vC36a100r.exe is usually located in the 'c:\Windows\System32\' folder.
Some of the anti-virus scanners at VirusTotal detected vC36a100r.exe.
If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.
vC36a100r.exe is not signed.
49 of the 73 anti-virus programs at VirusTotal detected the vC36a100r.exe file. That's a 67% detection rate.
| Scanner | Detection Name |
|---|---|
| Acronis | suspicious |
| Ad-Aware | Gen:Variant.Johnnie.213038 |
| AegisLab | Trojan.Win32.Sdum.4!c |
| AhnLab-V3 | Trojan/Win64.Agent.C3976447 |
| Alibaba | Trojan:Win32/amqsu.9bdc5eb4 |
| ALYac | Trojan.Agent.gen |
| Arcabit | Trojan.Johnnie.D3402E |
| Avast | Win64:Dropper-gen [Drp] |
| AVG | Win64:Dropper-gen [Drp] |
| Avira | TR/Drop.Agent.amqsu |
| BitDefender | Gen:Variant.Johnnie.213038 |
| CAT-QuickHeal | Trojan.Sdum |
| Comodo | ApplicUnwnt@#p664dsmzv3n5 |
| CrowdStrike | win/malicious_confidence_60% (W) |
| Cybereason | malicious.0b5056 |
| Cylance | Unsafe |
| Cyren | W64/Trojan.WAVL-2610 |
| Emsisoft | Gen:Variant.Johnnie.213038 (B) |
| Endgame | malicious (high confidence) |
| ESET-NOD32 | Win64/HackTool.Agent.E potentially unsafe |
| F-Secure | Trojan.TR/Drop.Agent.amqsu |
| FireEye | Generic.mg.20b50e68c813b2da |
| Fortinet | W32/PossibleThreat |
| GData | Gen:Variant.Johnnie.213038 |
| Jiangmin | Trojan.Sdum.v |
| K7AntiVirus | Riskware ( 0040eff71 ) |
| K7GW | Riskware ( 0040eff71 ) |
| Kaspersky | HEUR:Trojan.Win32.Sdum.gen |
| MAX | malware (ai score=89) |
| MaxSecure | Trojan.Malware.74733560.susgen |
| McAfee | RDN/Generic.dx |
| McAfee-GW-Edition | BehavesLike.Win64.Generic.hc |
| Microsoft | Trojan:Win32/Generic!rfn |
| MicroWorld-eScan | Gen:Variant.Johnnie.213038 |
| Paloalto | generic.ml |
| Panda | Trj/RnkBend.A |
| Qihoo-360 | Win32/Trojan.10b |
| Sangfor | Malware |
| SentinelOne | DFI - Malicious PE |
| Sophos | Generic PUA KM (PUA) |
| Symantec | Trojan.Gen.MBT |
| Tencent | Win32.Trojan.Sdum.Hqbt |
| TrendMicro | TROJ_GEN.R002C0PAS20 |
| TrendMicro-HouseCall | TROJ_GEN.R002C0PAS20 |
| VBA32 | Trojan.Sdum |
| VIPRE | Trojan.Win32.Generic!BT |
| Webroot | W32.Dropper.Gen |
| Zillya | Trojan.Sdum.Win32.132 |
| ZoneAlarm | HEUR:Trojan.Win32.Sdum.gen |
The following information was gathered by executing the file inside Cuckoo Sandbox.
Successfully executed process in sandbox.
{
"file_deleted": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp"
],
"file_created": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe"
],
"file_recreated": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
"\\Device\\KsecDD"
],
"regkey_written": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
"HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns\\EulaAccepted",
"HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\LanguageList"
],
"dll_loaded": [
"C:\\Windows\\system32\\bcryptprimitives.dll",
"imagehlp.dll",
"kernel32",
"API-MS-Win-Security-LSALookup-L1-1-0.dll",
"apphelp.dll",
"api-ms-win-core-localization-l1-2-1",
"CFGMGR32.dll",
"kernel32.dll",
"credssp.dll",
"CRYPTBASE.dll",
"C:\\Windows\\system32\\rsaenh.dll",
"SensApi.dll",
"ntdll.dll",
"cryptsp.dll",
"api-ms-win-core-synch-l1-2-0",
"winhttp.dll",
"ntmarta.dll",
"bcrypt.dll",
"API-MS-WIN-Service-Management-L1-1-0.dll",
"cryptnet.dll",
"setupapi.dll",
"C:\\Windows\\System32\\wship6.dll",
"api-ms-win-appmodel-runtime-l1-1-1",
"API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
"API-MS-WIN-Service-winsvc-L1-1-0.dll",
"ole32.dll",
"USERENV.dll",
"CRYPTSP.dll",
"USER32.dll",
"C:\\Windows\\system32\\mswsock.dll",
"API-MS-Win-Security-SDDL-L1-1-0.dll",
"SspiCli.dll",
"IPHLPAPI.DLL",
"C:\\Windows\\system32\\Wintrust.dll",
"ncrypt.dll",
"WindowsCodecs.dll",
"C:\\Windows\\system32\\CRYPT32.dll",
"NSI.dll",
"OLEAUT32.dll",
"profapi.dll",
"SHELL32.dll",
"RPCRT4.dll",
"DNSAPI.dll",
"C:\\Windows\\System32\\wshtcpip.dll",
"comctl32.dll",
"ext-ms-win-kernel32-package-current-l1-1-0",
"SHLWAPI.dll",
"API-MS-WIN-Service-Management-L2-1-0.dll",
"C:\\Windows\\system32\\advapi32.dll",
"api-ms-win-core-fibers-l1-1-1",
"WINTRUST.DLL",
"C:\\Windows\\system32\\cryptnet.dll",
"PROPSYS.dll",
"C:\\Windows\\system32\\crypt32.dll",
"DEVRTL.dll",
"C:\\Windows\\system32\\Kernel32.dll",
"ADVAPI32.dll",
"advapi32",
"SETUPAPI.dll",
"WS2_32.dll",
"Cabinet.dll",
"WINHTTP.dll"
],
"file_opened": [
"",
"C:\\Windows\\SysWOW64",
"C:\\Windows\\System32\\drivers\\amdk8.sys",
"C:\\Program Files\\Windows Media Player\\wmpnetwk.exe",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\",
"c:\\Windows\\SysWOW64\\iedkcs32.dll",
"C:\\Python27\\python.exe",
"c:\\program files (x86)\\windows mail\\WinMail.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RegisterSearch",
"C:\\Windows\\System32\\drivers\\ndisuio.sys",
"C:\\Windows\\System32\\drivers\\monitor.sys",
"C:\\Windows\\System32\\drivers\\WUDFPf.sys",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
"C:\\Windows\\System32\\aepdu.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
"C:\\Windows\\System32\\drivers\\blbdrive.sys",
"C:\\Windows\\System32\\clfs.sys",
"C:\\Windows\\System32\\drivers\\netbios.sys",
"C:\\Windows\\System32\\en-US\\KERNELBASE.dll.mui",
"C:\\Windows\\System32\\drivers\\mstee.sys",
"C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\",
"C:\\Windows\\System32\\drivers\\hidir.sys",
"c:\\Windows\\SysWOW64\\regsvr32.exe",
"C:\\Windows\\System32\\drivers\\rasl2tp.sys",
"C:\\Windows\\System32\\drivers\\srvnet.sys",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
"C:\\Windows\\System32\\drivers\\asyncmac.sys",
"C:\\Windows\\System32\\drivers\\flpydisk.sys",
"C:\\Windows\\System32\\imageres.dll",
"C:\\Windows\\System32\\drivers\\lsi_sas2.sys",
"C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727",
"C:\\Windows\\System32\\drivers\\mrxdav.sys",
"C:\\Windows\\System32\\drivers\\mountmgr.sys",
"C:\\ProgramData\\Microsoft\\",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
"C:\\Windows\\System32\\drivers\\rdyboost.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MobilePC\\HotStart",
"C:\\Windows\\System32\\drivers\\wacompen.sys",
"C:\\Users\\cuck\\Searches\\desktop.ini",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MUI\\LPRemove",
"C:\\Windows\\System32\\catroot",
"C:\\Windows\\System32\\drivers\\circlass.sys",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\",
"C:\\Windows\\System32\\drivers\\CompositeBus.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
"C:\\Windows\\System32\\drivers\\fdc.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SystemRestore\\SR",
"C:\\Windows\\System32\\drivers\\bthmodem.sys",
"C:\\Windows\\System32\\drivers\\compbatt.sys",
"C:\\Windows\\System32\\drivers\\RDPCDD.sys",
"C:\\Windows\\System32\\drivers\\filetrace.sys",
"C:\\Windows\\System32\\mctadmin.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
"C:\\Windows\\System32\\rsaenh.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Location\\Notifications",
"C:\\Windows\\System32\\drivers\\BrUsbSer.sys",
"C:\\Windows\\System32\\drivers\\vdrvroot.sys",
"C:\\Windows\\System32\\drivers\\stexstor.sys",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CRLs\\",
"C:\\Windows\\System32\\drivers\\BrFiltUp.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
"C:\\Windows\\System32\\drivers\\mshidkmdf.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\AitAgent",
"C:\\Users\\cuck\\AppData\\LocalLow",
"C:\\Windows\\System32\\drivers\\umbus.sys",
"C:\\Windows\\System32\\drivers\\HpSAMD.sys",
"C:\\Windows\\System32\\drivers\\E1G6032E.sys",
"C:\\Windows\\System32\\drivers\\msdsm.sys",
"C:\\Windows\\System32\\drivers\\lltdio.sys",
"C:\\Windows\\System32\\drivers\\vhdmp.sys",
"C:\\Windows\\System32\\drivers\\usbuhci.sys",
"C:\\Windows\\System32\\drivers\\pciide.sys",
"C:\\Windows\\System32\\dwm.exe",
"C:\\Windows\\System32\\drivers\\fltMgr.sys",
"C:\\Windows\\System32\\drivers\\rassstp.sys",
"C:\\Users\\cuck\\Links\\desktop.ini",
"C:\\Windows\\System32\\drivers\\IPMIDrv.sys",
"C:\\Windows\\System32\\raserver.exe",
"C:\\Windows\\SysWOW64\\ie4uinit.exe",
"C:\\Windows\\System32\\drivers\\ndis.sys",
"C:\\tmpyzbctd\\",
"C:\\Windows\\System32\\drivers\\tunnel.sys",
"C:\\Windows\\System32\\drivers\\hwpolicy.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
"C:\\Windows\\System32\\drivers\\sisraid4.sys",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Ras\\MobilityManager",
"C:\\Windows\\System32\\drivers\\ndiscap.sys",
"C:\\Program Files\\Windows Media Player\\",
"c:\\Windows\\System32\\cmd.exe",
"C:\\Windows\\System32\\drivers\\umpass.sys",
"C:\\Users\\cuck\\AppData",
"C:\\Windows\\System32\\drivers\\bowser.sys",
"C:\\Windows\\System32\\drivers\\partmgr.sys",
"C:\\Windows\\System32\\drivers\\iaStorV.sys",
"C:\\Windows\\System32\\drivers\\usbccgp.sys",
"C:\\Windows\\System32\\cmd.exe",
"C:\\Windows\\System32\\drivers\\sffp_sd.sys",
"C:\\Windows\\Microsoft.NET\\Framework",
"C:\\Windows\\System32\\drivers\\volsnap.sys",
"C:\\Windows\\ehome\\mcupdate.exe",
"C:\\Windows\\System32\\drivers\\mpsdrv.sys",
"C:\\Windows\\System32\\drivers\\wmiacpi.sys",
"C:\\Windows\\System32\\drivers\\MegaSR.sys",
"C:\\Windows\\System32\\drivers\\adpu320.sys",
"C:\\Windows\\SysWOW64\\unregmp2.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Task Manager\\Interactive",
"C:\\Windows\\System32\\drivers\\cdrom.sys",
"c:\\Windows\\System32\\regsvr32.exe",
"C:\\Windows\\System32\\drivers\\BrFiltLo.sys",
"C:\\Users\\cuck\\AppData\\Local\\",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
"C:\\Windows\\System32\\drivers\\pcw.sys",
"C:\\Windows\\System32\\Defrag.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Registry\\RegIdleBackup",
"C:\\Windows\\System32\\drivers\\megasas.sys",
"C:\\Windows\\System32\\drivers\\modem.sys",
"C:\\Windows\\System32\\unregmp2.exe",
"C:\\Windows\\System32\\drivers\\adp94xx.sys",
"C:\\Windows\\System32\\drivers\\iirsp.sys",
"C:\\Windows\\System32\\userinit.exe",
"C:\\Windows\\System32\\drivers\\rspndr.sys",
"C:\\Windows\\System32\\drivers\\hdaudbus.sys",
"C:\\Windows\\System32\\drivers\\vga.sys",
"C:\\",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
"C:\\Windows\\System32\\drivers\\wanarp.sys",
"C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe",
"C:\\Windows\\System32\\drivers\\dmvsc.sys",
"C:\\Windows\\System32\\drivers\\FsDepends.sys",
"C:\\Windows\\System32\\EhStorShell.dll",
"C:\\Windows\\System32\\conhost.exe",
"c:\\Windows\\System32\\rundll32.exe",
"C:\\Windows\\System32\\drivers\\sisraid2.sys",
"C:\\Windows\\System32\\appidpolicyconverter.exe",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
"C:\\Windows\\System32\\drivers\\ULIAGPKX.SYS",
"c:\\Windows\\SysWOW64\\ie4uinit.exe",
"C:\\Windows\\System32\\drivers\\rasacd.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Maintenance\\WinSAT",
"C:\\Windows\\System32\\drivers\\hcw85cir.sys",
"c:\\Windows\\System32\\iconcodecservice.dll",
"C:\\Windows\\System32\\drivers\\VMBusHID.sys",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db",
"C:\\Windows\\System32\\drivers\\intelide.sys",
"C:\\Windows\\ehome",
"C:\\Users\\cuck\\Favorites\\desktop.ini",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RAC\\RacTask",
"C:\\Windows\\System32\\drivers\\vmstorfl.sys",
"C:\\Windows\\System32\\drivers\\ipfltdrv.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
"C:\\Windows\\System32\\drivers\\HdAudio.sys",
"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe",
"c:\\Windows\\SysWOW64\\mscories.dll",
"C:\\Windows\\System32\\drivers\\srv.sys",
"C:\\Windows\\System32\\drivers\\msiscsi.sys",
"C:\\Windows\\System32\\drivers\\CmBatt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
"C:\\Windows\\System32\\drivers\\bxvbda.sys",
"C:\\Windows\\System32\\drivers\\vwifibus.sys",
"C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\ntexe.cat",
"C:\\Windows\\System32\\drivers\\drmkaud.sys",
"C:\\Windows\\System32\\drivers\\fvevol.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
"C:\\Windows\\System32\\ndfapi.dll",
"C:\\Windows\\Microsoft.Net\\Framework64\\v3.0\\",
"C:\\Windows\\System32\\drivers\\ksthunk.sys",
"C:\\Windows\\System32\\drivers\\ipnat.sys",
"C:\\Windows\\System32\\drivers\\kbdhid.sys",
"C:\\Windows\\System32\\alg.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
"C:\\Windows\\System32\\drivers\\disk.sys",
"C:\\Program Files (x86)",
"C:\\Windows\\System32\\lpremove.exe",
"C:\\Windows\\System32\\lsass.exe",
"C:\\Windows\\System32\\drivers\\kbdclass.sys",
"C:\\Windows\\System32\\ntshrui.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
"C:\\Windows\\System32\\drivers\\smb.sys",
"C:\\Windows\\System32\\drivers\\isapnp.sys",
"C:\\Windows\\System32\\drivers\\amdsbs.sys",
"C:\\Windows\\System32\\lsm.exe",
"C:\\Windows",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Autochk\\Proxy",
"C:\\Windows\\System32\\drivers\\usbcir.sys",
"C:\\Windows\\System32\\drivers\\vmbus.sys",
"C:\\Windows\\System32\\drivers\\tdpipe.sys",
"C:\\Windows\\System32\\drivers\\appid.sys",
"C:\\Windows\\System32\\drivers\\cng.sys",
"c:\\Windows\\System32\\userinit.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
"C:\\Windows\\System32\\drivers\\afd.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
"C:\\Users\\cuck\\Videos\\desktop.ini",
"C:\\Program Files\\Windows Mail",
"C:\\Windows\\System32\\drivers\\tcpip.sys",
"C:\\Windows\\System32\\services.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
"C:\\Users\\cuck\\Documents\\desktop.ini",
"C:\\Windows\\System32\\drivers\\BrSerWdm.sys",
"C:\\Windows\\System32\\drivers\\ndiswan.sys",
"C:\\Users\\cuck\\Contacts\\desktop.ini",
"C:\\Windows\\System32\\drivers\\serial.sys",
"C:\\Users\\cuck",
"C:\\Windows\\System32\\drivers\\lsi_sas.sys",
"C:\\Windows\\System32\\DFDWiz.exe",
"C:\\Windows\\System32\\drivers\\dxgkrnl.sys",
"C:\\Windows\\System32\\dfdts.dll",
"C:\\Windows\\System32\\drivers\\nvstor.sys",
"C:\\Windows\\System32\\LocationNotifications.exe",
"C:\\Windows\\System32\\FXSSVC.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
"C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat",
"C:\\Program Files (x86)\\Windows Mail",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WDI\\ResolutionHost",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ehDRMInit",
"C:\\Windows\\SysWOW64\\regsvr32.exe",
"C:\\Windows\\System32\\drivers\\csc.sys",
"C:\\Windows\\System32\\drivers\\i8042prt.sys",
"C:\\Windows\\System32\\gatherNetworkInfo.vbs",
"C:\\Windows\\System32\\drivers\\parport.sys",
"C:\\Windows\\System32\\drivers\\nfrd960.sys",
"C:\\Windows\\System32\\drivers\\msahci.sys",
"C:\\Program Files\\Windows Media Player\\wmpnscfg.exe",
"C:\\Windows\\System32\\winlogon.exe",
"C:\\Windows\\System32\\drivers\\sfloppy.sys",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
"C:\\Windows\\System32\\drivers\\RDPENCDD.sys",
"C:\\Windows\\System32\\drivers\\nwifi.sys",
"C:\\Windows\\System32\\drivers\\ws2ifsl.sys",
"C:\\Windows\\System32\\drivers\\PEAuth.sys",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
"C:\\Windows\\System32\\drivers\\NV_AGP.SYS",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
"C:\\Windows\\System32\\drivers\\rdpdr.sys",
"C:\\Users\\cuck\\Pictures\\desktop.ini",
"C:\\Windows\\System32\\drivers\\elxstor.sys",
"C:\\Windows\\System32\\drivers\\hidusb.sys",
"C:\\Windows\\System32\\drivers\\ql40xx.sys",
"c:\\Windows\\System32\\ie4uinit.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft",
"C:\\Windows\\System32\\",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
"C:\\Windows\\System32\\drivers\\amdxata.sys",
"C:\\ProgramData",
"C:\\Windows\\System32\\drivers\\usbhub.sys",
"C:\\Windows\\System32\\wininit.exe",
"C:\\Windows\\System32\\drivers\\vms3cap.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
"C:\\Windows\\SysWOW64\\en-US\\unregmp2.exe.mui",
"C:\\Windows\\System32\\drivers\\nsiproxy.sys",
"C:\\Windows\\System32\\drivers\\mup.sys",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
"C:\\Windows\\SysWOW64\\",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\Certificates\\",
"C:\\Windows\\System32\\BFE.DLL",
"C:\\Windows\\explorer.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
"C:\\Windows\\System32\\drivers\\netbt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
"C:\\Windows\\System32\\drivers\\atapi.sys",
"C:\\Windows\\System32\\drivers\\storvsc.sys",
"C:\\Program Files\\Windows Mail\\WinMail.exe",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs",
"C:\\Windows\\System32\\drivers\\fileinfo.sys",
"C:\\Windows\\System32\\drivers\\wd.sys",
"C:\\Windows\\System32\\drivers\\RDPREFMP.sys",
"C:\\Windows\\System32\\drivers\\pacer.sys",
"C:\\Windows\\System32\\drivers\\dfsc.sys",
"C:\\Windows\\System32\\drivers\\mrxsmb10.sys",
"c:\\program files\\windows mail\\WinMail.exe",
"C:\\Windows\\System32\\drivers\\mrxsmb20.sys",
"C:\\Windows\\System32\\appidcertstorecheck.exe",
"C:\\Windows\\System32\\drivers\\pci.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
"C:\\Windows\\Microsoft.NET\\Framework64\\",
"C:\\Windows\\Microsoft.NET",
"C:\\Users\\cuck\\AppData\\Roaming",
"C:\\Windows\\System32\\drivers\\b57nd60a.sys",
"C:\\Windows\\System32\\drivers\\wimmount.sys",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
"C:\\Program Files (x86)\\Windows Mail\\",
"C:\\Windows\\System32\\drivers\\TsUsbFlt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
"C:\\Program Files",
"C:\\Windows\\System32\\drivers\\acpi.sys",
"C:\\Windows\\System32\\drivers\\udfs.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\AutoWake",
"C:\\Windows\\System32\\drivers\\raspppoe.sys",
"C:\\Users\\cuck\\Saved Games\\desktop.ini",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
"C:\\Windows\\System32\\drivers\\hidbth.sys",
"c:\\Windows\\SysWOW64\\rundll32.exe",
"C:\\Windows\\System32\\drivers\\irenum.sys",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
"C:\\Windows\\System32\\drivers\\srv2.sys",
"C:\\Windows\\System32\\SearchIndexer.exe",
"C:\\Windows\\System32\\drivers\\serenum.sys",
"C:\\Windows\\System32\\drivers\\intelppm.sys",
"C:\\ProgramData\\Microsoft\\Windows",
"C:\\Windows\\System32\\drivers\\mskssrv.sys",
"C:\\Windows\\System32\\drivers\\mssmbios.sys",
"C:\\Windows\\System32\\drivers\\BrSerId.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
"C:\\Users\\",
"c:\\Windows\\explorer.exe",
"C:\\Windows\\System32\\drivers\\agilevpn.sys",
"C:\\Users",
"C:\\Windows\\System32\\drivers\\usbohci.sys",
"C:\\Windows\\System32\\drivers\\vsmraid.sys",
"C:\\Program Files (x86)\\Windows Mail\\WinMail.exe",
"C:\\Windows\\System32\\catroot2\\",
"C:\\Windows\\System32\\drivers\\amdppm.sys",
"C:\\Windows\\System32\\drivers\\pcmcia.sys",
"C:\\Windows\\System32\\svchost.exe",
"C:\\Users\\cuck\\",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
"C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\WPF",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SessionAgent",
"C:\\Windows\\System32\\drivers\\mspqm.sys",
"C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\",
"C:\\Windows\\System32\\drivers\\msisadrv.sys",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs",
"C:\\Windows\\System32\\catroot2",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
"C:\\Windows\\Microsoft.NET\\Framework64\\v3.0",
"C:\\Users\\cuck\\AppData\\",
"C:\\Windows\\System32\\drivers\\nvraid.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
"c:\\Windows\\System32\\unregmp2.exe",
"C:\\Windows\\ehome\\ehPrivJob.exe",
"C:\\Windows\\System32",
"C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727",
"C:\\Windows\\System32\\regsvr32.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
"C:\\Windows\\System32\\drivers\\mouclass.sys",
"C:\\Windows\\System32\\drivers\\vgapnp.sys",
"C:\\Windows\\System32\\ie4uinit.exe",
"C:\\Windows\\System32\\drivers\\volmgrx.sys",
"C:\\Windows\\System32\\drivers\\arcsas.sys",
"C:\\Windows\\System32\\drivers\\amdide.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
"C:\\Windows\\System32\\powercfg.exe",
"C:\\Windows\\System32\\drivers\\termdd.sys",
"C:\\Program Files\\desktop.ini",
"C:\\Windows\\System32\\drivers\\swenum.sys",
"C:\\Windows\\System32\\taskhost.exe",
"C:\\Windows\\System32\\drivers\\luafv.sys",
"C:\\Windows\\System32\\drivers\\tdx.sys",
"C:\\Windows\\System32\\drivers\\cmdide.sys",
"C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\infocard.exe",
"C:\\Windows\\System32\\drivers\\sbp2port.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\PolicyConverter",
"C:\\Windows\\System32\\drivers\\hidbatt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
"C:\\Windows\\System32\\drivers\\lsi_fc.sys",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
"C:\\Windows\\System32\\drivers\\ksecpkg.sys",
"C:\\Windows\\System32\\drivers\\USBSTOR.SYS",
"C:\\Windows\\ehome\\",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURActivate",
"C:\\Users\\cuck\\Music\\desktop.ini",
"C:\\Windows\\System32\\SystemPropertiesPerformance.exe",
"C:\\Windows\\ehome\\ehrecvr.exe",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
"C:\\Windows\\System32\\drivers\\tssecsrv.sys",
"C:\\Windows\\System32\\en-US\\WINHTTP.dll.mui",
"C:\\Windows\\Microsoft.Net\\Framework64\\",
"C:\\Windows\\System32\\drivers\\ndistapi.sys",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Diagnosis\\Scheduled",
"C:\\Windows\\System32\\drivers\\Wdf01000.sys",
"C:\\Windows\\System32\\drivers\\discache.sys",
"C:\\Users\\cuck\\Desktop\\desktop.ini",
"C:\\Windows\\System32\\drivers\\usbprint.sys",
"C:\\Windows\\System32\\drivers\\rdbss.sys",
"C:\\Windows\\System32\\drivers\\errdev.sys",
"C:\\Windows\\System32\\drivers\\processr.sys",
"C:\\Windows\\System32\\dllhost.exe",
"C:\\Windows\\System32\\drivers\\rdpbus.sys",
"C:\\Windows\\System32\\sc.exe",
"C:\\Windows\\System32\\drivers\\mspclock.sys",
"C:\\Windows\\System32\\drivers\\aliide.sys",
"C:\\Windows\\System32\\drivers\\mpio.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
"C:\\Windows\\System32\\drivers\\evbda.sys",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\mcupdate",
"C:\\Users\\cuck\\Downloads\\desktop.ini",
"C:\\Program Files\\Windows Mail\\",
"c:\\Windows\\System32\\systempropertiesperformance.exe",
"C:\\Windows\\System32\\wermgr.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\",
"C:\\Windows\\System32\\drivers\\ql2300.sys",
"C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation",
"C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\",
"C:\\Windows\\System32\\drivers\\TsUsbGD.sys",
"C:\\Windows\\System32\\drivers\\tdtcp.sys",
"C:\\Windows\\System32\\drivers\\acpipmi.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
"C:\\Windows\\System32\\drivers\\UAGP35.SYS",
"C:\\Windows\\System32\\drivers\\adpahci.sys",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu",
"C:\\Windows\\System32\\drivers\\sffdisk.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
"C:\\Windows\\System32\\notepad.exe",
"C:\\Windows\\System32\\drivers\\arc.sys",
"C:\\Windows\\System32\\rdpclip.exe",
"C:\\Program Files (x86)\\desktop.ini",
"C:\\Windows\\System32\\drivers\\ohci1394.sys",
"C:\\Windows\\Microsoft.NET\\Framework64",
"C:\\Windows\\System32\\drivers\\wfplwf.sys",
"C:\\Python27\\",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RecordingRestart",
"C:\\Windows\\System32\\drivers\\volmgr.sys",
"\\Device\\NamedPipe\\",
"C:\\Windows\\System32\\drivers\\cdfs.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
"C:\\Windows\\System32\\drivers\\GAGP30KX.SYS",
"c:\\Windows\\System32\\imageres.dll",
"C:\\Windows\\ehome\\ehsched.exe",
"C:\\Windows\\System32\\csrss.exe",
"c:\\program files\\windows defender\\MpCmdRun.exe",
"C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\WPF\\PresentationFontCache.exe",
"C:\\Windows\\System32\\drivers\\1394ohci.sys",
"C:\\Windows\\System32\\shdocvw.dll",
"C:\\Windows\\System32\\drivers\\ksecdd.sys",
"C:\\Windows\\System32\\drivers\\usbehci.sys",
"C:\\Users\\desktop.ini",
"C:\\Windows\\System32\\drivers\\amdsata.sys",
"c:\\Windows\\System32\\rdpclip.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\GadgetManager",
"C:\\Windows\\System32\\drivers\\MTConfig.sys",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
"C:\\Windows\\System32\\drivers\\crcdisk.sys",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\",
"C:\\Windows\\System32\\drivers\\mouhid.sys",
"C:\\Windows\\System32\\drivers\\BrUsbMdm.sys",
"C:\\Windows\\System32\\drivers\\lsi_scsi.sys",
"c:\\Windows\\System32\\iedkcs32.dll",
