A82C.log",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log",
        "type": "ASCII text, with no line terminators",
        "sha256": "a0ff54eac40a24b1731bac4bb9678725115435c605d40047454009d1dd1d88bd",
        "urls": [],
        "crc32": "A3B2BF67",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/a0ff54eac40a24b1_0294A82C.log",
        "ssdeep": null,
        "size": 8,
        "sha512": "bc263e0be2364d275f815c858ffcc75ccc1f4ca8eae6f27b98b6a26bd339a93b05e4325393a07268b1017485bf2bd2541f0ffd610b5ff4ae32909c004879e9d8",
        "pids": [
            2436
        ],
        "md5": "58b3f2790b9c6c88146492066bf49431"
    },
    {
        "yara": [],
        "sha1": "7563da7fa8845e65111e092fbc49be2c93a9f781",
        "name": "cf67489e041886a0_bg.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
        "type": "PNG image data, 646 x 504, 8-bit\/color RGB, non-interlaced",
        "sha256": "cf67489e041886a05568013927922bbae7e93f69a3597b92888ac4fadf8b8c7c",
        "urls": [],
        "crc32": "0B310A6D",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/cf67489e041886a0_bg.png",
        "ssdeep": null,
        "size": 3207,
        "sha512": "9bd1bada0549e10b8afa1bc4aa6218e3c10fdac7063d9ad4fc4e6ca70f9e842533e27697522ae0d1d848d2903c5ab2265d22f7685e612c7c425393dbf24e31c0",
        "pids": [
            2436
        ],
        "md5": "17285e115a289af21e95910c957bbabc"
    },
    {
        "yara": [],
        "sha1": "d141a79feb407506709f051e55c55438a12fd3b4",
        "name": "7bf800336671204d_pause_button.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
        "type": "PNG image data, 21 x 21, 8-bit\/color RGBA, non-interlaced",
        "sha256": "7bf800336671204de36b7d1f6ceffdff830040f51d21bc44f220f68d72cf492b",
        "urls": [],
        "crc32": "AC31F777",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/7bf800336671204d_pause_button.png",
        "ssdeep": null,
        "size": 577,
        "sha512": "3222cb5772a4e9b20de253914c0856c7e6383567df68fcf287801f6f79248f65957515e7ec4a44db1fbe910afeae8ca3349295c4bdf03df6aabde36f2aaa6b5e",
        "pids": [
            2436
        ],
        "md5": "84b37cb510f50c8fea812eb308d3f03f"
    },
    {
        "yara": [],
        "sha1": "13807a10369f7ff9ab3f9aba18135bccb98bec2d",
        "name": "974cd89e64bdaa85_progress-bar.css",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "974cd89e64bdaa85bf36ed2a50af266d245d781a8139f5b45d7c55a0b0841dda",
        "urls": [],
        "crc32": "AF154B27",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/974cd89e64bdaa85_progress-bar.css",
        "ssdeep": null,
        "size": 506,
        "sha512": "0d4e54d2ffe96ccf548097f7812e3608537b4dae9687816983fddfb73223c196159cc6a39fcdc000784c79b2ced878efbc7a5b5f6e057973bf25b128124510df",
        "pids": [
            2436
        ],
        "md5": "5335f1c12201b5f7cf5f8b4f5692e3d1"
    },
    {
        "yara": [],
        "sha1": "347f69357e225ab59d41a8dafe0732663a7e8c7e",
        "name": "ab4eeb3ea1eef4e8_progress-bg2.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg2.png",
        "type": "PNG image data, 20 x 26, 8-bit colormap, non-interlaced",
        "sha256": "ab4eeb3ea1eef4e84cb61eccb0ba0998b32108d70b3902df3619f4d9393f74c3",
        "urls": [],
        "crc32": "80C216FB",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/ab4eeb3ea1eef4e8_progress-bg2.png",
        "ssdeep": null,
        "size": 978,
        "sha512": "187b2103e7cf438840aa9bcbfde0800b1e8592eb6abf1d70367334a1969d21986154f34472f302512bf4971b29ed55500b2ad9d6d1ced3ae23ddacc5b7c61a00",
        "pids": [
            2436
        ],
        "md5": "b582d9a67bfe77d523ba825fd0b9dae3"
    },
    {
        "yara": [],
        "sha1": "1fb34409373b6ce2abee20d60947f1357f30e248",
        "name": "c1cf449536bc2778_progress-bg.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg.png",
        "type": "PNG image data, 19 x 22, 8-bit colormap, non-interlaced",
        "sha256": "c1cf449536bc2778e27348e45f0f53d04c284109199fb7a9af7a61016b91f8bc",
        "urls": [],
        "crc32": "81EF803E",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/c1cf449536bc2778_progress-bg.png",
        "ssdeep": null,
        "size": 1105,
        "sha512": "1b213f089da5502986da85f21673a522b36ceb4aec26bb1dffa809c58511056602cc0b99ab21ab206e2466928be0cdee7c7a95b39dc1183d8cfb529a22fe07c8",
        "pids": [
            2436
        ],
        "md5": "e9f12f92a9eeb8ebe911080721446687"
    },
    {
        "yara": [],
        "sha1": "a4bd01f828454f3619a815dbe5423b181ec4051c",
        "name": "f076773a6e3ae0f1_bootstrap_37556.html",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
        "type": "HTML document, ASCII text, with no line terminators",
        "sha256": "f076773a6e3ae0f1cee3c69232779a1aaaf05202db472040c0c8ea4a70af173a",
        "urls": [],
        "crc32": "CB024DFD",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/f076773a6e3ae0f1_bootstrap_37556.html",
        "ssdeep": null,
        "size": 156,
        "sha512": "965c10d2aa5312602153338da873e8866d2782e0cf633befe5a552b770e08abf47a4d2e007cdef7010c212ebcb9fefea5610c41c7ed1553440eaeab7ddd72daa",
        "pids": [
            2436
        ],
        "md5": "1ea9e5b417811379e874ad4870d5c51a"
    },
    {
        "yara": [],
        "sha1": "4b6876c6655cb3732a2218f89c9f170a32a820e7",
        "name": "83f15163a379cb5f_en.locale",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
        "type": "HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators",
        "sha256": "83f15163a379cb5f085e514406d4a40590a90594daf9d980d9ef455537f252b6",
        "urls": [],
        "crc32": "F035B9A2",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/83f15163a379cb5f_en.locale",
        "ssdeep": null,
        "size": 4038,
        "sha512": "e8cac92ababf18f9e3bcb329d6c4f57f28ebb5bbb808de43c3145b5366a1d3ce9543db7c1dacbea5abcadbbe21d108435004b316b32903712fc540ac7895f48f",
        "pids": [
            2436
        ],
        "md5": "5e2dde2c7d9c154bd3b1f6fd019e0ded"
    },
    {
        "yara": [],
        "sha1": "1d7757aebc836cf75b00c106741eb58a4f14fed5",
        "name": "86f2539351f57318_grey_button_hover.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button_Hover.png",
        "type": "PNG image data, 162 x 39, 8-bit\/color RGBA, non-interlaced",
        "sha256": "86f2539351f57318c65dc9936f49dee19a261540095e045b9c4c95be76cae143",
        "urls": [],
        "crc32": "1219B740",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/86f2539351f57318_grey_button_hover.png",
        "ssdeep": null,
        "size": 947,
        "sha512": "5d36e234672c61bd34809f105e05e95a4b13e3cda199884fb59c8bb629c80c0fb7b3f5b99df6df7dc310d48a87d39a6612e0ac3de79cd466eca5b423b75d3d8e",
        "pids": [
            2436
        ],
        "md5": "c92d77a8e40e884934d5e1ef355a3b82"
    },
    {
        "yara": [],
        "sha1": "787aeda3eee8053705fb208a6b399b8340820b82",
        "name": "6e6b964fd79b4a34_quick_specs.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
        "type": "PNG image data, 588 x 121, 2-bit colormap, non-interlaced",
        "sha256": "6e6b964fd79b4a3461f128e2ed145b9b641d108b8616695f36387661cae995bb",
        "urls": [],
        "crc32": "1DB62899",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/6e6b964fd79b4a34_quick_specs.png",
        "ssdeep": null,
        "size": 221,
        "sha512": "0159aca0c2a49393fd91acd4b6819217e67f8fd01e220297eb3e0fdd8132fad794fc317f5cc5e2b761d4123da71478b97df776908de6740eb6d54187c6c00754",
        "pids": [
            2436
        ],
        "md5": "07cd59b954e8495ad6cd6a7c11d2de86"
    },
    {
        "yara": [],
        "sha1": "8bd2699352da87d4d7c5d5c4698a0f90b2b6408d",
        "name": "63d6bd8e3e52c266_color_button_hover.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button_Hover.png",
        "type": "PNG image data, 162 x 39, 8-bit\/color RGBA, non-interlaced",
        "sha256": "63d6bd8e3e52c2665fbc1480eb2b27630b3c144e190d8cd5b094fc715d140e37",
        "urls": [],
        "crc32": "86342109",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/63d6bd8e3e52c266_color_button_hover.png",
        "ssdeep": null,
        "size": 1642,
        "sha512": "f1d59b28f11a24d8587cd2b0b0b09493e27d145aecfc6bef44adf0a7e453603e55c92f7ad41ec9208cb559a481eefa75814eca9052fadec9e4cae77bb2d4822a",
        "pids": [
            2436
        ],
        "md5": "507eb0a50680b1f332858f8547b8bf6e"
    },
    {
        "yara": [],
        "sha1": "233d056e36c35e752e8f7a4f5492e012ac7f5d58",
        "name": "5ef48a8c8c3771b4_browse.css",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\browse.css",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "5ef48a8c8c3771b4f233314d50dd3b5afdcd99dd4b74a9745c8fe7b22207056d",
        "urls": [],
        "crc32": "49459553",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/5ef48a8c8c3771b4_browse.css",
        "ssdeep": null,
        "size": 337,
        "sha512": "a62f805768d8aab4a773a2d5b480ad71e5b88b94af9eed8a7855caee0bfbcfce8a0bbad5de07a3b918f1da18f8e67ff961be575c000b64ce7ef5bee9292d2407",
        "pids": [
            2436
        ],
        "md5": "6009d6e864f60aea980a9df94c1f7e1c"
    },
    {
        "yara": [],
        "sha1": "bf228a3af2fd2e1c90eb9fa28c305ec2e94c837b",
        "name": "98def3a2f0343a87_tr.locale",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\TR.locale",
        "type": "HTML document, UTF-8 Unicode text, with very long lines, with CRLF line terminators",
        "sha256": "98def3a2f0343a87af3fa60b54476ebdec5ef805d4250c1df263604baf076d80",
        "urls": [],
        "crc32": "FEA8DEA5",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/98def3a2f0343a87_tr.locale",
        "ssdeep": null,
        "size": 4351,
        "sha512": "6b020c74b238433a6fb5034353f69a3a8ee04f96367f83eba0835c5936830b3a73e1c402468bb9145e3489bc35f1617c48bd2f05d6a07559320bc3274270861b",
        "pids": [
            2436
        ],
        "md5": "a9d0bfabe018ced0aaa315dcaeb68ff7"
    },
    {
        "yara": [],
        "sha1": "2075181a18827b789a9e85b116b192250e72b991",
        "name": "ffe7f4a3405c31af_color_button.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
        "type": "PNG image data, 162 x 39, 8-bit\/color RGBA, non-interlaced",
        "sha256": "ffe7f4a3405c31afecb32c66609bcab022d6ddf7ff6de3c6560166cc42037943",
        "urls": [],
        "crc32": "D1E263C0",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/ffe7f4a3405c31af_color_button.png",
        "ssdeep": null,
        "size": 1157,
        "sha512": "03e785062c31a5aa8570a8d210be2d47c396b4a067a869a3dd876b147a0cf499bbc6c3a8b1424937cec693707fdfa543965bb5500e44284b6a5000470bc4342f",
        "pids": [
            2436
        ],
        "md5": "c706108c7982dc4bad4accd00dbd4743"
    },
    {
        "yara": [],
        "sha1": "3a9a1ba234e613e5f808c3ffeda05a10a5dafe00",
        "name": "8d46eb0c60043dcb_sponsored.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
        "type": "PNG image data, 137 x 40, 8-bit\/color RGBA, non-interlaced",
        "sha256": "8d46eb0c60043dcb7d79ab3d0525148fc901764620c02e4b9c5dd8b0e9026303",
        "urls": [
            "http:\/\/ns.adobe.com\/xap\/1.0\/mm\/",
            "http:\/\/ns.adobe.com\/xap\/1.0\/",
            "http:\/\/ns.adobe.com\/xap\/1.0\/sType\/ResourceRef"
        ],
        "crc32": "40BB3269",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/8d46eb0c60043dcb_sponsored.png",
        "ssdeep": null,
        "size": 2082,
        "sha512": "e891552bee3aa10247cad1fcc510331077016a6e71d46827be2dd46017f943c5acc2c1506b41217880d35d52a94989923ad0a345f8791da4bb379eceefe3c407",
        "pids": [
            2436
        ],
        "md5": "e3758d529f93fee4807f5ea95fbc1a6c"
    },
    {
        "yara": [],
        "sha1": "2974f4bf37231205a256f2648189a461e74869c0",
        "name": "476a7b1085cc64de_loader.gif",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
        "type": "GIF image data, version 89a, 220 x 19",
        "sha256": "476a7b1085cc64de1c0eb74a6776fa8385d57eb18774f199df83fc4d7bbcc24e",
        "urls": [],
        "crc32": "2F7B5638",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/476a7b1085cc64de_loader.gif",
        "ssdeep": null,
        "size": 10819,
        "sha512": "2d50b9095d06ffd15eeeccf0eb438026ca8d09ba57141fed87a60edd2384e2139320fb5539144a2f16de885c49b0919a93690974f32b73654debca01d9d7d55c",
        "pids": [
            2436
        ],
        "md5": "57ca1a2085d82f0574e3ef740b9a5ead"
    },
    {
        "yara": [],
        "sha1": "91642b0d16021c0e2082b74f712a6cb4803ef4d7",
        "name": "e10d3217a8827abb_grey_button.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
        "type": "PNG image data, 162 x 39, 8-bit\/color RGBA, non-interlaced",
        "sha256": "e10d3217a8827abbd8d80b67fb34e31ca23be889a3628f8444a12e28e89ff916",
        "urls": [],
        "crc32": "3ADCA336",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/e10d3217a8827abb_grey_button.png",
        "ssdeep": null,
        "size": 478,
        "sha512": "bfccdf014c35aec8164cb4e098762531e51ce7c9313bc4adf086b888c744e09e8d40407102b4e642dcf2feceec6405abd60eea1034120ff19b7c7f4b231a24ea",
        "pids": [
            2436
        ],
        "md5": "c6664fd9c243aa6e40ea1aa8a9deccf9"
    },
    {
        "yara": [],
        "sha1": "2931e65dc245e567dd3c50f8a02ab419ddb4795c",
        "name": "03acfb58c4b49bfa_main.css",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "03acfb58c4b49bfa4116897754b2e0a763005dce24a36fd377dd79303dd6bb95",
        "urls": [],
        "crc32": "C59A87F1",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/03acfb58c4b49bfa_main.css",
        "ssdeep": null,
        "size": 8288,
        "sha512": "02fdc8837217b3ea43fe64a0dbfb0743386ee66467fe746d46ae3a133e70863e54144ed8c3603e8545464138aff1079b3156b29c7c060a9e7fca9b4032df5b26",
        "pids": [
            2436
        ],
        "md5": "3008e794273b2875b13521c7e495fcbc"
    },
    {
        "yara": [],
        "sha1": "cdee967961a3ea87565ae7ca287be8ed20496160",
        "name": "f638cc042b7ade6f_close.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
        "type": "PNG image data, 17 x 16, 8-bit\/color RGBA, non-interlaced",
        "sha256": "f638cc042b7ade6f43f2faf0077e020137562e559178396b7e975db39ac13df6",
        "urls": [],
        "crc32": "6408D24F",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/f638cc042b7ade6f_close.png",
        "ssdeep": null,
        "size": 207,
        "sha512": "db52224964ffd03fa65fddabea29d4f7c23840a18d1ad1028f228589c8c642280a762d2f4250159106f911455b8f0706a3b204dcbbb0484638d4f41f4f54a836",
        "pids": [
            2436
        ],
        "md5": "c222a4f3d309721c0898606960120266"
    },
    {
        "yara": [],
        "sha1": "4ec405f2668d5d93260525ad916abafa2414cb72",
        "name": "8e806f5b94fc294e_button.css",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\button.css",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "8e806f5b94fc294e918503c8053ef1284e4f4b1e02c7da4f4635e33ec33e0534",
        "urls": [],
        "crc32": "7DF9208E",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/8e806f5b94fc294e_button.css",
        "ssdeep": null,
        "size": 417,
        "sha512": "1a8a27a92abe35edaa2c950b130579c92f0d0d87b09971843c39569cf06d407b8e896751e73452676bfad45a363f0b6dd00cb6c5faf33966880539e106b19f94",
        "pids": [
            2436
        ],
        "md5": "37e1ff96e084ec201f0d95feef4d5e94"
    },
    {
        "yara": [],
        "sha1": "0b2769433e73e3c6c677a5c7294a9a2f45cb8a64",
        "name": "e37e99ddfc73ac7b_csshover3.htc",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\csshover3.htc",
        "type": "HTML document, ASCII text, with very long lines, with CRLF line terminators",
        "sha256": "e37e99ddfc73ac7ba774e23736b2ef429d9a0cb8c906453c75b14c029bdd5493",
        "urls": [
            "http:\/\/www.xs4all.nl\/",
            "http:\/\/creativecommons.org\/licenses\/LGPL\/2.1"
        ],
        "crc32": "3030E7E7",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/e37e99ddfc73ac7b_csshover3.htc",
        "ssdeep": null,
        "size": 2893,
        "sha512": "fff97c9f5954dac6477d619382fe30a4d625027a709b9d8b30e6524d31df35d9bd3c122cd501f785a18a65e998a2afb5220d5fe482a27d0b81a40baa6c9565da",
        "pids": [
            2436
        ],
        "md5": "52fa0da50bf4b27ee625c80d36c67941"
    },
    {
        "yara": [],
        "sha1": "a1615c118fbfa49253d98185eae283f26ea392d7",
        "name": "2693930c474fe640_button-bg.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\button-bg.png",
        "type": "PNG image data, 5 x 22, 8-bit\/color RGB, non-interlaced",