"C:\\Windows\\System32\\drivers\\sermouse.sys",
"C:\\Windows\\System32\\spoolsv.exe",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CTLs\\",
"C:\\Windows\\System32\\drivers\\scfilter.sys",
"C:\\Windows\\System32\\sdclt.exe",
"C:\\Windows\\System32\\en-US\\unregmp2.exe.mui",
"C:\\Windows\\System32\\cscui.dll",
"C:\\Windows\\",
"C:\\Windows\\System32\\drivers\\http.sys",
"C:\\Windows\\System32\\drivers\\raspptp.sys",
"C:\\ProgramData\\Microsoft",
"C:\\Windows\\System32\\drivers\\viaide.sys",
"C:\\Windows\\System32\\drivers\\tcpipreg.sys",
"C:\\Windows\\System32\\drivers\\qwavedrv.sys",
"C:\\Windows\\System32\\drivers\\mrxsmb.sys",
"C:\\Windows\\System32\\drivers\\AGP440.sys",
"C:\\Windows\\System32\\wsqmcons.exe",
"c:\\Windows\\SysWOW64\\unregmp2.exe",
"C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe",
"c:\\Windows\\System32\\mscories.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
"C:\\Windows\\System32\\drivers\\sffp_mmc.sys"
],
"regkey_opened": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\isapnp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Modem",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srvnet\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06308A56-69E7-4844-A784-8509C25B6C62}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Filetrace\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CC35D2E9-B9E1-4ADC-9DA5-71487D9E9EB5}",
"HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VaultSvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lmhosts",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4DE0CAB9-ECFE-4AA9-B95A-FE815A2EAA4E}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FltMgr\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_32\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBth",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcLocator",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wdf01000\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehSched\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDProxy\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iaStorV",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D0250F3F-6480-484F-B719-42F659AC64D5}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Schedule",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPDR",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vga\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MegaSR",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\discache",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2470470F-2634-478E-B181-571E98A789BB}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vds",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WbioSrvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbcir\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BDESVC\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache3.0.0.0\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WMPNetworkSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDPIPE",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rspndr\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WIMMount\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mshidkmdf\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1BB08CFD-C6AD-44C7-BD0B-8F23035A5731}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BDESVC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProfSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouhid\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B81A55E6-C03C-4EF0-B86F-A80A89DF468D}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Npfs",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbFlt\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppuinotify\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\1394ohci",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EventSystem",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stexstor\\Parameters",
"HKEY_CURRENT_USER\\Software\\Classes\\htmlfile\\shell\\open\\command",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAgileVpn",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CompositeBus\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVE",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NlaSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nv_agp\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{3307E641-F5EE-49E6-A1FE-BFB5D671441C}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\monitor",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinDefend",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidUsb\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Processor\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgrx\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Schedule\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IKEEXT",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A656BBE1-4E3E-4C8A-BD79-A8CA56782753}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection\\NAPStatus UI",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdK8\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{87F56B34-044E-4A48-8FDD-087BFABD5ECF}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UxSms\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltUp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\drmkaud",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fvevol",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CscService\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MRxDAV\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\s3cap\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ACPI",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\viaide",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\i8042prt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{00BB5F5C-4A20-4FD6-8900-4699F989BF01}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\discache\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanServer",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid2\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\exfat",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbohci",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Power",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mountmgr",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\CrawlStartPages",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4D19A151-A712-4920-AC6D-6C6FD81C8CDB}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteRegistry",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wercplsupport\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BFE\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPNAT\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storflt\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A132EB1D-A1EA-48EF-8B69-9358EADF5BD3}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql2300",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swenum",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\E1G60\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpahci\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcLocator\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DPS",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msahci\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SessionEnv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serial",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanWorkstation",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netman\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NativeWifiP\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdxata",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelppm\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tunnel\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SSDPSRV",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C4375D81-FA72-45AC-85F2-3B86A11CCC7D}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RacTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbSer\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4FDEA3B5-7CDE-48F7-940C-43CDBB18FB20}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wd\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nv_agp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmRdpService\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tdx\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Browser",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ohci1394",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPCDD",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msisadrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS2\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBatt\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\isapnp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermDD\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KtmRm",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetTcpPortSharing\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FltMgr",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fastfat",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\drmkaud\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\mcupdate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hkmsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iphlpsvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_sd",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{82676C49-21A7-4605-AA06-E04A067FB611}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sfloppy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURActivate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\megasas",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Appinfo",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TapiSrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\defragsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrSerWdm\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdpbus\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDIS",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{600F3312-A477-448A-936D-EB2DF977300B}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVEdrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAcd",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbehci",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sermouse\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dmvsc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPCSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Brserid\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_FC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wcncsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SessionEnv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sfloppy\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BITS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsata",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSDTC\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PolicyAgent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RACAgent",
"HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TBS\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbMdm\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wbengine\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupProvider\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5F5A18EB-DC73-4E45-A11C-B59043598412}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiSystemHost\\Parameters",
"HKEY_USERS\\.DEFAULT\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinRM\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HpSAMD",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbSer",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbFlt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cmdide",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BTHMODEM\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\udfs\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\THREADORDER\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ohci1394\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\MemUsageTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinHttpAutoProxySvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPAutoReg\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance\\WinSAT",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AFD",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCardSvr\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupProvider",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WbioSrvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupListener",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CertPropSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidIr",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrkWks",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volsnap\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SysMain",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\secdrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\scfilter\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arcsas\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\viaide\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecDD",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hidserv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DcomLaunch\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Beep",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSTEE",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CLFS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\atapi\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pciide",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WANARP\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lmhosts\\Parameters",
"HKEY_USERS\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdio",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vsmraid",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSTEE\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpu320",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdclass\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdpbus",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcSs",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adp94xx",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CmBatt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppIDSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PeerDistSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Fax\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tssecsrv",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2E941CB2-1B33-47C4-905B-8B4278819513}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpu320\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AsyncMac\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NlaSvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9979CB83-103A-4105-9E5D-C74B0AF6D198}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPCLOCK\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdbss",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RegisterSearch",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdPHost",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioSrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wcncsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Tcpip\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Rasl2tp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wbengine",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB07F7B4-BB95-4B74-9D32-4533D566453C}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rspndr",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hidserv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\napagent\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CmBatt\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PptpMiniport",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2pimsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAuto\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dhcp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsbs\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcEptMapper",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouclass",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SCSI\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPWD\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CD962721-73F1-4649-85D7-6884C1EF28D9}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gagp30kx\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PcaSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\napagent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BTHMODEM",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ndisuio",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBth\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ehDRMInit",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDTCP\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinDefend\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Brserid",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis\\Scheduled",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wanarpv6",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdyboost\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netlogon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UI0Detect",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FDResPub",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KeyIso",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Themes\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HpSAMD\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcEptMapper\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bowser\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E3163C33-301D-4730-A266-5518C5ED3967}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nfrd960",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Psched",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVEdrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WcsPlugInService",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
"HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBT",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HTTP",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tdx",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cmdide\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBIOS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermService\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CryptSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PcaSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdhid",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcw\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CertPropSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wudfsvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{96137355-BC34-4BA7-81B7-47C87B556E7D}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WcsPlugInService\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\blbdrive\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pciide\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wuauserv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasPppoe\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swprv\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SensrSvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}",
"HKEY_CURRENT_USER\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_CURRENT_USER\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbhub\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wercplsupport",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\flpydisk\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkCards\\12",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stisvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netlogon\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SNMPTRAP\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouhid",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\upnphost\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nfrd960\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MMCSS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HTTP\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hwpolicy\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VgaSave",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IRENUM\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sbp2port\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tcpipreg",
"HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ws2ifsl",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioSrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiServiceHost\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2psvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcSs\\Parameters",
"HKEY_LOCAL_MACHINE\\Software\\Sysinternals",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ebdrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisCap",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\W32Time",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{8C5ED038-CFAD-48A0-BB2F-D128286E49B3}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\atapi",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Power\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\E1G60",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPREFMP",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_sd\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvraid",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ntfs\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vwifibus",
"HKEY_CURRENT_USER\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pla\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPENCDD",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AxInstSV\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAgileVpn\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ALG\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b06bdrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VaultSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql2300\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Msfs\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sermouse",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanServer\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\i8042prt\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NativeWifiP",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdK8",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\PolicyConverter",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storflt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SstpSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wlansvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrustedInstaller\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC668097-4D6B-4093-AC14-014C09DBF820}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpsdrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPDBusEnum",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PerfHost\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\udfs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BE669C13-8165-4536-96D0-6D6C39292AAE}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{613612BA-897D-44CE-8DC1-8FC283F9FD51}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WebClient",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{448186F9-75B9-4FB7-A6E0-B19A2BADC1BE}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MRxDAV",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hkmsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Null\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AsyncMac",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpio\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbGD",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CNG",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mcx2Svc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdide\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tssecsrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CompositeBus",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\agp440\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermService",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9435F817-FED2-454E-88CD-7F78FDA62C48}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vmbus",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{268014E7-A27E-4FD7-89A6-A481DA222EC8}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BFE",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Tcpip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WudfPf\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdbss\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouclass\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iScsiPrt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmRdpService",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SDRSVC\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinRM",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DXGKrnl\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stisvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPBusEnum\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tunnel",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbuhci\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPDR\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06CD2154-751E-469F-8E4A-C3F118356423}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WSearch\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DcomLaunch",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hcw85cir",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehSched",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EventSystem\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\THREADORDER",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AxInstSV",