        "sha256": "2693930c474fe640e2fe8d6ef98abe2ecd303d2392c3d8b2e006e8942ba8f534",
        "urls": [],
        "crc32": "55349B32",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/2693930c474fe640_button-bg.png",
        "ssdeep": null,
        "size": 131,
        "sha512": "6529c2602a88139f44534c70bc41f02a3a99cda666cd9d2be5e3f1fb45bb2c9b288cf7eb4636070713787017e108b7c353983c7a7f5ff213a8dcfc5d780df945",
        "pids": [
            2436
        ],
        "md5": "98b1de48dfa64dc2aa1e52facfbee3b0"
    },
    {
        "yara": [],
        "sha1": "2dab653eb20be72b034a38dc1fcebbd18f079c86",
        "name": "9216d98a6574dfad_default_wi.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
        "type": "PNG image data, 629 x 142, 8-bit colormap, non-interlaced",
        "sha256": "9216d98a6574dfadacdc8321dc435454cb72c589b3ee8326a9b946966f756d7f",
        "urls": [
            "http:\/\/ns.adobe.com\/xap\/1.0\/mm\/",
            "http:\/\/ns.adobe.com\/xap\/1.0\/",
            "http:\/\/ns.adobe.com\/xap\/1.0\/sType\/ResourceRef"
        ],
        "crc32": "59778B45",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/9216d98a6574dfad_default_wi.png",
        "ssdeep": null,
        "size": 28178,
        "sha512": "25575fea9abb1491b5a5853244a9b655ce05f64d98f4b79134674f2d9a560a5af405c1783c9da4a07cfb38b51d060c7a70890c70df6c1c8f4b01e041aa4f649f",
        "pids": [
            2436
        ],
        "md5": "1cc2677e3e29e45e538985839cff2b42"
    },
    {
        "yara": [],
        "sha1": "adc23b97959b979927f5c7646ca407292566f2a5",
        "name": "27dd029405cbfb0c_form.bmp.mask",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\form.bmp.Mask",
        "type": "SysEx File -",
        "sha256": "27dd029405cbfb0c3bf8bac517be5db9aa83e981b1dc2bd5c5d6c549fa514101",
        "urls": [],
        "crc32": "DEC035D1",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/27dd029405cbfb0c_form.bmp.mask",
        "ssdeep": null,
        "size": 244,
        "sha512": "50ec40ef5795f57a8356e657aaa1708acb93354b6d6ef0319805cea5facf397f45d4e9896942bc49cb0a9a86dd6772a9dd3c27cce50a184e7e6559bf05a44274",
        "pids": [
            2436
        ],
        "md5": "d2fc989f9c2043cd32332ec0fad69c70"
    },
    {
        "yara": [],
        "sha1": "a5ee1d55de2cc60966039120c830fc19cefb0351",
        "name": "717f3f02f5d5fd14_progressbar.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
        "type": "PNG image data, 525 x 21, 8-bit\/color RGBA, non-interlaced",
        "sha256": "717f3f02f5d5fd1478b6d2ec44acef6e70bb8f1adcf2dc030c08b92e851737e1",
        "urls": [],
        "crc32": "55C9D5EA",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/717f3f02f5d5fd14_progressbar.png",
        "ssdeep": null,
        "size": 812,
        "sha512": "d232072c9540bf0e2fd56f353c2cc83518eabf8282cc02d9f8bec81c0341287ada29ba79f2a515d68722658686b6cce97be138a48f44409562d9a567af200bd6",
        "pids": [
            2436
        ],
        "md5": "eabb61abba55f80af418fa1128d1548d"
    },
    {
        "yara": [],
        "sha1": "98f4c693af708e02201de2aee31fe094dc3b0a9c",
        "name": "e466a2db2f755d9e_resume_button.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
        "type": "PNG image data, 21 x 21, 8-bit\/color RGBA, non-interlaced",
        "sha256": "e466a2db2f755d9eb68619439af37ff4e45559b7a3f476e226ab2a11aeadae1a",
        "urls": [],
        "crc32": "8B8EE214",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/e466a2db2f755d9e_resume_button.png",
        "ssdeep": null,
        "size": 718,
        "sha512": "9ddaaad53375f4d2874fe5c98b6782202d2bd975cdd9363796986dc7567368b94d9ec1aa3e839194097838b787bbd71d574540cf5b04fd04f10fa80d6a89e695",
        "pids": [
            2436
        ],
        "md5": "9d31583bcfad58a6b9ddeaf44549a5e6"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "Matched shellcode byte patterns",
                    "author": "nex"
                },
                "name": "shellcode",
                "offsets": {
                    "shell2": [
                        [
                            16100,
                            0
                        ]
                    ]
                },
                "strings": [
                    "ZKEw"
                ]
            }
        ],
        "sha1": "6e3a721aef65625bf99b639800476150d262dd4b",
        "name": "87af4027e8f89459_default_tb.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
        "type": "PNG image data, 630 x 117, 8-bit colormap, non-interlaced",
        "sha256": "87af4027e8f89459463bdd73df7b928b883eefb20514159d3a1a4be0d39e00c0",
        "urls": [
            "http:\/\/ns.adobe.com\/xap\/1.0\/mm\/",
            "http:\/\/ns.adobe.com\/xap\/1.0\/",
            "http:\/\/ns.adobe.com\/xap\/1.0\/sType\/ResourceRef"
        ],
        "crc32": "366777FA",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/87af4027e8f89459_default_tb.png",
        "ssdeep": null,
        "size": 19494,
        "sha512": "1efcf8af09cf857b3850cec43a88fc8c0992e3b04f78ad2c71b84c2ac7775e745df211582694588b29217aefb1ae02b29b94c2cfe52b5d32bdafb9dce73b9920",
        "pids": [
            2436
        ],
        "md5": "70e70599d4b853df0f12f6cb0e04695f"
    },
    {
        "yara": [],
        "sha1": "50f84ef8331341b48981af82313b146863eba526",
        "name": "b09504c1bf0486d3_checkbox.css",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\checkbox.css",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "b09504c1bf0486d3ec46500592b178a3a6c39284672af8815c3687cc3d29560d",
        "urls": [],
        "crc32": "19F79D2C",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/b09504c1bf0486d3_checkbox.css",
        "ssdeep": null,
        "size": 190,
        "sha512": "03e96bef74c0b3a31124c3d3c1bb78af1053a8719ca373c6b9316d63bac9545c1f4ecc2d747eb64341d8da31bc0f23da094e19c3e07ed46f65c28dc88e13bd3a",
        "pids": [
            2436
        ],
        "md5": "64773c6b0e3413c81aebc46cce8c9318"
    },
    {
        "yara": [],
        "sha1": "a00692b5a73c035da31aa5a285202cd117118290",
        "name": "dccfb478e6097086_icon_generic.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Icon_Generic.png",
        "type": "PNG image data, 34 x 32, 8-bit\/color RGBA, non-interlaced",
        "sha256": "dccfb478e6097086d886b5a01d120bf511b381982b0975e0c65eab3846e4234d",
        "urls": [],
        "crc32": "376898B4",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/dccfb478e6097086_icon_generic.png",
        "ssdeep": null,
        "size": 1906,
        "sha512": "1bd9612dc93217f1341764d1a4f917da8af338649772a41ae89798b5db7cc9bd9c6ec78b7a34945d3d0885b929bf7ae696a865dd50e4fb332ff3ca77bd84d629",
        "pids": [
            2436
        ],
        "md5": "a35aeb077ffa7ffb4382c639743d29cc"
    },
    {
        "yara": [],
        "sha1": "e792ed3676746fe81b1b93ec6c11c7b27a121c96",
        "name": "378c6b06f8c9a905_ie6_main.css",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\ie6_main.css",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "378c6b06f8c9a90540c61383b7250bc4df34f5547af4d96ddce717c3683c62d8",
        "urls": [],
        "crc32": "1DA8CD56",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/378c6b06f8c9a905_ie6_main.css",
        "ssdeep": null,
        "size": 1934,
        "sha512": "44556be46e32f9db923861f75309ea0cba579478524fa43b8eb4b9426b8a36a743ac62f671a1e9694a94ab27006f5e472b9367b47aaf88e2d87709fd4b243b7a",
        "pids": [
            2436
        ],
        "md5": "5fa9587859aea5525ad5461d188c169a"
    },
    {
        "yara": [],
        "sha1": "3bf74d0ac61083e97cf3ebd07d86a8f4fed1885b",
        "name": "86b6e6826bcde295_progress-bg-corner.png",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg-corner.png",
        "type": "PNG image data, 22 x 26, 8-bit\/color RGB, non-interlaced",
        "sha256": "86b6e6826bcde2955d64d4600a4e01693522c1fddf156ce31c4ba45b3653a7bd",
        "urls": [],
        "crc32": "F0FDCDCB",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/86b6e6826bcde295_progress-bg-corner.png",
        "ssdeep": null,
        "size": 1636,
        "sha512": "4ca9b7c5d3a2a87d3ec7e24c96e5a06e0c1390e993d51e8509f6dbcbd709064e476196c6ed5059e7fafa10ad258071e769feed91b890a010c9662804efd15787",
        "pids": [
            2436
        ],
        "md5": "608f1f20cd6ca9936eaa7e8c14f366be"
    }
]

Generic

[
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "process_name": "a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "pid": 816,
        "summary": {
            "file_opened": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
            ],
            "regkey_opened": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
                "HKEY_CURRENT_USER\\Software\\Borland\\Delphi\\Locales",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Borland\\Locales",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
                "HKEY_LOCAL_MACHINE\\Software\\Borland\\Locales",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}"
            ],
            "file_read": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin"
            ],
            "regkey_read": [
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugHeapFlags",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableImprovedZoneCheck",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Security_HKLM_only"
            ],
            "dll_loaded": [
                "gdi32.dll",
                "kernel32.dll",
                "UxTheme.dll",
                "oleaut32.dll",
                "C:\\Windows\\system32\\ole32.dll",
                "dwmapi.dll",
                "URLMON.DLL",
                "C:\\Windows\\syswow64\\MSCTF.dll",
                "KERNEL32.DLL",
                "OLEAUT32.DLL",
                "advapi32.dll",
                "comctl32",
                "ole32.dll",
                "comdlg32.dll",
                "olepro32.dll",
                "version.dll",
                "wininet.dll",
                "comctl32.dll",
                "Kernel32",
                "Kernel32.dll",
                "shell32.dll",
                "user32.dll"
            ]
        },
        "first_seen": 1562575988.0619,
        "ppid": 2436
    },
    {
        "process_path": "C:\\Windows\\System32\\lsass.exe",
        "process_name": "lsass.exe",
        "pid": 476,
        "summary": {},
        "first_seen": 1562575985.3438,
        "ppid": 376
    },
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "process_name": "a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
        "pid": 2436,
        "summary": {
            "file_created": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\ie6_main.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close_Hover.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\button-bg.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg2.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Icon_Generic.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\checkbox.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg-corner.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\form.bmp.Mask",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\csshover3.htc",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\TR.locale",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button_Hover.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button_Hover.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\button.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\browse.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
            ],
            "directory_created": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\"
            ],
            "dll_loaded": [
                "IEFRAME.dll",
                "C:\\Windows\\System32\\mswsock.dll",
                "urlmon.dll",
                "mshtml.dll",
                "apphelp.dll",
                "gdi32.dll",
                "DNSAPI.dll",
                "SHELL32.dll",
                "kernel32.dll",
                "UxTheme.dll",
                "oleaut32.dll",
                "C:\\Windows\\system32\\ole32.dll",
                "dwmapi.dll",
                "C:\\Windows\\system32\\napinsp.dll",
                "ImgUtil.dll",
                "ntmarta.dll",
                "URLMON.DLL",
                "C:\\Windows\\system32\\Msimtf.dll",
                "API-MS-WIN-Service-Management-L1-1-0.dll",
                "VERSION.dll",
                "C:\\Windows\\syswow64\\MSCTF.dll",
                "KERNEL32.DLL",
                "API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
                "OLEAUT32.DLL",
                "RASMAN.DLL",
                "IPHLPAPI.DLL",
                "advapi32.dll",
                "comctl32",
                "ole32.dll",
                "comdlg32.dll",
                "API-MS-WIN-Service-winsvc-L1-1-0.dll",
                "olepro32.dll",
                "rtutils.dll",
                "version.dll",
                "C:\\Windows\\SysWOW64\\oleaut32.dll",
                "wininet.dll",
                "ADVAPI32.dll",
                "OLEAUT32.dll",
                "C:\\Windows\\system32\\pnrpnsp.dll",
                "DHCPCSVC.DLL",
                "C:\\Windows\\System32\\winrnr.dll",
                "API-MS-Win-Security-SDDL-L1-1-0.dll",
                "comctl32.dll",
                "WININET.dll",
                "Kernel32",
                "SXS.DLL",
                "MLANG.dll",
                "Kernel32.dll",
                "powrprof.dll",
                "shell32.dll",
                "rpcrt4.dll",
                "SETUPAPI.dll",
                "WS2_32.dll",
                "user32.dll"
            ],
            "file_opened": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
                "C:\\",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Internet Explorer\\MSIMGSIZ.DAT",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\ie6_main.css",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db",
                "C:\\Users\\cuck\\AppData\\Local\\Temp",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
                "C:\\Users\\cuck\\AppData",
                "C:\\Windows\\SysWOW64\\ieframe.dll",
                "C:\\Users\\cuck\\AppData\\Local",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close_Hover.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
                "C:\\Users",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\button-bg.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg2.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Icon_Generic.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
                "\\\\?\\pipe\\0K1C1T1I1E1C1F1N1C1T1H_TEST",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\checkbox.css",
                "C:\\Users\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg-corner.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\form.bmp.Mask",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\csshover3.htc",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\TR.locale",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button_Hover.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button_Hover.png",
                "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\button.css",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db",
                "C:\\Users\\cuck",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\browse.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
            ],
            "command_line": [
                "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin\" \/_ShowProgress \/PrTxt:TG9hZGluZy4uLg=="
            ],
            "connects_host": [
                "rp.kralprogramcdn.com",
                "info.kralprogramcdn.com"
            ],
            "regkey_opened": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/pjpeg\\Bits",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\DnsClient",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/tiff\\Bits",
                "HKEY_CLASSES_ROOT\\Directory",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Main",
                "HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\about\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IEDDE_REGISTER_URLECHO",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Settings",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\DxTrans",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BROWSER_EMULATION",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\about",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced",
                "HKEY_CURRENT_USER\\SOFTWARE\\Classes\\PROTOCOLS\\Filter\\text\/html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IPERSISTMONIKER_LOAD_REDIRECTED_URL_KB976425",
                "HKEY_CURRENT_USER\\Software\\Policies",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\PageSetup",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\Rpc",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Styles",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\ShellEx\\IconHandler",
                "HKEY_CLASSES_ROOT\\MIME\\Database\\Content Type",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001",
                "HKEY_CURRENT_USER\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\Clsid",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\TravelLog",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Ftp",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
                "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IEDDE_REGISTER_PROTOCOL",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Ftp",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\LSA\\AccessProviders",
                "HKEY_CLASSES_ROOT\\.png",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/jpeg\\Bits",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_ZONE_ELEVATION",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International",
                "HKEY_CURRENT_USER\\Software\\Borland\\Delphi\\Locales",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights",
                "HKEY_CLASSES_ROOT\\.css",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Services",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\MediaTypeClass",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ACTIVEX_INACTIVATE_MODE_REMOVAL_REVERT",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Services",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Zoom",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_MIME_SNIFFING",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Zones",
                "HKEY_CURRENT_USER\\Software\\Borland\\Locales",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\ActiveDesktop",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Recovery",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer",
                "HKEY_LOCAL_MACHINE\\Software",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1\\0",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\Clsid",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\ActiveX Compatibility",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1\\0\\win32",
                "HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\Explorer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SCRIPTURL_MITIGATION",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\DnsCache\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BINARY_CALLER_SERVICE_PROVIDER",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\ShellEx\\IconHandler",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Ranges\\",
                "HKEY_CLASSES_ROOT\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\InProcServer32",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/png\\Bits",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld",
                "HKEY_LOCAL_MACHINE\\System\\Setup",
                "HKEY_CLASSES_ROOT\\SystemFileAssociations\\.html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SHOW_FAILED_CONNECT_CONTENT_KB942615",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_READ_ZONE_STRINGS_FROM_REGISTRY",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
                "HKEY_CLASSES_ROOT\\FirefoxURL-E7CF176E110C211B\\shell\\open\\command",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ADDITIONAL_IE8_MEMORY_CLEANUP",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\BrowserEmulation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\Feature_Enable_Compat_Logging",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Activities",
                "HKEY_CURRENT_USER\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}",
                "HKEY_CLASSES_ROOT\\SystemFileAssociations\\document",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD",
                "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler32",
                "HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\*\\",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Nls\\CodePage",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SUBDOWNLOAD_LOCKDOWN",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IGNORE_LEADING_FILE_SEPARATOR_IN_URI_KB933105",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\International\\Scripts",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Accepted Documents",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Ranges\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICTED_ZONE_WHEN_FILE_NOT_FOUND",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Restrictions",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\TravelLog",
                "HKEY_LOCAL_MACHINE\\Software\\Policies",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Control Panel",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\(Default)",
                "HKEY_CURRENT_USER\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OleAut",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Rpc",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProtocolDefaults\\",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Infodelivery\\Restrictions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
                "HKEY_CLASSES_ROOT\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\ShellFolder",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Main",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\BrowserEmulation",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Ratings",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_DOCUMENT_COMPATIBLE_MODE",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