"HKEY_USERS\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vdrvroot\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Psched\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FileInfo",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WMPNetworkSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAcd\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PptpMiniport\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Parport",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbohci\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisWan\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermDD",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DXGKrnl",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uagp35",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WerSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Disk",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSiSCSI",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PEAUTH\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serenum\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storvsc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteAccess\\Parameters",
"HKEY_USERS\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDIS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VSS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdide",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\AitAgent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5A40E926-9E86-4B89-9CFD-B12311724371}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{72DB7465-BC54-491B-A92A-4637A28C9BBF}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbGD\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SstpSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvstor\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache3.0.0.0",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\USBSTOR",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MsRPC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_mmc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\umbus",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecDD\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppID\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\flpydisk",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wecsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PolicyAgent\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stexstor",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2psvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\netprofm\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AcpiPmi\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\umbus\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WmiAcpi\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\elxstor\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_mmc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swenum\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ErrDev",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F18ED8A5-C696-4951-B068-CA8E83634C04}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{17F5B0DE-8DA9-4280-8CB8-91422B9A8CE1}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSDTC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\partmgr\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MozillaMaintenance\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPREFMP\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv2",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\elxstor",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore\\SR",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iScsiPrt\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MozillaMaintenance",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vdrvroot",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dnscache\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MMCSS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TCPIP6\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager\\Interactive",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adp94xx\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gpsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wmiApSrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProtectedStorage",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VgaSave\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b57nd60a",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CLFS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ndisuio\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wscsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB02381F-D652-4B1C-894A-712498C62C51}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dmvsc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsata\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b57nd60a\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FDResPub\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CSC\\Parameters",
"HKEY_CURRENT_USER\\SOFTWARE\\Classes\\exefile\\shell\\open\\command",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Rasl2tp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hcw85cir\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A48CABBF-24C8-4B87-B00F-9261807C3B43}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\scfilter",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mountmgr\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\OptinNotification",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ws2ifsl\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WIMMount",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storvsc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPQM\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Filetrace",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SENS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\partmgr",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serenum",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TBS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteAccess",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisWan",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fastfat\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WSearch",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql40xx",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EFS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ebdrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\secdrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vsmraid\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb20\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ksthunk\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D018DE2F-F02A-4BDB-BA74-56BCD427BE40}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MsRPC\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SysMain\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffdisk",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Smb\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Smb",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecPkg",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdio\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Winmgmt\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CDA5F4EE-8293-4A5D-8564-04CD067D1A85}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arcsas",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0004",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0007",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0006",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0001",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0000",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0003",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0002",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid4",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SamSs",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0009",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0008",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VMBusHID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb20",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0005",
"HKEY_USERS\\.DEFAULT\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\idsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI\\ResolutionHost",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpsdrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SENS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dnscache",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wudfsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\eventlog",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SamSs\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb10",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DfsC\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS2",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Compbatt\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FB3C354D-297A-4EB2-9B58-090F6361906B}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wuauserv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\COMSysApp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wdf01000",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iirsp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TCPIP6",
"HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gpsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbccgp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpahci",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDTCP",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\crcdisk\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mup\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\aliide",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\1394ohci\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetTcpPortSharing",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{551B3807-871F-4E48-A943-2330449F0615}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPNAT",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCPolicySvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCPolicySvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdrom\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\USBSTOR\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5BE46CE1-CA9B-4CAD-B2E9-8C3F7716AF90}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WANARP",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisCap\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SessionAgent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\spldr",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry\\RegIdleBackup",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmPass",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Beep\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pci\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ErrDev\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppIDSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\aliide\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupListener\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltLo",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uliagpkx\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msdsm",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SharedAccess\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RecordingRestart",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AeLookupSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Browser\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\netprofm",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdPHost\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcmcia\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SNMPTRAP",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\megasas\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CryptSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\luafv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\luafv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DfsC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbprint\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Modem\\Parameters",
"HKEY_USERS\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msahci",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netman",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Winmgmt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EFS",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A8B18D02-60CD-4305-90CC-7DAAC028BDCD}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdhid\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CNG\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_FC\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsi",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UI0Detect\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KtmRm\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPCLOCK",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv2\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\COMSysApp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdrom",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ALG",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisTapi\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MpsSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\blbdrive",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltUp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HDAudBus",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\GadgetManager",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid4\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelide",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ACPI\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IKEEXT\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\seclogon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pla",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bthserv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProtectedStorage\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinHttpAutoProxySvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppMgmt\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehRecvr",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AeLookupSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bthserv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pci",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBT\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System\\ConvertLogEntries",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPAutoReg",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DPS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasSstp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcw",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmPass\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PEAUTH",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TabletInputService",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehRecvr\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Spooler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcmcia",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbehci\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft",
"HKEY_USERS\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidUsb",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk\\Proxy",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSiSCSI\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsbs",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MpsSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BITS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrustedInstaller",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VSS\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B43033E6-1453-4AD6-AFBA-C03CFC178286}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteRegistry\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B78DBF96-841E-4336-BFE9-1C4975F9DA60}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelppm",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid2",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Spooler\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gagp30kx",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasMan",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelide\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bowser",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPDBusEnum\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MpIdleTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WacomPen",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_64\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dot3svc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wd",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\agp440",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WmiAcpi",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{874CFED9-D01D-4D16-9775-B8A7A05004BF}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msiserver\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serial\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\defragsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecPkg\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FsDepends",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\monitor\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPWD",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgrx",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IpFilterDriver",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb10\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location\\Notifications",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MTConfig",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPCSvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MegaSR\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PerfHost",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srvnet",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7F9C951C-D364-4B70-8D07-D2C9B7F76E35}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Null",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\s3cap",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPCDD\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC\\HotStart",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vga",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPMIDRV",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hwpolicy",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EapHost",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\AutoWake",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsiproxy\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Npfs\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dhcp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\StorSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\upnphost",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volsnap",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\StorSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vmbus\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wlansvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CSC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0010",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0011",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A7C73732-9F11-4281-8D19-764D4EC9D94D}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7DC691A2-CB15-44DB-853C-19938051BB22}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ntfs",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wanarpv6\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SSDPSRV\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{994C86AD-A929-4B2C-88A0-4E25A107A029}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VMBusHID\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSKSSRV",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrSerWdm",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBatt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WebClient\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-32-544",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCardSvr",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbuhci",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mshidkmdf",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SDRSVC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KeyIso\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasPppoe",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_32",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPQM",
"HKEY_LOCAL_MACHINE\\Software\\Classes\\htmlfile\\shell\\open\\command",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdPPM",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\idsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\spldr\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras\\MobilityManager",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgr\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbprint",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FsDepends\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioEndpointBuilder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanWorkstation\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msisadrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDPIPE\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ShellHWDetection",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbhub",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbcir",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uliagpkx",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsi\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vwifibus\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EapHost\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iphlpsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vds\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbccgp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WfpLwf\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MTConfig\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tcpipreg\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AFD\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{28011108-68DF-4C73-B91B-57427D501BBA}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sbp2port",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdfs\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\exfat\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpio",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiServiceHost",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WfpLwf",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WwanSvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasMan\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Appinfo\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iaStorV\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fvevol\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WudfPf",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dot3svc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WerSvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI\\LPRemove",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiSystemHost",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2pimsvc\\Parameters",
"HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AcpiPmi",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PlugPlay\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HdAudAddService\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkCards",
"HKEY_CURRENT_USER\\Software\\Sysinternals",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PeerDistSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsiproxy",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppMgmt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HDAudBus\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b06bdrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FileInfo\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPMIDRV\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Fax",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WwanSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wmiApSrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPBusEnum",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TapiSrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SharedAccess",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql40xx\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CscService",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SensrSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisTapi",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbMdm",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDProxy",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UxSms",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mcx2Svc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PlugPlay",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdPPM\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B936B1AF-0C7E-4C4D-84F1-CF67453259A1}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\circlass\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVE\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vhdmp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\seclogon\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SCSI",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Processor",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uagp35\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPENCDD\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Themes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msiserver",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ksthunk",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ShellHWDetection\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iirsp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\W32Time\\Parameters",
"HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance\\Disabled",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\crcdisk",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Parport\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Msfs",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrkWks\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WacomPen\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidIr\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IRENUM",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppuinotify",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HdAudAddService",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Compbatt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F6B1AFFE-48F0-4340-9F59-C73DDA17C17D}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mssmbios\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swprv",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{40DD7C5E-DA67-4A78-B96C-582A4CBAEDF3}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdxata\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\eventlog\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProfSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msdsm\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBIOS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mssmbios",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltLo\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvstor",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvraid\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasSstp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSKSSRV\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C016366B-7126-46CA-B36B-592A3D95A60B}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IpFilterDriver\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mup",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgr",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vhdmp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TabletInputService\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdyboost",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdfs",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wscsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioEndpointBuilder\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wecsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffdisk\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAuto",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Disk\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdclass",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\circlass"
],
"command_line": [
"\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe\" -accepteula",
"\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe\" -a s -ct -m -h *",
"\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe\" -accepteula"
],
"file_written": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe"
],
"regkey_deleted": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Sidebar",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\mctadmin"
],
"connects_ip": [
"103.114.163.252"
],
"file_exists": [
"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\rdpclip",
"C:\\Windows\\System32\\drivers\\amdk8.sys",
"C:\\Program Files\\Windows Media Player\\wmpnetwk.exe",
"C:\\Python27\\python.exe",
"C:\\Windows\\System32\\drivers\\filetrace.sys",
"C:\\Windows\\SysWOW64\\rundll32.exe",
"C:\\Windows\\System32\\certprop.dll",
"C:\\Windows\\System32\\drivers\\ndisuio.sys",
"C:\\Windows\\System32\\drivers\\monitor.sys",
"C:\\Windows\\System32\\drivers\\WUDFPf.sys",
"C:\\Windows\\System32\\svchost.exe -k netsvcs.dll",
"C:\\Windows\\SysWOW64\\iedkcs32.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf",
"C:\\Windows\\System32\\drivers\\wfplwf.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
"C:\\Windows\\System32\\drivers\\blbdrive.sys",
"C:\\Windows\\System32\\clfs.sys",
"C:\\Windows\\System32\\drivers\\netbios.sys",
"C:\\Windows\\System32\\drivers\\mstee.sys",
"C:\\Windows\\System32\\drivers\\hidir.sys",
"C:\\Windows\\System32\\drivers\\rasl2tp.sys",
"C:\\Windows\\System32\\drivers\\srvnet.sys",
"C:\\Python27\\Scripts\\rdpclip.exe",
"C:\\Windows\\System32\\drivers\\asyncmac.sys",
"C:\\Windows\\System32\\svchost.exe -k bthsvcs",
"C:\\Windows\\System32\\KMSVC.DLL",
"C:\\Windows\\System32\\drivers\\flpydisk.sys",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation.dll",
"C:\\Windows\\System32\\drivers\\lsi_sas2.sys",
"C:\\Windows\\System32\\drivers\\mrxdav.sys",
"C:\\Windows\\System32\\drivers\\mountmgr.sys",
"C:\\Windows\\System32\\svchost.exe -k NetworkService",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
"C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation.dll",
"C:\\Windows\\System32\\drivers\\rdyboost.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MobilePC\\HotStart",
"C:\\Windows\\System32\\drivers\\wacompen.sys",
"C:\\Windows\\System32\\FDResPub.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MUI\\LPRemove",
"C:\\Windows\\System32\\drivers\\circlass.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
"C:\\Windows\\System32\\drivers\\CompositeBus.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
"C:\\Windows\\System32\\drivers\\fdc.sys",
"C:\\Windows\\System32\\svchost.exe -k NetSvcs.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SystemRestore\\SR",
"C:\\Windows\\System32\\drivers\\bthmodem.sys",
"C:\\Windows\\System32\\drivers\\compbatt.sys",
"C:\\Program Files\\Windows Sidebar\\Sidebar.exe \\autoRun",
"C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation",
"C:\\Windows\\System32\\QAGENTRT.DLL",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation.com",
"C:\\Python27\\cmd.exe",
"C:\\Windows\\System32\\wevtsvc.dll",
"C:\\Windows\\System32\\iedkcs32.dll",
"C:\\Windows\\System32\\drivers\\RDPCDD.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RegisterSearch",
"C:\\Windows\\System32\\mctadmin.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Location\\Notifications",
"C:\\Windows\\System32\\rundll32.exe",
"C:\\Windows\\System32\\drivers\\BrUsbSer.sys",
"C:\\Windows\\System32\\drivers\\vms3cap.sys",
"C:\\Windows\\System32\\drivers\\stexstor.sys",
"C:\\Windows\\System32\\drivers\\BrFiltUp.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
"C:\\Windows\\System32\\drivers\\mshidkmdf.sys",
"C:\\Windows\\System32\\dhcpcore.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\AitAgent",
"C:\\Users\\cuck\\AppData\\LocalLow",
"C:\\Windows\\System32\\drivers\\TsUsbGD.sys",
"C:\\Windows\\System32\\drivers\\HpSAMD.sys",
"C:\\Windows\\System32\\drivers\\E1G6032E.sys",
"C:\\Windows\\System32\\drivers\\msdsm.sys",
"C:\\Windows\\System32\\drivers\\lltdio.sys",
"C:\\Windows\\System32\\drivers\\vhdmp.sys",
"C:\\tmpyzbctd\\bin\\inject-x64.exe",
"C:\\Windows\\System32\\drivers\\usbuhci.sys",
"C:\\Windows\\System32\\drivers\\pciide.sys",
"C:\\Windows\\System32\\dwm.exe",
"C:\\Windows\\System32\\drivers\\rassstp.sys",
"C:\\Windows\\System32\\rpcss.dll",
"C:\\Windows\\System32\\drivers\\IPMIDrv.sys",
"C:\\Windows\\SysWOW64\\ie4uinit.exe",
"C:\\Windows\\System32\\drivers\\ndis.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
"C:\\Windows\\System32\\ListSvc.dll",
"C:\\Windows\\System32\\drivers\\tunnel.sys",
"C:\\Windows\\System32\\drivers\\hwpolicy.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
"C:\\Windows\\System32\\bthserv.dll",
"C:\\Windows\\System32\\drivers\\sisraid4.sys",
"C:\\Windows\\System32\\iphlpsvc.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Ras\\MobilityManager",
"C:\\Users\\cuck\\AppData\\Local\\Temp",
"C:\\Windows\\System32\\drivers\\ndiscap.sys",
"C:\\Windows\\System32\\drivers\\umpass.sys",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled",
"C:\\Windows\\System32\\drivers\\bowser.sys",
"C:\\Windows\\System32\\drivers\\partmgr.sys",
"C:\\Windows\\System32\\drivers\\iaStorV.sys",
"C:\\Windows\\System32\\drivers\\usbccgp.sys",
"C:\\Windows\\System32\\cmd.exe",
"C:\\Windows\\System32\\drivers\\sffp_sd.sys",
"C:\\Windows\\System32\\drivers\\volsnap.sys",
"C:\\Windows\\System32\\svchost.exe -k LocalService.exe",
"C:\\Windows\\System32\\drivers\\mpsdrv.sys",
"C:\\Windows\\System32\\drivers\\wmiacpi.sys",
"C:\\Windows\\System32\\drivers\\MegaSR.sys",
"C:\\Windows\\System32\\drivers\\adpu320.sys",
"C:\\Windows\\SysWOW64\\unregmp2.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Task Manager\\Interactive",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation",
"C:\\Windows\\System32\\drivers\\cdrom.sys",
"C:\\Windows\\System32\\drivers\\BrFiltLo.sys",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork.dll",
"C:\\Windows\\System32\\AxInstSv.dll",
"C:\\Windows\\SysWOW64\\mscories.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
"C:\\Windows\\System32\\drivers\\pcw.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Registry\\RegIdleBackup",
"C:\\Windows\\System32\\svchost.exe -k DcomLaunch.com",
"C:\\Windows\\System32\\drivers\\megasas.sys",
"C:\\Windows\\System32\\drivers\\modem.sys",
"C:\\Windows\\System32\\unregmp2.exe",
"C:\\Windows\\System32\\drivers\\adp94xx.sys",
"C:\\Windows\\System32\\drivers\\iirsp.sys",
"C:\\Windows\\System32\\userinit.exe",
"C:\\Windows\\System32\\drivers\\rspndr.sys",
"C:\\Windows\\System32\\drivers\\hdaudbus.sys",
"C:\\Windows\\System32\\drivers\\vga.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
"C:\\Windows\\System32\\drivers\\wanarp.sys",
"C:\\Windows\\System32\\bdesvc.dll",
"C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe",
"C:\\Windows\\System32\\drivers\\dmvsc.sys",
"C:\\Windows\\System32\\drivers\\FsDepends.sys",
"C:\\Windows\\System32\\conhost.exe",
"C:\\Windows\\System32\\drivers\\sisraid2.sys",
"C:\\Windows\\System32\\drivers\\ULIAGPKX.SYS",
"C:\\Windows\\System32\\drivers\\rasacd.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Maintenance\\WinSAT",
"C:\\Windows\\System32\\drivers\\hcw85cir.sys",
"C:\\Windows\\System32\\drivers\\VMBusHID.sys",
"C:\\Windows\\System32\\svchost.exe -k defragsvc",
"C:\\Windows\\System32\\drivers\\intelide.sys",
"C:\\Windows\\System32\\mscories.dll",
"C:\\Windows\\System32\\drivers\\vmstorfl.sys",
"C:\\Windows\\System32\\svchost.exe -k.dll",
"C:\\Windows\\System32\\drivers\\ipfltdrv.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
"C:\\Windows\\System32\\drivers\\HdAudio.sys",
"C:\\Windows\\System32\\smss.exe",
"C:\\Windows\\System32\\drivers\\srv.sys",
"C:\\Windows\\System32\\drivers\\msiscsi.sys",
"C:\\Windows\\System32\\drivers\\CmBatt.sys",
"C:\\Windows\\System32\\svchost.exe -k LocalService.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
"C:\\Windows\\System32\\svchost.exe -k NetworkService.com",
"C:\\Windows\\System32\\drivers\\bxvbda.sys",
"C:\\Python27\\Scripts\\explorer.exe",
"C:\\Python27\\IconCodecService.dll",
"C:\\Windows\\System32\\drivers\\vwifibus.sys",
"C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\ntexe.cat",
"C:\\Windows\\System32\\drivers\\drmkaud.sys",
"C:\\Windows\\System32\\appidsvc.dll",
"C:\\Windows\\System32\\drivers\\fvevol.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork.com",
"C:\\Windows\\System32\\es.dll",
"C:\\Windows\\System32\\drivers\\ksthunk.sys",
"C:\\Windows\\System32\\drivers\\ipnat.sys",
"C:\\Windows\\System32\\drivers\\kbdhid.sys",
"C:\\Windows\\System32\\alg.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
"C:\\Windows\\System32\\drivers\\disk.sys",
"C:\\Windows\\System32\\svchost.exe -k DcomLaunch.dll",
"C:\\Windows\\System32\\lsass.exe",
"C:\\Windows\\System32\\drivers\\kbdclass.sys",
"C:\\Windows\\System32\\p2pcollab.dll",
"C:\\Windows\\System32\\drivers\\fltMgr.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
"C:\\Windows\\System32\\drivers\\smb.sys",
"C:\\Windows\\System32\\drivers\\isapnp.sys",
"C:\\Windows\\System32\\drivers\\amdsbs.sys",
"C:\\Windows\\System32\\lsm.exe",
"C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Autochk\\Proxy",
"C:\\Windows\\System32\\drivers\\usbcir.sys",
"C:\\Windows\\System32\\drivers\\vmbus.sys",
"C:\\Windows\\System32\\drivers\\tdpipe.sys",
"C:\\Windows\\System32\\drivers\\appid.sys",
"C:\\Windows\\System32\\drivers\\cng.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
"C:\\Windows\\System32\\drivers\\afd.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
"C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup.dll",
"C:\\Windows\\System32\\gpsvc.dll",
"C:\\Windows\\System32\\svchost.exe -k.exe",
"C:\\Windows\\System32\\drivers\\tcpip.sys",
"C:\\Windows\\System32\\services.exe",
"C:\\Windows\\System32\\dot3svc.dll",
"C:\\Windows\\System32\\svchost.exe -k defragsvc.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
"C:\\Windows\\System32\\drivers\\BrSerWdm.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
"C:\\Windows\\System32\\catroot2\\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\\",
"C:\\Windows\\System32\\drivers\\serial.sys",
"C:\\Windows\\System32\\drivers\\lsi_sas.sys",
"C:\\Windows\\System32\\fdPHost.dll",
"C:\\Windows\\System32\\drivers\\dxgkrnl.sys",
"C:\\Windows\\System32\\drivers\\nvstor.sys",
"C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup.com",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc",
"C:\\Windows\\System32\\FXSSVC.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
"C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WDI\\ResolutionHost",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ehDRMInit",
"C:\\Windows\\System32\\IKEEXT.DLL",
"C:\\Windows\\SysWOW64\\regsvr32.exe",
"C:\\Windows\\System32\\drivers\\csc.sys",
"C:\\Windows\\System32\\drivers\\i8042prt.sys",
"C:\\Windows\\System32\\drivers\\parport.sys",
"C:\\Windows\\System32\\drivers\\nfrd960.sys",
"C:\\Windows\\System32\\drivers\\msahci.sys",
"C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe",
"C:\\Windows\\System32\\ipbusenum.dll",
"C:\\Windows\\System32\\winlogon.exe",
"C:\\Windows\\System32\\drivers\\sfloppy.sys",
"C:\\Windows\\System32\\drivers\\ndiswan.sys",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
"C:\\Windows\\System32\\drivers\\RDPENCDD.sys",
"C:\\Windows\\System32\\drivers\\nwifi.sys",
"C:\\Windows\\System32\\drivers\\ws2ifsl.sys",
"C:\\Windows\\System32\\drivers\\PEAuth.sys",
"C:\\Windows\\System32\\drivers\\NV_AGP.SYS",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
"C:\\Windows\\System32\\drivers\\rdpdr.sys",
"C:\\Windows\\System32\\drivers\\elxstor.sys",
"C:\\Windows\\System32\\drivers\\hidusb.sys",
"C:\\Windows\\System32\\drivers\\ql40xx.sys",
"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\rdpclip.com",
"C:\\Windows\\System32\\msdtckrm.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork",
"C:\\Python27\\Scripts\\rdpclip",
"C:\\Python27\\Scripts\\cmd.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
"C:\\Windows\\System32\\drivers\\amdxata.sys",
"C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted.dll",
"C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted",
"C:\\Windows\\System32\\NOTEPAD.EXE %1",
"C:\\Windows\\System32\\drivers\\usbhub.sys",
"C:\\Windows\\System32\\wininit.exe",
"C:\\Python27\\rdpclip.com",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\",
"C:\\Windows\\System32\\aelupsvc.dll",
"C:\\Windows\\System32\\drivers\\nsiproxy.sys",
"C:\\Windows\\System32\\drivers\\mup.sys",
"C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation.exe",
"C:\\Windows\\System32\\BFE.DLL",
"C:\\Windows\\explorer.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
"C:\\Python27\\Scripts\\rdpclip.com",
"C:\\Windows\\System32\\drivers\\netbt.sys",
"C:\\Windows\\System32\\svchost.exe -k LocalService",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
"C:\\Windows\\System32\\drivers\\atapi.sys",
"C:\\Windows\\System32\\audiosrv.dll",
"C:\\Windows\\System32\\drivers\\storvsc.sys",
"C:\\Program Files\\Windows Mail\\WinMail.exe",
"C:\\Windows\\System32\\drivers\\fileinfo.sys",
"C:\\Windows\\System32\\drivers\\wd.sys",
"C:\\Windows\\System32\\drivers\\RDPREFMP.sys",
"C:\\Windows\\System32\\drivers\\pacer.sys",
"C:\\Windows\\System32\\drivers\\dfsc.sys",
"C:\\Windows\\System32\\svchost.exe -k bthsvcs.exe",
"C:\\Windows\\System32\\drivers\\mrxsmb10.sys",
"C:\\Windows\\System32\\cscsvc.dll",
"C:\\Windows\\System32\\drivers\\mrxsmb20.sys",
"C:\\Windows\\System32\\drivers\\pci.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation.exe",
"C:\\Windows\\System32\\appmgmts.dll",
"C:\\Windows\\Microsoft.Net\\Framework64\\v3.0\\WPF\\PresentationFontCache.exe",
"C:\\Users\\cuck\\AppData\\Roaming",
"C:\\Windows\\System32\\drivers\\b57nd60a.sys",
"C:\\Windows\\System32\\drivers\\wimmount.sys",
"C:\\Python27\\Scripts\\IconCodecService.dll",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
"C:\\Windows\\System32\\drivers\\TsUsbFlt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
"C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup.exe",
"C:\\Windows\\System32\\svchost.exe -k NetSvcs",
"C:\\Python27\\SystemPropertiesPerformance.exe",
"C:\\Windows\\rdpclip",
"C:\\Windows\\System32\\drivers\\acpi.sys",
"C:\\Windows\\System32\\drivers\\udfs.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\AutoWake",
"C:\\Windows\\System32\\drivers\\raspppoe.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
"C:\\Windows\\System32\\drivers\\hidbth.sys",
"C:\\Python27\\Scripts\\regsvr32.exe",
"C:\\Windows\\System32\\drivers\\irenum.sys",
"C:\\Windows\\System32\\cryptsvc.dll",
"C:\\Windows\\System32\\drivers\\srv2.sys",
"C:\\Windows\\System32\\SearchIndexer.exe",
"C:\\Windows\\System32\\drivers\\serenum.sys",
"C:\\Windows\\System32\\drivers\\intelppm.sys",
"C:\\Windows\\System32\\drivers\\mskssrv.sys",
"C:\\Windows\\System32\\drivers\\mssmbios.sys",
"C:\\Windows\\System32\\drivers\\BrSerId.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
"C:\\Windows\\System32\\provsvc.dll",
"C:\\Windows\\System32\\drivers\\cdfs.sys",
"C:\\Windows\\System32\\svchost.exe -k defragsvc.com",
"C:\\Windows\\System32\\drivers\\usbohci.sys",
"C:\\Windows\\System32\\catroot\\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\\",
"C:\\Windows\\System32\\drivers\\vsmraid.sys",
"C:\\Program Files (x86)\\Windows Mail\\WinMail.exe",
"C:\\Windows\\System32\\drivers\\amdppm.sys",
"C:\\Windows\\System32\\drivers\\vdrvroot.sys",
"C:\\Windows\\System32\\drivers\\pcmcia.sys",
"C:\\Windows\\System32\\hidserv.dll",
"C:\\Windows\\System32\\svchost.exe",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
"C:\\Windows\\System32\\svchost.exe -k netsvcs.com",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SessionAgent",
"C:\\Windows\\System32\\drivers\\mspqm.sys",
"C:\\Windows\\System32\\drivers\\msisadrv.sys",
"C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
"C:\\Windows\\System32\\IconCodecService.dll",
"C:\\Windows\\System32\\drivers\\nvraid.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
"C:\\Windows\\System32\\rdpclip.com",
"C:\\Windows\\System32\\dnsrslvr.dll",
"C:\\Windows\\System32\\rdpclip",
"C:\\Windows\\System32\\eapsvc.dll",
"C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted.com",
"C:\\Windows\\System32\\regsvr32.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
"C:\\Windows\\System32\\drivers\\mouclass.sys",
"C:\\Windows\\System32\\drivers\\vgapnp.sys",
"C:\\Windows\\System32\\ie4uinit.exe",
"C:\\Windows\\System32\\drivers\\volmgrx.sys",
"C:\\Windows\\System32\\svchost.exe -k defragsvc.dll",
"C:\\Windows\\System32\\drivers\\arcsas.sys",
"C:\\Windows\\System32\\drivers\\amdide.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
"C:\\Windows\\System32\\browser.dll",
"C:\\Windows\\System32\\drivers\\termdd.sys",
"C:\\Windows\\System32\\svchost.exe -k NetSvcs.com",
"C:\\Windows\\System32\\drivers\\swenum.sys",
"C:\\Windows\\System32\\taskhost.exe",
"C:\\Windows\\System32\\drivers\\luafv.sys",
"C:\\Python27\\rdpclip",
"C:\\Windows\\System32\\drivers\\tdx.sys",
"C:\\Windows\\System32\\drivers\\cmdide.sys",
"C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\infocard.exe",
"C:\\Windows\\System32\\drivers\\sbp2port.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\PolicyConverter",
"C:\\Windows\\System32\\drivers\\hidbatt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
"C:\\Windows\\System32\\drivers\\lsi_fc.sys",
"C:\\Windows\\System32\\drivers\\ksecpkg.sys",
"C:\\Windows\\System32\\drivers\\USBSTOR.SYS",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURActivate",
"C:\\Windows\\System32\\SystemPropertiesPerformance.exe",
"C:\\Windows\\ehome\\ehrecvr.exe",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
"C:\\Python27\\Scripts\\SystemPropertiesPerformance.exe",
"C:\\Windows\\System32\\drivers\\tssecsrv.sys",
"C:\\Windows\\System32\\drivers\\ndistapi.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Diagnosis\\Scheduled",
"C:\\Windows\\System32\\drivers\\Wdf01000.sys",
"C:\\Windows\\System32\\drivers\\discache.sys",