                "HKEY_CLASSES_ROOT\\.html\\OpenWithProgids",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_WEBOC_DOCUMENT_ZOOM",
                "HKEY_CLASSES_ROOT\\FirefoxHTML-E7CF176E110C211B",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\Clsid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\OpenWithProgids",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\IconHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SSLUX",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\%s",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BLOCK_LMZ_IMG",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Zoom",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_CUSTOM_IMAGE_MIME_TYPES_KB910561",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\Directory",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\DxTrans",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_XSSFILTER",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Zoom",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Wpad",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\System\\DNSClient",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\Adv AddrBar Spoof Detection",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
                "HKEY_CURRENT_USER\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}",
                "HKEY_CURRENT_USER\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\TreatAs",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Services",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap",
                "HKEY_CLASSES_ROOT\\Folder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CLASSES_ROOT\\.gif",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\Adv AddrBar Spoof Detection",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-jg\\Bits",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LDAP",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\http\\UserChoice",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3050f819-98b5-11cf-bb82-00aa00bdce0b}",
                "HKEY_CURRENT_USER\\Software",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\ShellEx\\IconHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\MAIN",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\COM3",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Filter\\text\/html",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\ShellEx\\IconHandler",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\iexplore.exe",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LEGACY_DLCONTROL_BEHAVIORS",
                "HKEY_CLASSES_ROOT\\AllFilesystemObjects",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3050f4e1-98b5-11cf-bb82-00aa00bdce0b}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_SNIFFING",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Zoom",
                "HKEY_CURRENT_USER\\TypeLib",
                "HKEY_CURRENT_USER\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\about",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\CurVer",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SSLUX",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
                "HKEY_CLASSES_ROOT\\.html",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\Floppy Access",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-icon\\Bits",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\Clsid",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MANAGE_SCRIPT_CIRCULAR_REFS",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Infodelivery\\Restrictions",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\RASMANCS",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\Explorer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3050f4f5-98B5-11CF-BB82-00AA00BDCE0B}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-wmf\\Bits",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Connections",
                "HKEY_CLASSES_ROOT\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Applications\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\CurVer",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png\\Bits",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Low Rights",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Shell\\RegisteredApplications\\UrlAssociations\\Directory\\OpenWithProgids",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\ActiveX Compatibility\\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_Cross_Domain_Redirect_Mitigation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/bmp\\Bits",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/gif\\Bits",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\Clsid",
                "HKEY_CURRENT_USER\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}",
                "HKEY_CLASSES_ROOT\\htmlfile",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Activities",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Activities",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Ranges\\",
                "HKEY_LOCAL_MACHINE\\Software\\Borland\\Locales",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MSHTML_AUTOLOAD_IEFRAME",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Restrictions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESPECT_OBJECTSAFETY_POLICY_KB905547",
                "HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\file\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_ZONE_ELEVATION",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_MIME_HANDLING"
            ],
            "resolves_host": [
                "wpad",
                "cuckpc"
            ],
            "file_written": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\ie6_main.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close_Hover.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\button-bg.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg2.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Icon_Generic.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\checkbox.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg-corner.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\form.bmp.Mask",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\csshover3.htc",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\TR.locale",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button_Hover.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button_Hover.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\button.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\browse.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
            ],
            "regkey_deleted": [
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
            ],
            "file_deleted": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
            ],
            "file_exists": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\",
                "C:\\",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft",
                "C:\\Users\\cuck\\",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css:Zone.Identifier",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\",
                "C:\\Users\\",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Internet Explorer",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css:Zone.Identifier",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html:Zone.Identifier",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\",
                "C:\\Users\\cuck\\AppData\\"
            ],
            "mutex": [
                "MSIMGSIZECacheMutex",
                "Local\\ZonesCounterMutex",
                "Local\\ZonesLockedCacheCounterMutex",
                "Local\\ZoneAttributeCacheCounterMutex",
                "IESQMMUTEX_0_208",
                "Local\\ZonesCacheCounterMutex"
            ],
            "file_failed": [
                "\\\\?\\pipe\\0K1C1T1I1E1C1F1N1C1T1H",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html"
            ],
            "guid": [
                "{275c23e2-3747-11d0-9fea-00aa003f8646}",
                "{6a01fda0-30df-11d0-b724-00aa006c1a01}",
                "{30c3b080-30fb-11d0-b724-00aa006c1a01}",
                "{dccfc164-2b38-11d2-b7ec-00c04f8f5d9a}",
                "{25336920-03f9-11cf-8fd0-00aa00686f13}",
                "{a3ccedf7-2de2-11d0-86f4-00a0c913f750}",
                "{dcb00c01-570f-4a9b-8d69-199fdba5723b}",
                "{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
                "{4ef17940-30e0-11d0-b724-00aa006c1a01}",
                "{6e89f8e2-9a2a-4797-9b91-41146bdf0e7b}",
                "{00000146-0000-0000-c000-000000000046}",
                "{6c736dc1-ab0d-11d0-a2ad-00a0c90f27e8}",
                "{d0074ffd-570f-4a9b-8d69-199fdba5723b}",
                "{a3ccedf3-2de2-11d0-86f4-00a0c913f750}",
                "{f414c260-6ac0-11cf-b6d1-00aa00bbbb58}",
                "{000214e6-0000-0000-c000-000000000046}",
                "{00000001-0000-0000-c000-000000000046}",
                "{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}",
                "{d9e89500-30fa-11d0-b724-00aa006c1a01}",
                "{00000323-0000-0000-c000-000000000046}",
                "{e7e4bc40-e76a-11ce-a9bb-00aa004ae837}",
                "{8856f961-340a-11d0-a96b-00c04fd705a2}",
                "{dcb00000-570f-4a9b-8d69-199fdba5723b}",
                "{50d5107a-d278-4871-8989-f4ceaaf59cfc}",
                "{bb1a2ae1-a4f9-11cf-8f20-00805f2cd064}",
                "{a47979d2-c419-11d9-a5b4-001185ad2b89}",
                "{00000112-0000-0000-c000-000000000046}",
                "{6c736db1-bd94-11d0-8a23-00aa00b58e10}",
                "{3050f406-98b5-11cf-bb82-00aa00bdce0b}",
                "{08c0e040-62d1-11d1-9326-0060b067b86e}",
                "{e569bde7-a8dc-47f3-893f-fd2b31b3eefd}"
            ],
            "file_read": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
                "C:\\Windows\\SysWOW64\\ieframe.dll",
                "C:\\Users\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\MaxRpcSize",
                "HKEY_CURRENT_USER\\.html\\Content Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector\\VML",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFileUrl",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEFontSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SUBDOWNLOAD_LOCKDOWN\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\FileDirectory",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoProxyDetectType",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Domain",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableImprovedZoneCheck",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\RecommendedLevel",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\MinLevel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\Icon",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\UrlEncoding",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.gif\\Content Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableConsoleTracing",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableCachingOfSSLPages",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\XDomainRequest",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Display Inline Images",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\MinLevel",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Zoom\\ZoomDisabled",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\Flags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\about\\CLSID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\EnableFileTracing",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\IsTextPlainHonored",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png\\Image Filter CLSID",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEFixedFontName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Show image placeholders",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\InProcServer32\\LoadWithoutCOM",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\InProcServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONE_ELEVATION\\*",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights\\ProtectedModeOffForAllZones",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LEGACY_DLCONTROL_BEHAVIORS\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileTracingMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\SmoothScroll",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Use Stylesheets",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\Flags",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\950",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\2106",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1201",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\TabProcGrowth",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldDllVersionLow",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Always Use My Font Size",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\InprocServer32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/jpeg\\Bits\\0",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Enable AutoImageResize",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldDllVersionHigh",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\2500",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\CurrentLevel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoWebView",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.css\\Content Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2000",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\AcceptLanguage",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FrameTabWindow",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\RecommendedLevel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/pjpeg\\Bits\\0",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2700",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\ProgramData",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LEGACY_DLCONTROL_BEHAVIORS\\*",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Move