"C:\\Windows\\System32\\svchost.exe -k bthsvcs.dll",
"C:\\Windows\\System32\\drivers\\usbprint.sys",
"C:\\Windows\\System32\\drivers\\rdbss.sys",
"C:\\Windows\\System32\\drivers\\errdev.sys",
"C:\\Windows\\System32\\drivers\\processr.sys",
"C:\\Windows\\System32\\dllhost.exe",
"C:\\Windows\\System32\\drivers\\rdpbus.sys",
"C:\\Windows\\System32\\drivers\\mspclock.sys",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted.exe",
"C:\\Windows\\System32\\drivers\\aliide.sys",
"C:\\Windows\\System32\\drivers\\mpio.sys",
"C:\\Python27\\rdpclip.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
"C:\\Windows\\System32\\drivers\\evbda.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\mcupdate",
"C:\\Windows\\System32\\svchost.exe -k NetworkService.exe",
"C:\\Windows\\System32\\qmgr.dll",
"C:\\Windows\\System32\\defragsvc.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
"C:\\Windows\\System32\\FntCache.dll",
"C:\\Windows\\System32\\drivers\\ql2300.sys",
"C:\\Windows\\System32\\drivers\\umbus.sys",
"C:\\Windows\\System32\\drivers\\tdtcp.sys",
"C:\\Windows\\System32\\drivers\\acpipmi.sys",
"C:\\Windows\\System32\\svchost.exe -k netsvcs",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
"C:\\Windows\\System32\\drivers\\UAGP35.SYS",
"C:\\Windows\\System32\\svchost.exe -k NetworkService.dll",
"C:\\Windows\\System32\\drivers\\adpahci.sys",
"C:\\Python27\\regsvr32.exe",
"C:\\Windows\\System32\\drivers\\sffdisk.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
"C:\\Windows\\System32\\drivers\\arc.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
"C:\\Windows\\System32\\dnsapi.dll",
"C:\\Windows\\System32\\rdpclip.exe",
"C:\\Windows\\System32\\drivers\\ohci1394.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RecordingRestart",
"C:\\Windows\\System32\\svchost.exe -k netsvcs.exe",
"C:\\Windows\\System32\\drivers\\volmgr.sys",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RAC\\RacTask",
"C:\\Windows\\System32\\drivers\\agilevpn.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
"C:\\Windows\\System32\\drivers\\GAGP30KX.SYS",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe",
"C:\\Windows\\rdpclip.com",
"C:\\Windows\\System32\\svchost.exe -k bthsvcs.com",
"C:\\Windows\\System32\\dps.dll",
"C:\\Windows\\ehome\\ehsched.exe",
"C:\\Windows\\System32\\csrss.exe",
"C:\\Windows\\System32\\svchost.exe -k.com",
"C:\\Windows\\System32\\drivers\\1394ohci.sys",
"C:\\Windows\\System32\\drivers\\ksecdd.sys",
"C:\\Windows\\System32\\drivers\\usbehci.sys",
"C:\\Windows\\System32\\drivers\\amdsata.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\GadgetManager",
"C:\\Windows\\System32\\drivers\\MTConfig.sys",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted.com",
"C:\\Windows\\System32\\drivers\\mrxsmb.sys",
"C:\\Windows\\System32\\drivers\\crcdisk.sys",
"C:\\Windows\\System32\\drivers\\mouhid.sys",
"C:\\Windows\\System32\\drivers\\BrUsbMdm.sys",
"C:\\Windows\\System32\\drivers\\lsi_scsi.sys",
"C:\\Windows\\System32\\svchost.exe -k NetSvcs.exe",
"C:\\Windows\\System32\\drivers\\sermouse.sys",
"C:\\Windows\\System32\\spoolsv.exe",
"C:\\Windows\\System32\\drivers\\scfilter.sys",
"C:\\Windows\\System32\\drivers\\http.sys",
"C:\\Windows\\System32\\appinfo.dll",
"C:\\Windows\\System32\\drivers\\raspptp.sys",
"C:\\Windows\\inf\\",
"C:\\Windows\\System32\\svchost.exe -k LocalService.com",
"C:\\Windows\\System32\\fveui.dll",
"C:\\Windows\\System32\\svchost.exe -k DcomLaunch.exe",
"C:\\Windows\\System32\\drivers\\viaide.sys",
"C:\\Python27\\explorer.exe",
"C:\\Windows\\System32\\drivers\\tcpipreg.sys",
"C:\\Windows\\System32\\drivers\\qwavedrv.sys",
"C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation.com",
"C:\\Windows\\System32\\wbem\\rdpclip",
"C:\\Windows\\System32\\drivers\\AGP440.sys",
"C:\\Windows\\System32\\svchost.exe -k DcomLaunch",
"C:\\Windows\\System32\\explorer.exe",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork.exe",
"C:\\Windows\\System32\\wbem\\rdpclip.com",
"C:\\Windows\\System32\\svchost.exe -k",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
"C:\\Windows\\System32\\drivers\\sffp_mmc.sys"
],
"file_failed": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\%USERPROFILE%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\aitagent",
"C:\\ProgramData\\Microsoft\\desktop.ini",
"C:\\Windows\\ehome\\ehrec",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\B8CC409ACDBF2A2FE04C56F2875B1FD6",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\BthUdTask.exe",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\F90F18257CBB4D84216AC1E1F3BB2C76",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\C24EC5BDAF13613245B4CECC3DE91DC6",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\%1",
"C:\\Program",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\696F3DE637E6DE85B458996D49D759AD",
"C:\\Windows\\ehome\\mcupdate",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\%USERPROFILE%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\desktop.ini",
"C:\\Windows\\System32\\d",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\sc.exe",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\%USERPROFILE%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup"
],
"resolves_host": [
"crl.microsoft.com",
"www.microsoft.com"
],
"guid": [
"{add8ba80-002b-11d0-8f0f-00c04fd7d062}",
"{08244ee6-92f0-47f2-9fc9-929baa2e7235}",
"{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
"{4e77131d-3629-431c-9818-c5679dc83e81}",
"{d9144dcd-e998-4eca-ab6a-dcd83ccba16d}",
"{dffacdc5-679f-4156-8947-c5c76bc0b67f}",
"{0c6c4200-c589-11d0-999a-00c04fd655e1}",
"{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}"
],
"file_read": [
"C:\\Windows\\System32\\drivers\\amdk8.sys",
"C:\\Program Files\\Windows Media Player\\wmpnetwk.exe",
"C:\\Python27\\python.exe",
"C:\\Windows\\System32\\drivers\\filetrace.sys",
"C:\\Windows\\System32\\drivers\\ndisuio.sys",
"C:\\Windows\\System32\\drivers\\monitor.sys",
"C:\\Windows\\System32\\drivers\\WUDFPf.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
"C:\\Windows\\System32\\aepdu.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
"C:\\Windows\\System32\\drivers\\blbdrive.sys",
"C:\\Windows\\System32\\clfs.sys",
"C:\\Windows\\System32\\drivers\\netbios.sys",
"C:\\Windows\\System32\\drivers\\mstee.sys",
"C:\\Windows\\System32\\drivers\\hidir.sys",
"C:\\Windows\\System32\\drivers\\rasl2tp.sys",
"C:\\Windows\\System32\\drivers\\srvnet.sys",
"C:\\Windows\\System32\\drivers\\ipfltdrv.sys",
"C:\\Windows\\System32\\drivers\\asyncmac.sys",
"C:\\Windows\\System32\\drivers\\flpydisk.sys",
"C:\\Windows\\System32\\drivers\\lsi_sas2.sys",
"C:\\Windows\\System32\\drivers\\mrxdav.sys",
"C:\\Windows\\System32\\drivers\\mountmgr.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
"C:\\Windows\\System32\\drivers\\rdyboost.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MobilePC\\HotStart",
"C:\\Windows\\System32\\drivers\\wacompen.sys",
"C:\\Users\\cuck\\Searches\\desktop.ini",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MUI\\LPRemove",
"C:\\Windows\\System32\\drivers\\circlass.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
"C:\\Windows\\System32\\drivers\\CompositeBus.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
"C:\\Windows\\System32\\drivers\\fdc.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SystemRestore\\SR",
"C:\\Windows\\System32\\drivers\\bthmodem.sys",
"C:\\Windows\\System32\\drivers\\compbatt.sys",
"C:\\Windows\\System32\\drivers\\RDPCDD.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RegisterSearch",
"C:\\Windows\\System32\\mctadmin.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Location\\Notifications",
"C:\\Windows\\System32\\drivers\\BrUsbSer.sys",
"C:\\Windows\\System32\\drivers\\vdrvroot.sys",
"C:\\Windows\\System32\\drivers\\stexstor.sys",
"C:\\Windows\\System32\\drivers\\BrFiltUp.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
"C:\\Windows\\System32\\drivers\\mshidkmdf.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\AitAgent",
"C:\\Windows\\System32\\drivers\\TsUsbGD.sys",
"C:\\Windows\\System32\\drivers\\HpSAMD.sys",
"C:\\Windows\\System32\\drivers\\E1G6032E.sys",
"C:\\Windows\\System32\\drivers\\msdsm.sys",
"C:\\Windows\\System32\\drivers\\lltdio.sys",
"C:\\Windows\\System32\\drivers\\vhdmp.sys",
"C:\\Windows\\System32\\drivers\\usbuhci.sys",
"C:\\Windows\\System32\\drivers\\pciide.sys",
"C:\\Windows\\System32\\dwm.exe",
"C:\\Windows\\System32\\drivers\\rassstp.sys",
"C:\\Windows\\System32\\drivers\\IPMIDrv.sys",
"C:\\Windows\\System32\\raserver.exe",
"C:\\Windows\\System32\\drivers\\ndis.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
"C:\\Windows\\System32\\drivers\\tunnel.sys",
"C:\\Windows\\System32\\drivers\\hwpolicy.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
"C:\\Windows\\System32\\drivers\\sisraid4.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Ras\\MobilityManager",
"C:\\Windows\\System32\\drivers\\ndiscap.sys",
"C:\\Windows\\System32\\drivers\\umpass.sys",
"C:\\Windows\\System32\\drivers\\bowser.sys",
"C:\\Windows\\System32\\drivers\\partmgr.sys",
"C:\\Windows\\System32\\drivers\\iaStorV.sys",
"C:\\Windows\\System32\\drivers\\wfplwf.sys",
"C:\\Windows\\System32\\drivers\\usbccgp.sys",
"C:\\Windows\\System32\\cmd.exe",
"C:\\Windows\\System32\\drivers\\sffp_sd.sys",
"C:\\Windows\\System32\\drivers\\volsnap.sys",
"C:\\Windows\\ehome\\mcupdate.exe",
"C:\\Windows\\System32\\drivers\\mpsdrv.sys",
"C:\\Windows\\System32\\drivers\\wmiacpi.sys",
"C:\\Windows\\System32\\drivers\\MegaSR.sys",
"C:\\Windows\\System32\\drivers\\adpu320.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Task Manager\\Interactive",
"C:\\Windows\\System32\\drivers\\cdrom.sys",
"C:\\Windows\\System32\\drivers\\BrFiltLo.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
"C:\\Windows\\System32\\drivers\\pcw.sys",
"C:\\Windows\\System32\\Defrag.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Registry\\RegIdleBackup",
"C:\\Windows\\System32\\drivers\\megasas.sys",
"C:\\Windows\\System32\\drivers\\modem.sys",
"C:\\Windows\\System32\\drivers\\adp94xx.sys",
"C:\\Windows\\System32\\drivers\\iirsp.sys",
"C:\\Windows\\System32\\drivers\\rspndr.sys",
"C:\\Windows\\System32\\drivers\\hdaudbus.sys",
"C:\\Windows\\System32\\drivers\\vga.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
"C:\\Windows\\System32\\drivers\\wanarp.sys",
"C:\\Windows\\System32\\drivers\\dmvsc.sys",
"C:\\Windows\\System32\\drivers\\FsDepends.sys",
"C:\\Windows\\System32\\conhost.exe",
"C:\\Windows\\System32\\drivers\\sisraid2.sys",
"C:\\Windows\\System32\\appidpolicyconverter.exe",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
"C:\\Windows\\System32\\drivers\\ULIAGPKX.SYS",
"C:\\Windows\\System32\\drivers\\rasacd.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Maintenance\\WinSAT",
"C:\\Windows\\System32\\drivers\\hcw85cir.sys",
"C:\\Windows\\System32\\drivers\\VMBusHID.sys",
"C:\\Windows\\System32\\drivers\\intelide.sys",
"C:\\Users\\cuck\\Favorites\\desktop.ini",
"C:\\Windows\\System32\\drivers\\vmstorfl.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
"C:\\Windows\\System32\\drivers\\HdAudio.sys",
"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe",
"C:\\Windows\\System32\\drivers\\srv.sys",
"C:\\Windows\\System32\\drivers\\msiscsi.sys",
"C:\\Windows\\System32\\drivers\\CmBatt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
"C:\\Windows\\System32\\drivers\\bxvbda.sys",
"C:\\Windows\\System32\\drivers\\vwifibus.sys",
"C:\\Windows\\System32\\drivers\\drmkaud.sys",
"C:\\Windows\\System32\\drivers\\fvevol.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
"C:\\Windows\\System32\\ndfapi.dll",
"C:\\Windows\\System32\\drivers\\ksthunk.sys",
"C:\\Windows\\System32\\drivers\\ipnat.sys",
"C:\\Windows\\System32\\drivers\\kbdhid.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
"C:\\Windows\\System32\\drivers\\disk.sys",
"C:\\Windows\\System32\\lpremove.exe",
"C:\\Windows\\System32\\lsass.exe",
"C:\\Windows\\System32\\drivers\\kbdclass.sys",
"C:\\Windows\\System32\\drivers\\fltMgr.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
"C:\\Windows\\System32\\drivers\\smb.sys",
"C:\\Windows\\System32\\drivers\\isapnp.sys",
"C:\\Windows\\System32\\drivers\\amdsbs.sys",
"C:\\Windows\\System32\\lsm.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Autochk\\Proxy",
"C:\\Windows\\System32\\drivers\\usbcir.sys",
"C:\\Windows\\System32\\drivers\\vmbus.sys",
"C:\\Windows\\System32\\drivers\\tdpipe.sys",
"C:\\Windows\\System32\\drivers\\appid.sys",
"C:\\Windows\\System32\\drivers\\cng.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
"C:\\Windows\\System32\\drivers\\afd.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
"C:\\Users\\cuck\\Videos\\desktop.ini",
"C:\\Windows\\System32\\drivers\\tcpip.sys",
"C:\\Windows\\System32\\services.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
"C:\\Windows\\System32\\drivers\\BrSerWdm.sys",
"C:\\Windows\\System32\\drivers\\ndiswan.sys",
"C:\\Users\\cuck\\Contacts\\desktop.ini",
"C:\\Windows\\System32\\drivers\\serial.sys",
"C:\\Windows\\System32\\drivers\\lsi_sas.sys",
"C:\\Windows\\System32\\DFDWiz.exe",
"C:\\Windows\\System32\\drivers\\dxgkrnl.sys",
"C:\\Windows\\System32\\dfdts.dll",
"C:\\Windows\\System32\\drivers\\nvstor.sys",
"C:\\Windows\\System32\\LocationNotifications.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WDI\\ResolutionHost",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ehDRMInit",
"C:\\Windows\\System32\\drivers\\csc.sys",
"C:\\Windows\\System32\\drivers\\i8042prt.sys",
"C:\\Windows\\System32\\gatherNetworkInfo.vbs",
"C:\\Windows\\System32\\drivers\\parport.sys",
"C:\\Windows\\System32\\drivers\\nfrd960.sys",
"C:\\Windows\\System32\\drivers\\msahci.sys",
"C:\\Program Files\\Windows Media Player\\wmpnscfg.exe",
"C:\\Windows\\System32\\winlogon.exe",
"C:\\Windows\\System32\\drivers\\sfloppy.sys",
"C:\\Windows\\System32\\drivers\\RDPENCDD.sys",
"C:\\Windows\\System32\\wininit.exe",
"C:\\Windows\\System32\\drivers\\nwifi.sys",
"C:\\Windows\\System32\\drivers\\ws2ifsl.sys",
"C:\\Windows\\System32\\drivers\\PEAuth.sys",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
"C:\\Windows\\System32\\drivers\\NV_AGP.SYS",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
"C:\\Windows\\System32\\drivers\\rdpdr.sys",
"C:\\Users\\cuck\\Pictures\\desktop.ini",
"C:\\Windows\\System32\\drivers\\elxstor.sys",
"C:\\Windows\\System32\\drivers\\hidusb.sys",
"C:\\Windows\\System32\\drivers\\ql40xx.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
"C:\\Windows\\System32\\drivers\\amdxata.sys",
"C:\\Windows\\System32\\drivers\\usbhub.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
"C:\\Windows\\System32\\drivers\\vms3cap.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
"C:\\Windows\\System32\\drivers\\nsiproxy.sys",
"C:\\Windows\\System32\\drivers\\mup.sys",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
"C:\\Windows\\System32\\BFE.DLL",
"C:\\Windows\\explorer.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
"C:\\Windows\\System32\\drivers\\netbt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
"C:\\Windows\\System32\\drivers\\atapi.sys",
"C:\\Windows\\System32\\drivers\\storvsc.sys",
"C:\\Windows\\System32\\drivers\\fileinfo.sys",
"C:\\Windows\\System32\\drivers\\wd.sys",
"C:\\Windows\\System32\\drivers\\RDPREFMP.sys",
"C:\\Windows\\System32\\drivers\\pacer.sys",
"C:\\Windows\\System32\\drivers\\dfsc.sys",
"C:\\Windows\\System32\\drivers\\mrxsmb10.sys",
"C:\\Users\\cuck\\Documents\\desktop.ini",
"C:\\Windows\\System32\\drivers\\mrxsmb20.sys",
"C:\\Windows\\System32\\appidcertstorecheck.exe",
"C:\\Windows\\System32\\drivers\\pci.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
"C:\\Windows\\System32\\drivers\\b57nd60a.sys",
"C:\\Windows\\System32\\drivers\\wimmount.sys",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
"C:\\Windows\\System32\\drivers\\TsUsbFlt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
"C:\\Windows\\System32\\drivers\\acpi.sys",
"C:\\Windows\\System32\\drivers\\udfs.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\AutoWake",
"C:\\Windows\\System32\\drivers\\raspppoe.sys",
"C:\\Users\\cuck\\Saved Games\\desktop.ini",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
"C:\\Windows\\System32\\drivers\\hidbth.sys",
"C:\\Windows\\System32\\drivers\\irenum.sys",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
"C:\\Windows\\System32\\drivers\\srv2.sys",
"C:\\Windows\\System32\\SearchIndexer.exe",
"C:\\Windows\\System32\\drivers\\serenum.sys",
"C:\\Windows\\System32\\drivers\\intelppm.sys",
"C:\\Windows\\System32\\drivers\\mskssrv.sys",
"C:\\Windows\\System32\\drivers\\mssmbios.sys",
"C:\\Windows\\System32\\drivers\\BrSerId.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
"C:\\Windows\\System32\\drivers\\agilevpn.sys",
"C:\\Windows\\System32\\drivers\\usbohci.sys",
"C:\\Windows\\System32\\drivers\\vsmraid.sys",
"C:\\Windows\\System32\\drivers\\amdppm.sys",
"C:\\Windows\\System32\\drivers\\pcmcia.sys",
"C:\\Windows\\System32\\svchost.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SessionAgent",
"C:\\Windows\\System32\\drivers\\mspqm.sys",
"C:\\Windows\\System32\\drivers\\msisadrv.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
"C:\\Windows\\System32\\drivers\\nvraid.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
"C:\\Windows\\ehome\\ehPrivJob.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
"C:\\Windows\\System32\\drivers\\mouclass.sys",
"C:\\Windows\\System32\\drivers\\vgapnp.sys",
"C:\\Windows\\System32\\drivers\\volmgrx.sys",
"C:\\Windows\\System32\\drivers\\arcsas.sys",
"C:\\Windows\\System32\\drivers\\amdide.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
"C:\\Windows\\System32\\powercfg.exe",
"C:\\Windows\\System32\\drivers\\termdd.sys",
"C:\\Program Files\\desktop.ini",
"C:\\Windows\\System32\\drivers\\swenum.sys",
"C:\\Windows\\System32\\taskhost.exe",
"C:\\Windows\\System32\\drivers\\luafv.sys",
"C:\\Windows\\System32\\drivers\\tdx.sys",
"C:\\Windows\\System32\\drivers\\cmdide.sys",
"C:\\Windows\\System32\\drivers\\sbp2port.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\PolicyConverter",
"C:\\Windows\\System32\\drivers\\hidbatt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
"C:\\Windows\\System32\\drivers\\lsi_fc.sys",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
"C:\\Windows\\System32\\drivers\\ksecpkg.sys",
"C:\\Windows\\System32\\drivers\\USBSTOR.SYS",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURActivate",
"C:\\Users\\cuck\\Music\\desktop.ini",
"C:\\Windows\\System32\\drivers\\tssecsrv.sys",
"C:\\Windows\\System32\\drivers\\ndistapi.sys",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Diagnosis\\Scheduled",
"C:\\Windows\\System32\\drivers\\Wdf01000.sys",
"C:\\Windows\\System32\\drivers\\discache.sys",
"C:\\Users\\cuck\\Desktop\\desktop.ini",
"C:\\Windows\\System32\\drivers\\usbprint.sys",
"C:\\Windows\\System32\\drivers\\rdbss.sys",
"C:\\Windows\\System32\\drivers\\errdev.sys",
"C:\\Windows\\System32\\drivers\\processr.sys",
"C:\\Windows\\System32\\drivers\\rdpbus.sys",
"C:\\Windows\\System32\\sc.exe",
"C:\\Windows\\System32\\drivers\\mspclock.sys",
"C:\\Windows\\System32\\drivers\\aliide.sys",
"C:\\Windows\\System32\\drivers\\mpio.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
"C:\\Windows\\System32\\drivers\\evbda.sys",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\mcupdate",
"C:\\Users\\cuck\\Downloads\\desktop.ini",
"C:\\Windows\\System32\\wermgr.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
"C:\\Windows\\System32\\drivers\\ql2300.sys",
"C:\\Windows\\System32\\drivers\\umbus.sys",
"C:\\Windows\\System32\\drivers\\tdtcp.sys",
"C:\\Windows\\System32\\drivers\\acpipmi.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
"C:\\Windows\\System32\\drivers\\UAGP35.SYS",
"C:\\Windows\\System32\\drivers\\adpahci.sys",
"C:\\Windows\\System32\\drivers\\sffdisk.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
"C:\\Windows\\System32\\notepad.exe",
"C:\\Windows\\System32\\drivers\\arc.sys",
"C:\\Program Files (x86)\\desktop.ini",
"C:\\Windows\\System32\\drivers\\ohci1394.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RecordingRestart",
"C:\\Windows\\System32\\drivers\\volmgr.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RAC\\RacTask",
"C:\\Windows\\System32\\drivers\\cdfs.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
"C:\\Windows\\System32\\drivers\\GAGP30KX.SYS",
"C:\\Windows\\System32\\csrss.exe",
"c:\\program files\\windows defender\\MpCmdRun.exe",
"C:\\Windows\\System32\\drivers\\1394ohci.sys",
"C:\\Windows\\System32\\drivers\\ksecdd.sys",
"C:\\Windows\\System32\\drivers\\usbehci.sys",
"C:\\Users\\desktop.ini",
"C:\\Windows\\System32\\drivers\\amdsata.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\GadgetManager",
"C:\\Windows\\System32\\drivers\\MTConfig.sys",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
"C:\\Windows\\System32\\drivers\\crcdisk.sys",
"C:\\Windows\\System32\\drivers\\mouhid.sys",
"C:\\Windows\\System32\\drivers\\BrUsbMdm.sys",
"C:\\Windows\\System32\\drivers\\lsi_scsi.sys",
"C:\\Windows\\System32\\drivers\\sermouse.sys",
"C:\\Windows\\System32\\spoolsv.exe",
"C:\\Windows\\System32\\drivers\\scfilter.sys",
"C:\\Windows\\System32\\sdclt.exe",
"C:\\Users\\cuck\\Links\\desktop.ini",
"C:\\Windows\\System32\\drivers\\http.sys",
"C:\\Windows\\System32\\drivers\\raspptp.sys",
"C:\\Windows\\System32\\drivers\\viaide.sys",
"C:\\Windows\\System32\\drivers\\tcpipreg.sys",
"C:\\Windows\\System32\\drivers\\qwavedrv.sys",
"C:\\Windows\\System32\\drivers\\mrxsmb.sys",
"C:\\Windows\\System32\\drivers\\AGP440.sys",
"C:\\Windows\\System32\\wsqmcons.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