System Caret",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1\\0\\win32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\AdminTabProcs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\SessionMerging",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-wmf\\Bits\\0",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\RecommendedLevel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\ThreadingModel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Anchor Color Visited",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SSLUX\\*",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SeparateProcess",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\SecuritySafe",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_SNIFFING\\*",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldVersionHigh",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\COM+Enabled",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableCachingOfSSLPages",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\DOMStorage",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\2500",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2000",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\UrlEncoding",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\AlwaysShowExt",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\*",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Hostname",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\IEXPLORE.EXE\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\MiscFlags",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Services\\SelectionActivityButtonDisable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\UseHR",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\DOMStorage",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\SmartDithering",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\SessionMerging",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\2500",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Print_Background",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Force Offscreen Composition",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BLOCK_LMZ_IMG\\*",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\UrlEncoding",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\Icon",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Disable Script Debugger",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1400",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\XMLHTTP",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\CurrentLevel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\CurrentLevel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT\\*",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\RtfConverterFlags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileDirectory",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONE_ELEVATION\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\UseClearType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SSLUX\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\2500",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\Flags",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Play_Animations",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BROWSER_EMULATION\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\http\\UserChoice\\Progid",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FrameTabWindow",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Use Anchor Hover Color",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Default_CodePage",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldVersionLow",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\Default_IEFontSizePrivate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\EnableConsoleTracing",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_SNIFFING\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice\\Progid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEFontSizePrivate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Anchor Color",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png\\Bits\\0",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
                "HKEY_CURRENT_USER\\.html\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\No3DBorder",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Print_Background",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History\\DaysToKeep",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2106",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\XDomainRequest",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugHeapFlags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\MaxFileSize",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\CurrentLevel",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Disable Visited Hyperlinks",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\*",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\MinLevel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\MinLevel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DontShowSuperHidden",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector\\WindowsEdition",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\MaxFileSize",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Expand Alt Text",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Play_Background_Sounds",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Display Inline Videos",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_XSSFILTER\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\ConsoleTracingMask",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableCachingOfSSLPages",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableFileTracing",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD\\*",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetCrawling",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Q300829",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\TabProcGrowth",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\OOBEInProgress",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Display Inline Videos",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\NoProtectedModeBanner",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AutoRecover",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\ConsoleTracingMask",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\No3DBorder",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragDelay",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\AdminTabProcs",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Always Use My Font Face",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.png\\Content Type",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2106",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\NavigationDelay",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Cryptography\\MachineGuid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\2500",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\2500",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\RecommendedLevel",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MSHTML_AUTOLOAD_IEFRAME\\*",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFileMenu",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\CurrentLevel",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SmartDithering",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_XSSFILTER\\*",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\AutoDetect",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Anchor Underline",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\FileTracingMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Page_Transitions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WarnOnIntranet",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1",
                "HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\DocObject",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Use_DlgBox_Colors",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\*",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector\\IE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClassicShell",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Allow Programmatic Cut_Copy_Paste",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2700",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\FTP\\Use Web Based FTP",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\2500",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\MachineGuid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Page_Transitions",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\160A",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\DocObject",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\2500",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\DisableScriptDebuggerIE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FrameMerging",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\Flags",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Always Use My Colors",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Anchor Color Hover",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollInterval",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess",
                "HKEY_CURRENT_USER\\FirefoxURL-E7CF176E110C211B\\shell\\open\\command\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollInset",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\RecommendedLevel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Cleanup HTCs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SUBDOWNLOAD_LOCKDOWN\\*",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK\\*",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollDelay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/bmp\\Bits\\0",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WarnOnIntranet",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WarnOnIntranet",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ComputerName\\ActiveComputerName\\ComputerName",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\SmoothScroll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BROWSER_EMULATION\\*",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Show image placeholders",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1201",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MSHTML_AUTOLOAD_IEFRAME\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\MinLevel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/png\\Bits\\0",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FrameMerging",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Security_HKLM_only",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BLOCK_LMZ_IMG\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/gif\\Bits\\0",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\PageSetup\\Print_Background",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\Flags",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\UseThemes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEPropFontName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSimpleStartMenu",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Enable AutoImageResize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\CSS_Compat",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\160A"
            ],
            "directory_enumerated": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\system.js",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\compatibility.js",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\wizard.js",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\i18n.js",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\package.js",
                "C:\\Windows\\System32\\ras\\*.pbk",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\tray.js",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\script\\main.js",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
                "C:\\Users\\cuck\\AppData",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\form.js",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\installer.js",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\logicBox.js",
                "C:\\Users",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\menu.js",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\webBrowser.js",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
                "C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\libs\\idp.js",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\utils.js",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\ui\\progressBar.js",
                "C:\\Users\\cuck\\AppData\\Local",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\debug.js",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\*.pbk",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\script\\flow.js",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\libs\\json2.js",
                "C:\\Users\\cuck",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\eventListener.js",
                "C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\*.pbk",
                "C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\adManager.js",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\application.js"
            ],
            "regkey_written": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableConsoleTracing",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionReason",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecision",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadNetworkName",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableFileTracing",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\MaxFileSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileTracingMask",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionTime",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileDirectory",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\ConsoleTracingMask"
            ]
        },
        "first_seen": 1562575985.5781,
        "ppid": 2660
    }
]

Signatures

[
    {
        "markcount": 2,
        "families": [],
        "description": "Collects information to fingerprint the system (MachineGuid, DigitalProductId, SystemBiosDate)",
        "severity": 1,
        "marks": [
            {
                "category": "registry",
                "ioc": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\MachineGuid",
                "type": "ioc",
                "description": null
            },
            {
                "category": "registry",
                "ioc": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Cryptography\\MachineGuid",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "recon_fingerprint"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GlobalMemoryStatusEx",
                    "return_value": 1,
                    "arguments": {},
                    "time": 1562575985.9371,
                    "tid": 2124,
                    "flags": {}
                },
                "pid": 2436,
                "type": "call",
                "cid": 1543
            }
        ],
        "references": [],
        "name": "antivm_memory_available"
    },
    {
        "markcount": 3,
        "families": [],
        "description": "The executable contains unknown PE section names indicative of a packer (could be a false positive)",
        "severity": 1,
        "marks": [
            {
                "category": "section",
                "ioc": "CODE",
                "type": "ioc",
                "description": null
            },
            {
                "category": "section",
                "ioc": "DATA",
                "type": "ioc",
                "description": null
            },
            {
                "category": "section",
                "ioc": "BSS",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "pe_features"
    },
    {
        "markcount": 10,
        "families": [],
        "description": "Allocates read-write-execute memory (usually to unpack itself)",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2436,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 40960,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x00401000"
                    },
                    "time": 1562575985.7181,
                    "tid": 2124,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2436,
                "type": "call",
                "cid": 0
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2436,
                        "region_size": 720896,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "allocation_type": 4096,
                        "base_address": "0x00730000"
                    },
                    "time": 1562575985.7181,
                    "tid": 2124,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE",
                        "allocation_type": "MEM_COMMIT"
                    }
                },
                "pid": 2436,
                "type": "call",
                "cid": 12
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2436,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 1,
                        "length": 819200,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x00901000"
                    },
                    "time": 1562575985.7501,
                    "tid": 2124,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2436,
                "type": "call",
                "cid": 159
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2436,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 1,
                        "length": 643072,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x009c9000"
                    },
                    "time": 1562575985.7501,
                    "tid": 2124,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2436,
                "type": "call",
                "cid": 160
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2436,
                        "region_size": 4096,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "allocation_type": 4096,
                        "base_address": "0x007f0000"
                    },
                    "time": 1562575985.7961,
                    "tid": 2124,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE",
                        "allocation_type": "MEM_COMMIT"
                    }
                },
                "pid": 2436,
                "type": "call",
                "cid": 852
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 816,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 40960,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x00401000"
                    },
                    "time": 1562575988.1869,
                    "tid": 2256,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 816,
                "type": "call",
                "cid": 0
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 816,
                        "region_size": 720896,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "allocation_type": 4096,
                        "base_address": "0x00420000"
                    },
                    "time": 1562575988.1869,
                    "tid": 2256,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE",
                        "allocation_type": "MEM_COMMIT"
                    }
                },
                "pid": 816,
                "type": "call",
                "cid": 12
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 816,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 1,
                        "length": 819200,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x01dd1000"
                    },
                    "time": 1562575988.2029,
                    "tid": 2256,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 816,
                "type": "call",
                "cid": 159
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 816,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 1,
                        "length": 643072,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x01e99000"
                    },
                    "time": 1562575988.2029,
                    "tid": 2256,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 816,
                "type": "call",
                "cid": 160
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 816,
                        "region_size": 4096,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "allocation_type": 4096,
                        "base_address": "0x004d0000"
                    },
                    "time": 1562575988.2499,
                    "tid": 2256,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE",
                        "allocation_type": "MEM_COMMIT"
                    }
                },
                "pid": 816,
                "type": "call",
                "cid": 852
            }
        ],
        "references": [],
        "name": "allocates_rwx"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "A process attempted to delay the analysis task.",
        "severity": 2,
        "marks": [
            {
                "type": "generic",
                "description": "a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin tried to sleep 170 seconds, actually delayed analysis time by 170 seconds"
            }
        ],
        "references": [],
        "name": "antisandbox_sleep"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Checks adapter addresses which can be used to detect virtual network interfaces",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "network",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741772,
                    "api": "GetAdaptersAddresses",
                    "return_value": 111,
                    "arguments": {
                        "flags": 0,
                        "family": 0
                    },
                    "time": 1562575986.0621,
                    "tid": 2820,
                    "flags": {}
                },
                "pid": 2436,
                "type": "call",
                "cid": 2834
            }
        ],
        "references": [],
        "name": "antivm_network_adapters"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Expresses interest in specific running processes",
        "severity": 2,
        "marks": [
            {
                "category": "process",
                "ioc": "a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "process_interest"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Terminates another process",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "process",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": 0,
                    "api": "NtTerminateProcess",
                    "return_value": 0,
                    "arguments": {
                        "status_code": "0x00000103",
                        "process_identifier": 816,
                        "process_handle": "0x00000214"
                    },
                    "time": 1562575999.2811,
                    "tid": 2124,
                    "flags": {}
                },
                "pid": 2436,
                "type": "call",
                "cid": 6677
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtTerminateProcess",
                    "return_value": 0,
                    "arguments": {
                        "status_code": "0x00000103",
                        "process_identifier": 816,
                        "process_handle": "0x00000214"
                    },
                    "time": 1562575999.2811,
                    "tid": 2124,
                    "flags": {}
                },
                "pid": 2436,
                "type": "call",
                "cid": 6678
            }
        ],
        "references": [],
        "name": "terminates_remote_process"
    },
    {
        "markcount": 5,
        "families": [],
        "description": "Sets or modifies WPAD proxy autoconfiguration file for traffic interception",
        "severity": 3,
        "marks": [
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegSetValueExA",
                    "return_value": 0,
                    "arguments": {
                        "key_handle": "0x000004d0",
                        "value": 1,
                        "regkey_r": "WpadDecisionReason",
                        "reg_type": 4,
                        "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionReason"
                    },
                    "time": 1562575986.7341,
                    "tid": 2820,
                    "flags": {
                        "reg_type": "REG_DWORD"
                    }
                },
                "pid": 2436,
                "type": "call",
                "cid": 4055
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegSetValueExA",
                    "return_value": 0,
                    "arguments": {
                        "key_handle": "0x000004d0",
                        "value": "\u00e0\u00c4\u009e\u009d\u00ad5\u00d5\u0001",
                        "regkey_r": "WpadDecisionTime",
                        "reg_type": 3,
                        "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionTime"
                    },
                    "time": 1562575986.7341,
                    "tid": 2820,
                    "flags": {
                        "reg_type": "REG_BINARY"
                    }
                },
                "pid": 2436,
                "type": "call",
                "cid": 4056
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegSetValueExA",
                    "return_value": 0,
                    "arguments": {
                        "key_handle": "0x000004d0",
                        "value": 3,
                        "regkey_r": "WpadDecision",
                        "reg_type": 4,
                        "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecision"
                    },
                    "time": 1562575986.7341,
                    "tid": 2820,
                    "flags": {
                        "reg_type": "REG_DWORD"
                    }
                },
                "pid": 2436,
                "type": "call",
                "cid": 4057
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegSetValueExW",
                    "return_value": 0,
                    "arguments": {
                        "key_handle": "0x000004d0",
                        "value": "Unidentified network",
                        "regkey_r": "WpadNetworkName",
                        "reg_type": 1,
                        "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadNetworkName"
                    },
                    "time": 1562575986.7341,
                    "tid": 2820,
                    "flags": {
                        "reg_type": "REG_SZ"
                    }
                },
                "pid": 2436,
                "type": "call",
                "cid": 4058
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegSetValueExW",
                    "return_value": 0,
                    "arguments": {
                        "key_handle": "0x00000418",
                        "value": "{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}",
                        "regkey_r": "WpadLastNetwork",
                        "reg_type": 1,
                        "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork"
                    },
                    "time": 1562575986.7341,
                    "tid": 2820,
                    "flags": {
                        "reg_type": "REG_SZ"
                    }
                },
                "pid": 2436,
                "type": "call",
                "cid": 4126
            }
        ],
        "references": [],
        "name": "modifies_proxy_wpad"
    }
]