"C:\\Windows\\System32\\drivers\\sffp_mmc.sys"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Attributes",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{3307E641-F5EE-49E6-A1FE-BFB5D671441C}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Type",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Favorites",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{448186F9-75B9-4FB7-A6E0-B19A2BADC1BE}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D0250F3F-6480-484F-B719-42F659AC64D5}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\PreventItemCreationInUsersFilesFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\ProfileImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MpIdleTask\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\RpcId",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\CallForAttributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location\\Notifications\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\Content Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0003\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI\\ResolutionHost\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fs_Rec\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Roamable",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB02381F-D652-4B1C-894A-712498C62C51}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Capabilities",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2470470F-2634-478E-B181-571E98A789BB}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\ImagePath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A656BBE1-4E3E-4C8A-BD79-A8CA56782753}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4DE0CAB9-ECFE-4AA9-B95A-FE815A2EAA4E}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\ProfileImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\StorageDelegate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoWebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D018DE2F-F02A-4BDB-BA74-56BCD427BE40}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Version",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A7C73732-9F11-4281-8D19-764D4EC9D94D}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.44.3.4!7\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Cryptography\\PrivKeyCachePurgeIntervalSeconds",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Type",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{374DE290-123F-4565-9164-39C4925E467B}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager\\Interactive\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP\\UPnPHostConfig\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5F5A18EB-DC73-4E45-A11C-B59043598412}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HideOnDesktopPerUser",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FB3C354D-297A-4EB2-9B58-090F6361906B}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB02381F-D652-4B1C-894A-712498C62C51}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HideFolderVerbs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B81A55E6-C03C-4EF0-B86F-A80A89DF468D}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06308A56-69E7-4844-A784-8509C25B6C62}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SessionAgent\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\WinHttpSettings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\DocObject",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\DocObject",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DefaultIcon\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Logon Synchronization\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06308A56-69E7-4844-A784-8509C25B6C62}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{87F56B34-044E-4A48-8FDD-087BFABD5ECF}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MaxSockaddrLength",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB07F7B4-BB95-4B74-9D32-4533D566453C}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\SuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\VmApplet",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\PerceivedType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControls\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5BE46CE1-CA9B-4CAD-B2E9-8C3F7716AF90}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\PinToNameSpaceTree",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\RelativePath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\Safety Warning Level",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7DC691A2-CB15-44DB-853C-19938051BB22}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{28011108-68DF-4C73-B91B-57427D501BBA}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F18ED8A5-C696-4951-B068-CA8E83634C04}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CC35D2E9-B9E1-4ADC-9DA5-71487D9E9EB5}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\CryptnetPreFetchTriggerPeriodSeconds",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BE669C13-8165-4536-96D0-6D6C39292AAE}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Comment",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\Mapping",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\Content Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E3163C33-301D-4730-A266-5518C5ED3967}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsAliasedNotifications",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Max Cached Icons",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Load",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ESENT\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\WinStations\\RDP-Tcp\\InitialProgram",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Data\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsFORDISPLAY",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Cryptography\\PrivKeyCacheMaxItems",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore\\SR\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\AppSetup",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{40DD7C5E-DA67-4A78-B96C-582A4CBAEDF3}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.47.1.1!7\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{551B3807-871F-4E48-A943-2330449F0615}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\DefaultIcon\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\LocalRedirectOnly",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B78DBF96-841E-4336-BFE9-1C4975F9DA60}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\MemUsageTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4D19A151-A712-4920-AC6D-6C6FD81C8CDB}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\LoadWithoutCOM",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\PolicyConverter\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip6\\WinSock 2.0 Provider ID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledProcesses\\78ED498",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-18\\Flags",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{268014E7-A27E-4FD7-89A6-A481DA222EC8}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{8C5ED038-CFAD-48A0-BB2F-D128286E49B3}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4FDEA3B5-7CDE-48F7-940C-43CDBB18FB20}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\StorageDelegateSuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A8B18D02-60CD-4305-90CC-7DAAC028BDCD}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\AutorunsDisabled",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxUrlRetrievalByteCount",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RegisterSearch\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\WOW64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Description",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\PerceivedType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableMandatoryBasicConstraints",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0004\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\Mapping",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHPORT\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1BB08CFD-C6AD-44C7-BD0B-8F23035A5731}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DiagMatchAnyMask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NETFramework\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\MinSockaddrLength",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{17F5B0DE-8DA9-4280-8CB8-91422B9A8CE1}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\WOW64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Stream",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\AltStartup",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C016366B-7126-46CA-B36B-592A3D95A60B}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\AitAgent\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C016366B-7126-46CA-B36B-592A3D95A60B}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag\\ScheduledDefrag\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HideInWebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ini\\PerceivedType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\ImagePath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\FolderTypeID",
"HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\system32\\p2pcollab.dll,-8042",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0001\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks\\Id",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC668097-4D6B-4093-AC14-014C09DBF820}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrScheduleTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{96137355-BC34-4BA7-81B7-47C87B556E7D}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\\SuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\IconServiceLib",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0005\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SeparateProcess",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9979CB83-103A-4105-9E5D-C74B0AF6D198}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06CD2154-751E-469F-8E4A-C3F118356423}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B78DBF96-841E-4336-BFE9-1C4975F9DA60}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\97817950D81C9670CC34D809CF794431367EF474\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ehDRMInit\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{72DB7465-BC54-491B-A92A-4637A28C9BBF}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\ChainCacheResyncFiletime",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\InstallPlayReady\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Parameters\\Transports",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\MachineThrottling",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Description",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Video",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\Shell",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Parameters\\ServiceDll",
"HKEY_CURRENT_USER\\Software\\Sysinternals\\EulaAccepted",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{82676C49-21A7-4605-AA06-E04A067FB611}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\DefaultIcon\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\StreamResource",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Startup",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\ObjectName",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Pictures",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia\\SystemSoundsService\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\Description",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip\\WinSock 2.0 Provider ID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask\\Id",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{40DD7C5E-DA67-4A78-B96C-582A4CBAEDF3}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{96137355-BC34-4BA7-81B7-47C87B556E7D}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsUniversalDelegate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ShareCredsWithWinHttp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Defaults\\Provider\\Microsoft Enhanced RSA and AES Cryptographic Provider\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F6B1AFFE-48F0-4340-9F59-C73DDA17C17D}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCountPerChain",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\Enabled",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Parameters\\ServiceDll",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Local AppData",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\SafeProcessSearchMode",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk\\Proxy\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\SuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\HelperDllName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetCrawling",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\LsaExtensionConfig\\SspiCli\\CheckSignatureRoutine",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FB3C354D-297A-4EB2-9B58-090F6361906B}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\LsaExtensionConfig\\SspiCli\\CheckSignatureDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{8C5ED038-CFAD-48A0-BB2F-D128286E49B3}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SystemDataProviders\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\LoadWithoutCOM",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsParseDisplayName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Start",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\WOW64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{72DB7465-BC54-491B-A92A-4637A28C9BBF}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\WOW64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\UseDelayedAcceptance",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\UseDelayedAcceptance",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RacTask\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\LocalRedirectOnly",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Music",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\Wds\\rdpwd\\StartupPrograms",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClassicShell",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4DE0CAB9-ECFE-4AA9-B95A-FE815A2EAA4E}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0002\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{994C86AD-A929-4B2C-88A0-4E25A107A029}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\WOW64",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Security",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.67.1.1!7\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for SqlServer\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableCANameConstraints",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\UseDropHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp\\DisableBranchCache",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\GlobalSession",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableWeakSignatureFlags",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9435F817-FED2-454E-88CD-7F78FDA62C48}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{448186F9-75B9-4FB7-A6E0-B19A2BADC1BE}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0008\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7DC691A2-CB15-44DB-853C-19938051BB22}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CDA5F4EE-8293-4A5D-8564-04CD067D1A85}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CDA5F4EE-8293-4A5D-8564-04CD067D1A85}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Serial_Access_Num",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{268014E7-A27E-4FD7-89A6-A481DA222EC8}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\WOW64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{613612BA-897D-44CE-8DC1-8FC283F9FD51}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCertCount",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection\\NAPStatus UI\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B43033E6-1453-4AD6-AFBA-C03CFC178286}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2E941CB2-1B33-47C4-905B-8B4278819513}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\Flags",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\MachineGuid",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CC35D2E9-B9E1-4ADC-9DA5-71487D9E9EB5}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5F5A18EB-DC73-4E45-A11C-B59043598412}\\Actions",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{4E77131D-3629-431C-9818-C5679DC83E81} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\OptinNotification\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\QueryForInfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A7C73732-9F11-4281-8D19-764D4EC9D94D}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4D19A151-A712-4920-AC6D-6C6FD81C8CDB}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\\Blob",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Stream",
"HKEY_CURRENT_USER\\Environment\\UserInitMprLogonScript",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DiagLevel",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DontShowSuperHidden",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\MaximumAllowedAllocationSize",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InitFolderHandler",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\MaxSockaddrLength",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance\\WinSAT\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\SecurityProviders",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0010\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Start",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Startup",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\mcupdate\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Networking\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugFlags",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\GadgetManager\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Common Startup",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC668097-4D6B-4093-AC14-014C09DBF820}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Category",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\WOW64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\DocObject",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{874CFED9-D01D-4D16-9775-B8A7A05004BF}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\WOW64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlCountInCert",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0000\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{17F5B0DE-8DA9-4280-8CB8-91422B9A8CE1}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsFORPARSING",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{87F56B34-044E-4A48-8FDD-087BFABD5ECF}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC\\HotStart\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\CrawlStartPages\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\RelativePath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\RestrictedAttributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{551B3807-871F-4E48-A943-2330449F0615}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI\\LPRemove\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{3307E641-F5EE-49E6-A1FE-BFB5D671441C}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\ObjectName",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Taskman",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A48CABBF-24C8-4B87-B00F-9261807C3B43}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxySettingsPerUser",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\MapNetDriveVerbs",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableUnsupportedCriticalExtensions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates\\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Defaults\\Provider\\Microsoft Enhanced RSA and AES Cryptographic Provider\\Image Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4FDEA3B5-7CDE-48F7-940C-43CDBB18FB20}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0009\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.67.1.2!7\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for Oracle\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DCLocator\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A48CABBF-24C8-4B87-B00F-9261807C3B43}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F6B1AFFE-48F0-4340-9F59-C73DDA17C17D}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A656BBE1-4E3E-4C8A-BD79-A8CA56782753}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2E941CB2-1B33-47C4-905B-8B4278819513}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\Type",
"HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\System32\\fveui.dll,-844",
"HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\System32\\fveui.dll,-843",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D0250F3F-6480-484F-B719-42F659AC64D5}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5A40E926-9E86-4B89-9CFD-B12311724371}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0007\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\WOW64",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location\\Id",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Run",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Security",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\WOW64",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras\\MobilityManager\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\LoadWithoutCOM",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\Flags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A8B18D02-60CD-4305-90CC-7DAAC028BDCD}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0006\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{28011108-68DF-4C73-B91B-57427D501BBA}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MinSockaddrLength",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5A40E926-9E86-4B89-9CFD-B12311724371}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RecordingRestart\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Parameters\\ServiceDll",
"HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\system32\\dnsapi.dll,-103",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\NoFileFolderJunction",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D018DE2F-F02A-4BDB-BA74-56BCD427BE40}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Background Synchronization\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp\\Tracing\\Enabled",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Start",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F} {ADD8BA80-002B-11D0-8F0F-00C04FD7D062} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BE669C13-8165-4536-96D0-6D6C39292AAE}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\ObjectName",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\ImagePath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\ImagePath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RACAgent\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Stream",
"HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns\\EulaAccepted",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB07F7B4-BB95-4B74-9D32-4533D566453C}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F18ED8A5-C696-4951-B068-CA8E83634C04}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{994C86AD-A929-4B2C-88A0-4E25A107A029}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\TokenSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates\\7D7F4414CCEF168ADF6BF40753B5BECD78375931\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\LocalRedirectOnly",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SafeBoot\\AlternateShell",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\SuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkCards\\12\\ServiceName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Description",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURActivate\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\ImagePath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\QueryForOverlay",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\AutorunsDisabled",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis\\Scheduled\\Id",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Start",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ini\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\InitFolderHandler",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Description",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Personal",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{82676C49-21A7-4605-AA06-E04A067FB611}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Start",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadOverride",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Common AltStartup",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B81A55E6-C03C-4EF0-B86F-A80A89DF468D}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURDiscovery\\Id",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Desktop",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CD962721-73F1-4649-85D7-6884C1EF28D9}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\shell\\open\\command\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\ImagePath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing\\State",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\StubPath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{56784854-C6CB-462B-8169-88E350ACB882}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ini\\Content Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\HelperDllName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParsingName",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System\\ConvertLogEntries\\Id",
"HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\system32\\qagentrt.dll,-10",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\\Blob",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\Flags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\UpdateRecordPath\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\WOW64",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2470470F-2634-478E-B181-571E98A789BB}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1BB08CFD-C6AD-44C7-BD0B-8F23035A5731}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BattC\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0011\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0011\\MatchingDeviceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Attributes",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9979CB83-103A-4105-9E5D-C74B0AF6D198}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\AutoWake\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscovery\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\inetaccs\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adsi\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{874CFED9-D01D-4D16-9775-B8A7A05004BF}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5BE46CE1-CA9B-4CAD-B2E9-8C3F7716AF90}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalByteCount",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B43033E6-1453-4AD6-AFBA-C03CFC178286}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Cryptography\\PrivateKeyLifetimeSeconds",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06CD2154-751E-469F-8E4A-C3F118356423}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CD962721-73F1-4649-85D7-6884C1EF28D9}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\ImagePath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E3163C33-301D-4730-A266-5518C5ED3967}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableInetUnknownAuth",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\SuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry\\RegIdleBackup\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HasNavigationEnum",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9435F817-FED2-454E-88CD-7F78FDA62C48}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{613612BA-897D-44CE-8DC1-8FC283F9FD51}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\\InProcServer32\\LoadWithoutCOM",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSimpleStartMenu",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\Description"
],
"directory_created": [
"C:\\Windows\\System32\\catroot2",
"C:\\Windows\\System32\\catroot",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf"
]
}[
{
"yara": [],
"sha1": "e685d8b955cff4d4e74c948df638202a14a07fbc",
"name": "bea5da8b6487dac6_autorunsc64.exe",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
"type": "PE32+ executable (console) x86-64, for MS Windows",
"sha256": "700909607974e22e1de20018a28ad11d090f09f9f5d85404caa9048e73552d47",
"urls": [
"http:\/\/www.microsoft.com\/exporting"
],
"crc32": "DA11C829",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/7635\/files\/bea5da8b6487dac6_autorunsc64.exe",
"ssdeep": null,
"size": 600060,
"sha512": "17622d4e9fc6490228fcd80af2c25291a17094bcd46d6a58521b82bd3b0343e63b7d9459a60f7a04db393b152b7df9fce4db5cbc60e9559836d52f8f3cd184af",
"pids": [
1268
],
"md5": "dc634bbd7d0eb8a6dce71d4123cad424"
},
{
"yara": [],
"sha1": "c64ad224b877cd5bbdcdb1799b71f3682602d231",
"name": "b0a39e28d93f7822_TarD41D.tmp",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
"type": "data",
"sha256": "b0a39e28d93f7822fe6cac1e082c7adc581dcd2b61eb9f536e74bd14a75b27bc",
"urls": [
"http:\/\/www.microsoft.com\/pkiops\/certs\/Microsoft%20Certificate%20Trust%20List%20PCA(3).crt0",
"http:\/\/www.microsoft.com\/pki\/certs\/MicRooCerAut_2010-06-23.crt07",
"http:\/\/www.microsoft.com\/pki\/certs\/MicCerLisCA2011_2011-03-29.crt0",
"http:\/\/www.microsoft.com\/pki\/certs\/MicrosoftRootCert.crt0",
"http:\/\/www.microsoft.com\/pkiops\/crl\/Microsoft%20Certificate%20Trust%20List%20PCA(3).crl0u"
],
"crc32": "B495BE07",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/7635\/files\/b0a39e28d93f7822_TarD41D.tmp",
"ssdeep": null,
"size": 138525,
"sha512": "0663fb22bcefd0ac5f090104322a8c0dc1ceb77a168b589d7dbb9a74d109daf38beac97dab715220abab08c355496f5719159e17995248caa19eff45bc2a5d46",
"pids": [
2096
],
"md5": "0e34ebf89b843b303f0fb5f194be9d28"
},
{
"yara": [],
"sha1": "cf925fc512b936fe7d44ceb6e999e4a020ed6ff0",
"name": "4c9c4d831d61c8c3_CabD41C.tmp",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
"type": "Microsoft Cabinet archive data, 56952 bytes, 1 file",
"sha256": "4c9c4d831d61c8c38b2513f9b431ef4f4cf6af9fb18a2317cd2178d6e0997822",
"urls": [],
"crc32": "5168F337",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/7635\/files\/4c9c4d831d61c8c3_CabD41C.tmp",
"ssdeep": null,
"size": 56952,
"sha512": "65dc435f6d3e1afd347ba1617a3eee59c6660f221faa36456a09e307d434d7276e8095e8aa34d59933e685a9f84564ec783e59ae9658791f7ebdbbc2eda32f7a",
"pids": [
2096
],
"md5": "04d79a0dc77a8f449cbff6252862d398"
},
{
"yara": [],
"sha1": "556da65e88aadbfab90c518d9a52acbe4fd2b0e0",
"name": "53e2e246655679e4_xggbwk",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
"type": "Microsoft Cabinet archive data, 331565 bytes, 1 file",
"sha256": "53e2e246655679e4629237a11b4a079cc30eca0f2843b160aa45330813430702",
"urls": [],
"crc32": "895CFD7E",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/7635\/files\/53e2e246655679e4_xggbwk",
"ssdeep": null,
"size": 331565,
"sha512": "29c86685ca018ade365c7e47321b1b0cc873e666375c8ef9164c65424f5b1d2b3461330115f844582d12416a8ea55b81db3dfab3e64c063bd3fd78123c0f1f7c",
"pids": [
1268
],
"md5": "115004a462a913f1033cdf317a519c93"
}
][
{
"process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
"process_name": "autorunsc64.exe",
"pid": 144,
"summary": {
"regkey_written": [
"HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns\\EulaAccepted"
],
"dll_loaded": [
"kernel32",
"API-MS-Win-Security-LSALookup-L1-1-0.dll",
"apphelp.dll",
"api-ms-win-core-localization-l1-2-1",
"kernel32.dll",
"api-ms-win-core-synch-l1-2-0",
"ntmarta.dll",
"API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
"ole32.dll",
"API-MS-Win-Security-SDDL-L1-1-0.dll",
"C:\\Windows\\system32\\Wintrust.dll",
"WindowsCodecs.dll",
"OLEAUT32.dll",
"profapi.dll",
"SHELL32.dll",
"comctl32.dll",
"C:\\Windows\\system32\\advapi32.dll",
"api-ms-win-core-fibers-l1-1-1",
"C:\\Windows\\system32\\crypt32.dll",
"C:\\Windows\\system32\\Kernel32.dll",
"ADVAPI32.dll",
"SETUPAPI.dll"
],
"file_opened": [
"C:\\Windows\\System32\\imageres.dll",
"C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727",
"C:\\",
"C:\\Windows\\System32\\",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db",
"C:\\Windows\\System32\\dllhost.exe",
"C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe",
"C:\\Windows\\System32\\EhStorShell.dll",
"C:\\Windows\\System32\\lsass.exe",
"C:\\Windows\\System32\\cscui.dll",
"C:\\Windows\\ehome\\ehrecvr.exe",
"C:\\Windows\\System32",
"c:\\Windows\\System32\\imageres.dll",
"C:\\Windows\\",
"C:\\Windows\\Microsoft.NET\\Framework64\\",
"C:\\Windows\\ehome\\ehsched.exe",
"C:\\Windows\\Microsoft.Net\\Framework64\\",
"C:\\Windows\\Microsoft.NET",
"C:\\Windows\\ehome\\",
"C:\\Windows\\Microsoft.Net\\Framework64\\v3.0\\",
"C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\WPF\\PresentationFontCache.exe",
"C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation",
"C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\infocard.exe",
"C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\WPF",
"C:\\Users\\cuck\\Desktop\\desktop.ini",
"C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727",
"C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\",
"C:\\Windows\\System32\\svchost.exe",
"C:\\Windows\\System32\\ntshrui.dll",
"C:\\Windows\\ehome",
"C:\\Windows\\System32\\FXSSVC.exe",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
"C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\",
"C:\\Windows\\Microsoft.NET\\Framework64\\v3.0",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db",
"C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe",
"C:\\Windows\\Microsoft.NET\\Framework",
"C:\\Windows\\System32\\alg.exe",
"C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\",
"C:\\Windows",
"C:\\Windows\\Microsoft.NET\\Framework64"
],
"regkey_opened": [
"HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance\\Disabled",
"HKEY_LOCAL_MACHINE\\Software\\Sysinternals",
"HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns",
"HKEY_CURRENT_USER\\Software\\Sysinternals",
"HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance"
],
"file_exists": [
"C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted",
"C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted.dll",
"C:\\Windows\\System32\\bdesvc.dll",
"C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe",
"C:\\Windows\\ehome\\ehrecvr.exe",
"C:\\Windows\\System32\\svchost.exe -k netsvcs.dll",
"C:\\Windows\\System32\\aelupsvc.dll",
"C:\\Windows\\System32\\svchost.exe -k bthsvcs.dll",
"C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation.exe",
"C:\\Windows\\System32\\BFE.DLL",
"C:\\Windows\\System32\\svchost.exe -k netsvcs",
"C:\\Windows\\System32\\FntCache.dll",
"C:\\Windows\\System32\\svchost.exe -k LocalService",
"C:\\Windows\\System32\\audiosrv.dll",
"C:\\Windows\\System32\\svchost.exe -k.dll",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted.exe",
"C:\\Windows\\System32\\svchost.exe -k bthsvcs",
"C:\\Windows\\System32\\KMSVC.DLL",
"C:\\Windows\\System32\\svchost.exe -k bthsvcs.exe",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation.dll",
"C:\\Windows\\System32\\svchost.exe -k NetworkService.exe",
"C:\\Windows\\System32\\qmgr.dll",
"C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup.dll",
"C:\\Windows\\System32\\defragsvc.dll",
"C:\\Windows\\System32\\svchost.exe -k NetworkService",
"C:\\Windows\\System32\\cscsvc.dll",
"C:\\Windows\\System32\\svchost.exe -k LocalService.dll",
"C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation.dll",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation.exe",
"C:\\Windows\\System32\\appidsvc.dll",
"C:\\Windows\\System32\\appmgmts.dll",
"C:\\Windows\\Microsoft.Net\\Framework64\\v3.0\\WPF\\PresentationFontCache.exe",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork.com",
"C:\\Windows\\System32\\svchost.exe -k NetSvcs.dll",
"C:\\Windows\\System32\\es.dll",
"C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation",
"C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup.exe",
"C:\\Windows\\System32\\svchost.exe -k NetSvcs",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation.com",
"C:\\Windows\\System32\\certprop.dll",
"C:\\Windows\\System32\\lsass.exe",
"C:\\Windows\\System32\\wevtsvc.dll",
"C:\\Windows\\System32\\svchost.exe -k NetworkService.dll",
"C:\\Windows\\System32\\svchost.exe -k.exe",
"C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup",
"C:\\Windows\\System32\\fdPHost.dll",
"C:\\Windows\\System32\\svchost.exe -k DcomLaunch.com",
"C:\\Windows\\System32\\cryptsvc.dll",
"C:\\Windows\\System32\\svchost.exe -k netsvcs.exe",
"C:\\Windows\\System32\\svchost.exe -k defragsvc",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted",
"C:\\Windows\\System32\\dllhost.exe",
"C:\\Windows\\System32\\dot3svc.dll",
"C:\\Windows\\System32\\svchost.exe -k NetworkService.com",
"C:\\Windows\\System32\\dhcpcore.dll",
"C:\\Windows\\System32\\gpsvc.dll",
"C:\\Windows\\System32\\svchost.exe -k DcomLaunch.dll",
"C:\\Windows\\System32\\svchost.exe -k bthsvcs.com",
"C:\\Windows\\System32\\provsvc.dll",
"C:\\Windows\\ehome\\ehsched.exe",
"C:\\Windows\\System32\\FDResPub.dll",
"C:\\Windows\\System32\\svchost.exe -k defragsvc.com",
"C:\\Windows\\System32\\svchost.exe -k.com",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted.com",
"C:\\Windows\\System32\\rpcss.dll",
"C:\\Windows\\System32\\hidserv.dll",
"C:\\Windows\\System32\\svchost.exe -k defragsvc.exe",
"C:\\Windows\\System32\\svchost.exe",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted.dll",
"C:\\Windows\\System32\\svchost.exe -k netsvcs.com",
"C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup.com",
"C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation.com",
"C:\\Windows\\System32\\FXSSVC.exe",
"C:\\Windows\\System32\\bthserv.dll",
"C:\\Windows\\System32\\iphlpsvc.dll",
"C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted.exe",
"C:\\Windows\\System32\\IKEEXT.DLL",
"C:\\Windows\\System32\\dnsrslvr.dll",
"C:\\Windows\\System32\\svchost.exe -k NetSvcs.exe",
"C:\\Windows\\System32\\ListSvc.dll",
"C:\\Windows\\System32\\eapsvc.dll",
"C:\\Windows\\System32\\ipbusenum.dll",
"C:\\Windows\\System32\\svchost.exe -k LocalService.exe",
"C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted.com",
"C:\\Windows\\System32\\appinfo.dll",
"C:\\Windows\\System32\\alg.exe",
"C:\\Windows\\System32\\svchost.exe -k LocalService.com",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation",
"C:\\Windows\\System32\\svchost.exe -k defragsvc.dll",
"C:\\Windows\\System32\\svchost.exe -k DcomLaunch.exe",
"C:\\Windows\\System32\\browser.dll",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork.dll",
"C:\\Windows\\System32\\AxInstSv.dll",
"C:\\Windows\\System32\\svchost.exe -k NetSvcs.com",
"C:\\Windows\\System32\\msdtckrm.dll",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork",
"C:\\Windows\\System32\\svchost.exe -k DcomLaunch",
"C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork.exe",
"C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe",
"C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\infocard.exe",
"C:\\Windows\\System32\\dps.dll",
"C:\\Windows\\System32\\svchost.exe -k"
],
"guid": [
"{08244ee6-92f0-47f2-9fc9-929baa2e7235}",
"{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
"{4e77131d-3629-431c-9818-c5679dc83e81}",
"{d9144dcd-e998-4eca-ab6a-dcd83ccba16d}",
"{0c6c4200-c589-11d0-999a-00c04fd655e1}",
"{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}"
],
"file_read": [
"C:\\Users\\cuck\\Desktop\\desktop.ini"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NETFramework\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NeverShowExt",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\ProfileImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Start",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\WOW64",
"HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns\\EulaAccepted",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\LoadWithoutCOM",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\Content Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\Flags",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ServiceDll",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Start",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Start",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Type",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{4E77131D-3629-431C-9818-C5679DC83E81} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\SuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\NeverShowExt",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\ProfileImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SeparateProcess",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoWebView",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\FolderTypeID",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Start",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for Oracle\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Networking\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Parameters\\ServiceDll",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Desktop",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\AutorunsDisabled",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Start",
"HKEY_CURRENT_USER\\Software\\Sysinternals\\EulaAccepted",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\DocObject",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Parameters\\ServiceDll",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DefaultIcon\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalRedirectOnly",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\WOW64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ServiceDll",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Type",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ServiceDll",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalRedirectOnly",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\Flags",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DontShowSuperHidden",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\PerceivedType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\WOW64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\SafeProcessSearchMode",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\SuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\WOW64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetCrawling",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Max Cached Icons",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BattC\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\WOW64",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ESENT\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DCLocator\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Data\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fs_Rec\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\LoadWithoutCOM",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Type",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\WOW64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Security",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\WOW64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\WOW64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\inetaccs\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\DefaultIcon\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\LoadWithoutCOM",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\Flags",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClassicShell",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\Content Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\WOW64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Start",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Start",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-18\\Flags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for SqlServer\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\SuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\AutorunsDisabled",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\WOW64",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adsi\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Parameters\\ServiceDll",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\PerceivedType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\WOW64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSimpleStartMenu",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHPORT\\Start"
],
"directory_created": [
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches"
]
},
"first_seen": 1589777684.999374,
"ppid": 1268
},
{
"process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe",
"process_name": "autorunsc64.exe",
"pid": 2716,
"summary": {
"regkey_written": [
"HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns\\EulaAccepted"
],
"dll_loaded": [
"kernel32",
"API-MS-Win-Security-LSALookup-L1-1-0.dll",
"apphelp.dll",
"api-ms-win-core-localization-l1-2-1",
"kernel32.dll",
"api-ms-win-core-synch-l1-2-0",
"ntmarta.dll",
"API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
"ole32.dll",
"API-MS-Win-Security-SDDL-L1-1-0.dll",
"C:\\Windows\\system32\\Wintrust.dll",
"WindowsCodecs.dll",
"OLEAUT32.dll",
"profapi.dll",
"SHELL32.dll",
"comctl32.dll",
"C:\\Windows\\system32\\advapi32.dll",
"api-ms-win-core-fibers-l1-1-1",
"C:\\Windows\\system32\\crypt32.dll",
"C:\\Windows\\system32\\Kernel32.dll",
"ADVAPI32.dll",
"SETUPAPI.dll"
],
"file_opened": [
"C:\\Windows\\System32\\ntshrui.dll",
"c:\\Windows\\System32\\imageres.dll",
"C:\\Users\\cuck\\Desktop\\desktop.ini",
"C:\\Windows\\",
"C:\\",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db",
"c:\\Windows\\System32\\userinit.exe",
"C:\\Windows\\System32\\",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db",
"C:\\Windows\\System32\\cscui.dll",
"C:\\Windows",
"c:\\Windows\\System32\\rdpclip.exe",
"C:\\Windows\\System32\\EhStorShell.dll",
"C:\\Windows\\System32\\rdpclip.exe",
"C:\\Windows\\System32\\userinit.exe",
"C:\\Windows\\System32"
],
"regkey_opened": [
"HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance\\Disabled",
"HKEY_LOCAL_MACHINE\\Software\\Sysinternals",
"HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns",
"HKEY_CURRENT_USER\\Software\\Sysinternals",
"HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance"
],
"file_exists": [
"C:\\Windows\\System32\\rdpclip.com",
"C:\\Windows\\rdpclip.com",
"C:\\Python27\\Scripts\\rdpclip.exe",
"C:\\Python27\\Scripts\\rdpclip",
"C:\\Python27\\rdpclip.exe",
"C:\\Python27\\rdpclip.com",
"C:\\Python27\\rdpclip",
"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\rdpclip",
"C:\\Windows\\System32\\wbem\\rdpclip.com",
"C:\\Windows\\System32\\wbem\\rdpclip",
"C:\\Windows\\rdpclip",
"C:\\Windows\\System32\\userinit.exe",
"C:\\Python27\\Scripts\\rdpclip.com",
"C:\\Windows\\System32\\rdpclip.exe",
"C:\\Windows\\System32\\rdpclip",
"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\rdpclip.com"
],
"guid": [
"{08244ee6-92f0-47f2-9fc9-929baa2e7235}",
"{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
"{4e77131d-3629-431c-9818-c5679dc83e81}",
"{d9144dcd-e998-4eca-ab6a-dcd83ccba16d}",
"{0c6c4200-c589-11d0-999a-00c04fd655e1}",
"{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}"
],
"file_read": [
"C:\\Users\\cuck\\Desktop\\desktop.ini"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InfoTip",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\Flags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalizedName",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\LoadWithoutCOM",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\LoadWithoutCOM",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DontShowSuperHidden",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\Flags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\ProfileImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\(Default)",
"HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns\\EulaAccepted",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\Wds\\rdpwd\\StartupPrograms",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClassicShell",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\Content Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\Flags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Roamable",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\FolderTypeID",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\SuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResourceType",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-18\\Flags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResourceType",
"HKEY_CURRENT_USER\\Software\\Sysinternals\\EulaAccepted",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DefaultIcon\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetCrawling",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Attributes",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Description",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Desktop",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\SuppressionPolicy",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\LoadWithoutCOM",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\SafeProcessSearchMode",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Max Cached Icons",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{4E77131D-3629-431C-9818-C5679DC83E81} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\SuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Description",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Description",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\ProfileImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\AlwaysShowExt",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SeparateProcess",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\AlwaysShowExt",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\AppSetup",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSimpleStartMenu",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoWebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\FolderTypeID"
],
"directory_created": [
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches"
]
},
"first_seen": 1589777702.733751,
"ppid": 1268
},
{
"process_path": "C:\\Windows\\System32\\lsass.exe",
"process_name": "lsass.exe",
"pid": 476,
"summary": {},
"first_seen": 1589777586.359375,
"ppid": 376
},
{