Yara

The Yara rules did not detect anything in the file.

Network

{
    "tls": [],
    "udp": [
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 662,
            "time": 6.2578480243683,
            "dport": 137,
            "sport": 137
        },
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 5342,
            "time": 12.396643161774,
            "dport": 138,
            "sport": 138
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7186,
            "time": 5.389858007431,
            "dport": 5355,
            "sport": 51001
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7506,
            "time": 4.1576540470123,
            "dport": 5355,
            "sport": 53595
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7834,
            "time": 6.278126001358,
            "dport": 5355,
            "sport": 53848
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8162,
            "time": 4.6621291637421,
            "dport": 5355,
            "sport": 54255
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8490,
            "time": 3.0445830821991,
            "dport": 5355,
            "sport": 55314
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8818,
            "time": 6.4014711380005,
            "dport": 5355,
            "sport": 55880
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 9146,
            "time": 4.6740159988403,
            "dport": 1900,
            "sport": 1900
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 28556,
            "time": 4.1755800247192,
            "dport": 3702,
            "sport": 49152
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 36940,
            "time": 6.4004640579224,
            "dport": 1900,
            "sport": 53598
        }
    ],
    "dns_servers": [],
    "http": [],
    "icmp": [],
    "smtp": [],
    "tcp": [],
    "smtp_ex": [],
    "mitm": [],
    "hosts": [],
    "pcap_sha256": "f1316b1036a6aa0f430067c2ee4e1b86d50c7f3b4ba257f2e6841c52541a6f54",
    "dns": [],
    "http_ex": [],
    "domains": [],
    "dead_hosts": [],
    "sorted_pcap_sha256": "9cc0c7a18cc1a577847e6c2cdfced92df4be355de5672019d139d8b0574d3bba",
    "irc": [],
    "https_ex": []
}

Screenshots

Screenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandbox

iron25072014.exe removal instructions

The instructions below shows how to remove iron25072014.exe with help from the FreeFixer removal tool. Basically, you install FreeFixer, scan your computer, check the iron25072014.exe file for removal, restart your computer and scan it again to verify that iron25072014.exe has been successfully removed. Here are the removal instructions in more detail:

  1. Download and install FreeFixer: http://www.freefixer.com/download.html
  2. Start FreeFixer and press the Start Scan button. The scan will finish in approximately five minutes.
    Screenshot of Start Scan button
  3. When the scan is finished, locate iron25072014.exe in the scan result and tick the checkbox next to the iron25072014.exe file. Do not check any other file for removal unless you are 100% sure you want to delete it. Tip: Press CTRL-F to open up FreeFixer's search dialog to quickly locate iron25072014.exe in the scan result.
    Red arrow point on the unwanted file
    c:\downloads\iron25072014.exe
  4. Scroll down to the bottom of the scan result and press the Fix button. FreeFixer will now delete the iron25072014.exe file.
    Screenshot of Fix button
  5. Restart your computer.
  6. Start FreeFixer and scan your computer again. If iron25072014.exe still remains in the scan result, proceed with the next step. If iron25072014.exe is gone from the scan result you're done.
  7. If iron25072014.exe still remains in the scan result, check its checkbox again in the scan result and click Fix.
  8. Restart your computer.
  9. Start FreeFixer and scan your computer again. Verify that iron25072014.exe no longer appear in the scan result.
Please select the option that best describe your thoughts on the removal instructions given above








Free Questionnaires

Hashes [?]

PropertyValue
MD58a8092df66056fb72ae7ce95fe38d43e
SHA256a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880

Error Messages

These are some of the error messages that can appear related to iron25072014.exe:

iron25072014.exe has encountered a problem and needs to close. We are sorry for the inconvenience.

iron25072014.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.

has stopped working.

End Program - iron25072014.exe. This program is not responding.

iron25072014.exe is not a valid Win32 application.

iron25072014.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.

What will you do with the file?

To help other users, please let us know what you will do with the file:



Comments

Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.

I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.

No comments posted yet.

Leave a reply