"process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
"process_name": "6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
"pid": 1268,
"summary": {
"file_created": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe"
],
"directory_created": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf"
],
"dll_loaded": [
"kernel32",
"api-ms-win-core-fibers-l1-1-1",
"api-ms-win-core-localization-l1-2-1",
"kernel32.dll",
"DEVRTL.dll",
"advapi32",
"Cabinet.dll",
"api-ms-win-core-synch-l1-2-0"
],
"file_opened": [
"",
"C:\\Windows\\System32\\drivers\\amdk8.sys",
"C:\\Program Files\\Windows Media Player\\wmpnetwk.exe",
"C:\\Python27\\python.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RegisterSearch",
"C:\\Windows\\System32\\drivers\\ndisuio.sys",
"C:\\Windows\\System32\\drivers\\monitor.sys",
"C:\\Windows\\System32\\drivers\\WUDFPf.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
"C:\\Windows\\System32\\aepdu.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
"C:\\Windows\\System32\\drivers\\blbdrive.sys",
"C:\\Windows\\System32\\clfs.sys",
"C:\\Windows\\System32\\drivers\\netbios.sys",
"C:\\Windows\\System32\\drivers\\mstee.sys",
"C:\\Windows\\System32\\drivers\\hidir.sys",
"C:\\Windows\\System32\\drivers\\rasl2tp.sys",
"C:\\Windows\\System32\\drivers\\srvnet.sys",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
"C:\\Windows\\System32\\drivers\\asyncmac.sys",
"C:\\Windows\\System32\\drivers\\flpydisk.sys",
"C:\\Windows\\System32\\drivers\\lsi_sas2.sys",
"C:\\Windows\\System32\\drivers\\mrxdav.sys",
"C:\\Windows\\System32\\drivers\\mountmgr.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
"C:\\Windows\\System32\\drivers\\rdyboost.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MobilePC\\HotStart",
"C:\\Windows\\System32\\drivers\\wacompen.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MUI\\LPRemove",
"C:\\Windows\\System32\\drivers\\circlass.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
"C:\\Windows\\System32\\drivers\\CompositeBus.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
"C:\\Windows\\System32\\drivers\\fdc.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SystemRestore\\SR",
"C:\\Windows\\System32\\drivers\\bthmodem.sys",
"C:\\Windows\\System32\\drivers\\compbatt.sys",
"C:\\Windows\\System32\\drivers\\RDPCDD.sys",
"C:\\Windows\\System32\\drivers\\filetrace.sys",
"C:\\Windows\\System32\\mctadmin.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Location\\Notifications",
"C:\\Windows\\System32\\drivers\\BrUsbSer.sys",
"C:\\Windows\\System32\\drivers\\vdrvroot.sys",
"C:\\Windows\\System32\\drivers\\stexstor.sys",
"C:\\Windows\\System32\\drivers\\BrFiltUp.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
"C:\\Windows\\System32\\drivers\\mshidkmdf.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\AitAgent",
"C:\\Windows\\System32\\drivers\\TsUsbGD.sys",
"C:\\Windows\\System32\\drivers\\HpSAMD.sys",
"C:\\Windows\\System32\\drivers\\E1G6032E.sys",
"C:\\Windows\\System32\\drivers\\msdsm.sys",
"C:\\Windows\\System32\\drivers\\lltdio.sys",
"C:\\Windows\\System32\\drivers\\vhdmp.sys",
"C:\\Windows\\System32\\drivers\\usbuhci.sys",
"C:\\Windows\\System32\\drivers\\pciide.sys",
"C:\\Windows\\System32\\dwm.exe",
"C:\\Windows\\System32\\drivers\\rassstp.sys",
"C:\\Windows\\System32\\drivers\\IPMIDrv.sys",
"C:\\Windows\\System32\\raserver.exe",
"C:\\Windows\\System32\\drivers\\ndis.sys",
"C:\\tmpyzbctd\\",
"C:\\Windows\\System32\\drivers\\tunnel.sys",
"C:\\Windows\\System32\\drivers\\hwpolicy.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
"C:\\Windows\\System32\\drivers\\sisraid4.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Ras\\MobilityManager",
"C:\\Windows\\System32\\drivers\\ndiscap.sys",
"C:\\Program Files\\Windows Media Player\\",
"C:\\Windows\\System32\\drivers\\umpass.sys",
"C:\\Windows\\System32\\drivers\\bowser.sys",
"C:\\Windows\\System32\\drivers\\partmgr.sys",
"C:\\Windows\\System32\\drivers\\iaStorV.sys",
"C:\\Windows\\System32\\drivers\\usbccgp.sys",
"C:\\Windows\\System32\\cmd.exe",
"C:\\Windows\\System32\\drivers\\sffp_sd.sys",
"C:\\Windows\\System32\\drivers\\volsnap.sys",
"C:\\Windows\\ehome\\mcupdate.exe",
"C:\\Windows\\System32\\drivers\\mpsdrv.sys",
"C:\\Windows\\System32\\drivers\\wmiacpi.sys",
"C:\\Windows\\System32\\drivers\\MegaSR.sys",
"C:\\Windows\\System32\\drivers\\adpu320.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Task Manager\\Interactive",
"C:\\Windows\\System32\\drivers\\cdrom.sys",
"C:\\Windows\\System32\\drivers\\BrFiltLo.sys",
"C:\\Users\\cuck\\AppData\\Local\\",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
"C:\\Windows\\System32\\drivers\\pcw.sys",
"C:\\Windows\\System32\\Defrag.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Registry\\RegIdleBackup",
"C:\\Windows\\System32\\drivers\\megasas.sys",
"C:\\Windows\\System32\\drivers\\modem.sys",
"C:\\Windows\\System32\\drivers\\adp94xx.sys",
"C:\\Windows\\System32\\drivers\\iirsp.sys",
"C:\\Windows\\System32\\drivers\\rspndr.sys",
"C:\\Windows\\System32\\drivers\\hdaudbus.sys",
"C:\\Windows\\System32\\drivers\\vga.sys",
"C:\\",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
"C:\\Windows\\System32\\drivers\\wanarp.sys",
"C:\\Windows\\System32\\drivers\\dmvsc.sys",
"C:\\Windows\\System32\\drivers\\FsDepends.sys",
"C:\\Windows\\System32\\conhost.exe",
"C:\\Windows\\System32\\drivers\\sisraid2.sys",
"C:\\Windows\\System32\\appidpolicyconverter.exe",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
"C:\\Windows\\System32\\drivers\\ULIAGPKX.SYS",
"C:\\Windows\\System32\\drivers\\rasacd.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Maintenance\\WinSAT",
"C:\\Windows\\System32\\drivers\\hcw85cir.sys",
"C:\\Windows\\System32\\drivers\\VMBusHID.sys",
"C:\\Windows\\System32\\drivers\\intelide.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RAC\\RacTask",
"C:\\Windows\\System32\\drivers\\vmstorfl.sys",
"C:\\Windows\\System32\\drivers\\ipfltdrv.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
"C:\\Windows\\System32\\drivers\\HdAudio.sys",
"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe",
"C:\\Windows\\System32\\drivers\\srv.sys",
"C:\\Windows\\System32\\drivers\\msiscsi.sys",
"C:\\Windows\\System32\\drivers\\CmBatt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
"C:\\Windows\\System32\\drivers\\bxvbda.sys",
"C:\\Windows\\System32\\drivers\\vwifibus.sys",
"C:\\Windows\\System32\\drivers\\drmkaud.sys",
"C:\\Windows\\System32\\drivers\\fvevol.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
"C:\\Windows\\System32\\ndfapi.dll",
"C:\\Windows\\System32\\drivers\\ksthunk.sys",
"C:\\Windows\\System32\\drivers\\ipnat.sys",
"C:\\Windows\\System32\\drivers\\kbdhid.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
"C:\\Windows\\System32\\drivers\\disk.sys",
"C:\\Windows\\System32\\lpremove.exe",
"C:\\Windows\\System32\\lsass.exe",
"C:\\Windows\\System32\\drivers\\kbdclass.sys",
"C:\\Windows\\System32\\drivers\\fltMgr.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
"C:\\Windows\\System32\\drivers\\smb.sys",
"C:\\Windows\\System32\\drivers\\isapnp.sys",
"C:\\Windows\\System32\\drivers\\amdsbs.sys",
"C:\\Windows\\System32\\lsm.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Autochk\\Proxy",
"C:\\Windows\\System32\\drivers\\usbcir.sys",
"C:\\Windows\\System32\\drivers\\vmbus.sys",
"C:\\Windows\\System32\\drivers\\tdpipe.sys",
"C:\\Windows\\System32\\drivers\\appid.sys",
"C:\\Windows\\System32\\drivers\\cng.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
"C:\\Windows\\System32\\drivers\\afd.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
"C:\\Windows\\System32\\drivers\\tcpip.sys",
"C:\\Windows\\System32\\services.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
"C:\\Windows\\System32\\drivers\\BrSerWdm.sys",
"C:\\Windows\\System32\\drivers\\ndiswan.sys",
"C:\\Windows\\System32\\drivers\\serial.sys",
"C:\\Windows\\System32\\drivers\\lsi_sas.sys",
"C:\\Windows\\System32\\DFDWiz.exe",
"C:\\Windows\\System32\\drivers\\dxgkrnl.sys",
"C:\\Windows\\System32\\dfdts.dll",
"C:\\Windows\\System32\\drivers\\nvstor.sys",
"C:\\Windows\\System32\\LocationNotifications.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WDI\\ResolutionHost",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ehDRMInit",
"C:\\Windows\\System32\\drivers\\csc.sys",
"C:\\Windows\\System32\\drivers\\i8042prt.sys",
"C:\\Windows\\System32\\gatherNetworkInfo.vbs",
"C:\\Windows\\System32\\drivers\\parport.sys",
"C:\\Windows\\System32\\drivers\\nfrd960.sys",
"C:\\Windows\\System32\\drivers\\msahci.sys",
"C:\\Program Files\\Windows Media Player\\wmpnscfg.exe",
"C:\\Windows\\System32\\winlogon.exe",
"C:\\Windows\\System32\\drivers\\sfloppy.sys",
"C:\\Windows\\System32\\drivers\\RDPENCDD.sys",
"C:\\Windows\\System32\\drivers\\nwifi.sys",
"C:\\Windows\\System32\\drivers\\ws2ifsl.sys",
"C:\\Windows\\System32\\drivers\\PEAuth.sys",
"C:\\Windows\\System32\\drivers\\NV_AGP.SYS",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
"C:\\Windows\\System32\\drivers\\rdpdr.sys",
"C:\\Windows\\System32\\drivers\\elxstor.sys",
"C:\\Windows\\System32\\drivers\\hidusb.sys",
"C:\\Windows\\System32\\drivers\\ql40xx.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
"C:\\Windows\\System32\\",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
"C:\\Windows\\System32\\drivers\\amdxata.sys",
"C:\\Windows\\System32\\drivers\\usbhub.sys",
"C:\\Windows\\System32\\wininit.exe",
"C:\\Windows\\System32\\drivers\\vms3cap.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
"C:\\Windows\\System32\\drivers\\nsiproxy.sys",
"C:\\Windows\\System32\\drivers\\mup.sys",
"C:\\Windows\\System32\\BFE.DLL",
"C:\\Windows\\explorer.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
"C:\\Windows\\System32\\drivers\\netbt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
"C:\\Windows\\System32\\drivers\\atapi.sys",
"C:\\Windows\\System32\\drivers\\storvsc.sys",
"C:\\Windows\\System32\\drivers\\fileinfo.sys",
"C:\\Windows\\System32\\drivers\\wd.sys",
"C:\\Windows\\System32\\drivers\\RDPREFMP.sys",
"C:\\Windows\\System32\\drivers\\pacer.sys",
"C:\\Windows\\System32\\drivers\\dfsc.sys",
"C:\\Windows\\System32\\drivers\\mrxsmb10.sys",
"C:\\Windows\\System32\\drivers\\mrxsmb20.sys",
"C:\\Windows\\System32\\appidcertstorecheck.exe",
"C:\\Windows\\System32\\drivers\\pci.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
"C:\\Windows\\System32\\drivers\\b57nd60a.sys",
"C:\\Windows\\System32\\drivers\\wimmount.sys",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
"C:\\Windows\\System32\\drivers\\TsUsbFlt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
"C:\\Windows\\System32\\drivers\\acpi.sys",
"C:\\Windows\\System32\\drivers\\udfs.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\AutoWake",
"C:\\Windows\\System32\\drivers\\raspppoe.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
"C:\\Windows\\System32\\drivers\\hidbth.sys",
"C:\\Windows\\System32\\drivers\\irenum.sys",
"C:\\Windows\\System32\\drivers\\srv2.sys",
"C:\\Windows\\System32\\SearchIndexer.exe",
"C:\\Windows\\System32\\drivers\\serenum.sys",
"C:\\Windows\\System32\\drivers\\intelppm.sys",
"C:\\Windows\\System32\\drivers\\mskssrv.sys",
"C:\\Windows\\System32\\drivers\\mssmbios.sys",
"C:\\Windows\\System32\\drivers\\BrSerId.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
"C:\\Users\\",
"C:\\Windows\\System32\\drivers\\agilevpn.sys",
"C:\\Windows\\System32\\drivers\\usbohci.sys",
"C:\\Windows\\System32\\drivers\\vsmraid.sys",
"C:\\Windows\\System32\\drivers\\amdppm.sys",
"C:\\Windows\\System32\\drivers\\pcmcia.sys",
"C:\\Windows\\System32\\svchost.exe",
"C:\\Windows\\System32\\spoolsv.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SessionAgent",
"C:\\Windows\\System32\\drivers\\mspqm.sys",
"C:\\Windows\\System32\\drivers\\msisadrv.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
"C:\\Users\\cuck\\AppData\\",
"C:\\Windows\\System32\\drivers\\nvraid.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
"C:\\Windows\\ehome\\ehPrivJob.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
"C:\\Windows\\System32\\drivers\\mouclass.sys",
"C:\\Windows\\System32\\drivers\\vgapnp.sys",
"C:\\Windows\\System32\\drivers\\volmgrx.sys",
"C:\\Windows\\System32\\drivers\\arcsas.sys",
"C:\\Windows\\System32\\drivers\\amdide.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
"C:\\Windows\\System32\\powercfg.exe",
"C:\\Windows\\System32\\drivers\\termdd.sys",
"C:\\Windows\\System32\\drivers\\swenum.sys",
"C:\\Windows\\System32\\taskhost.exe",
"C:\\Windows\\System32\\drivers\\luafv.sys",
"C:\\Windows\\System32\\drivers\\tdx.sys",
"C:\\Windows\\System32\\drivers\\cmdide.sys",
"C:\\Windows\\System32\\drivers\\sbp2port.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\PolicyConverter",
"C:\\Windows\\System32\\drivers\\hidbatt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
"C:\\Windows\\System32\\drivers\\lsi_fc.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
"C:\\Windows\\System32\\drivers\\ksecpkg.sys",
"C:\\Windows\\System32\\drivers\\USBSTOR.SYS",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURActivate",
"C:\\Windows\\System32\\drivers\\tssecsrv.sys",
"C:\\Windows\\System32\\drivers\\ndistapi.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Diagnosis\\Scheduled",
"C:\\Windows\\System32\\drivers\\Wdf01000.sys",
"C:\\Windows\\System32\\drivers\\discache.sys",
"C:\\Windows\\System32\\drivers\\usbprint.sys",
"C:\\Windows\\System32\\drivers\\rdbss.sys",
"C:\\Windows\\System32\\drivers\\errdev.sys",
"C:\\Windows\\System32\\drivers\\processr.sys",
"C:\\Windows\\System32\\drivers\\rdpbus.sys",
"C:\\Windows\\System32\\sc.exe",
"C:\\Windows\\System32\\drivers\\mspclock.sys",
"C:\\Windows\\System32\\drivers\\aliide.sys",
"C:\\Windows\\System32\\drivers\\mpio.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
"C:\\Windows\\System32\\drivers\\evbda.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\mcupdate",
"C:\\Windows\\System32\\wermgr.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
"C:\\Windows\\System32\\drivers\\ql2300.sys",
"C:\\Windows\\System32\\drivers\\umbus.sys",
"C:\\Windows\\System32\\drivers\\tdtcp.sys",
"C:\\Windows\\System32\\drivers\\acpipmi.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
"C:\\Windows\\System32\\drivers\\UAGP35.SYS",
"C:\\Windows\\System32\\drivers\\adpahci.sys",
"C:\\Windows\\System32\\drivers\\sffdisk.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
"C:\\Windows\\System32\\notepad.exe",
"C:\\Windows\\System32\\drivers\\arc.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
"C:\\Windows\\System32\\drivers\\ohci1394.sys",
"C:\\Windows\\System32\\drivers\\wfplwf.sys",
"C:\\Python27\\",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RecordingRestart",
"C:\\Windows\\System32\\drivers\\volmgr.sys",
"\\Device\\NamedPipe\\",
"C:\\Windows\\System32\\drivers\\cdfs.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
"C:\\Windows\\System32\\drivers\\GAGP30KX.SYS",
"C:\\Windows\\System32\\csrss.exe",
"c:\\program files\\windows defender\\MpCmdRun.exe",
"C:\\Windows\\System32\\drivers\\1394ohci.sys",
"C:\\Windows\\System32\\drivers\\ksecdd.sys",
"C:\\Windows\\System32\\drivers\\usbehci.sys",
"C:\\Windows\\System32\\drivers\\amdsata.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\GadgetManager",
"C:\\Windows\\System32\\drivers\\MTConfig.sys",
"C:\\Windows\\System32\\drivers\\crcdisk.sys",
"C:\\Windows\\System32\\drivers\\mouhid.sys",
"C:\\Windows\\System32\\drivers\\BrUsbMdm.sys",
"C:\\Windows\\System32\\drivers\\lsi_scsi.sys",
"C:\\Windows\\System32\\drivers\\sermouse.sys",
"C:\\Users\\cuck\\",
"C:\\Windows\\System32\\drivers\\scfilter.sys",
"C:\\Windows\\System32\\sdclt.exe",
"C:\\Windows\\",
"C:\\Windows\\System32\\drivers\\http.sys",
"C:\\Windows\\System32\\drivers\\raspptp.sys",
"C:\\Windows\\System32\\drivers\\viaide.sys",
"C:\\Windows\\System32\\drivers\\tcpipreg.sys",
"C:\\Windows\\System32\\drivers\\qwavedrv.sys",
"C:\\Windows\\System32\\drivers\\mrxsmb.sys",
"C:\\Windows\\System32\\drivers\\AGP440.sys",
"C:\\Windows\\System32\\wsqmcons.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
"C:\\Windows\\System32\\drivers\\sffp_mmc.sys"
],
"regkey_opened": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\isapnp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Modem",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srvnet\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06308A56-69E7-4844-A784-8509C25B6C62}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Filetrace\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CC35D2E9-B9E1-4ADC-9DA5-71487D9E9EB5}",
"HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VaultSvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lmhosts",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4DE0CAB9-ECFE-4AA9-B95A-FE815A2EAA4E}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FltMgr\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_32\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBth",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcLocator",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wdf01000\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehSched\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDProxy\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iaStorV",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D0250F3F-6480-484F-B719-42F659AC64D5}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Schedule",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPDR",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vga\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MegaSR",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\discache",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2470470F-2634-478E-B181-571E98A789BB}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vds",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WbioSrvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbcir\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BDESVC\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache3.0.0.0\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WMPNetworkSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDPIPE",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rspndr\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WIMMount\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mshidkmdf\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1BB08CFD-C6AD-44C7-BD0B-8F23035A5731}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BDESVC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProfSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouhid\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B81A55E6-C03C-4EF0-B86F-A80A89DF468D}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Npfs",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbFlt\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppuinotify\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\1394ohci",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EventSystem",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stexstor\\Parameters",
"HKEY_CURRENT_USER\\Software\\Classes\\htmlfile\\shell\\open\\command",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAgileVpn",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EapHost\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVE",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NlaSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nv_agp\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{3307E641-F5EE-49E6-A1FE-BFB5D671441C}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbMdm\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\monitor",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinDefend",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidUsb\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Processor\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgrx\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Schedule\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IKEEXT",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A656BBE1-4E3E-4C8A-BD79-A8CA56782753}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection\\NAPStatus UI",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdK8\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{87F56B34-044E-4A48-8FDD-087BFABD5ECF}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UxSms\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltUp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\drmkaud",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fvevol",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CscService\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MRxDAV\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\s3cap\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ACPI",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\viaide",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\i8042prt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{00BB5F5C-4A20-4FD6-8900-4699F989BF01}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\discache\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanServer",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid2\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\exfat",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbohci",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Power",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mountmgr",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\CrawlStartPages",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4D19A151-A712-4920-AC6D-6C6FD81C8CDB}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteRegistry",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wercplsupport\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BFE\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPNAT\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storflt\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A132EB1D-A1EA-48EF-8B69-9358EADF5BD3}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql2300",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swenum",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\E1G60\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpahci\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcLocator\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DPS",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msahci\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SessionEnv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serial",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanWorkstation",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netman\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NativeWifiP\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdxata",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelppm\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tunnel\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SSDPSRV",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C4375D81-FA72-45AC-85F2-3B86A11CCC7D}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RacTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbSer\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4FDEA3B5-7CDE-48F7-940C-43CDBB18FB20}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wd\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nv_agp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmRdpService\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tdx\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Browser",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ohci1394",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPCDD",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msisadrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS2\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBatt\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\isapnp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermDD\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KtmRm",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetTcpPortSharing\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FltMgr",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fastfat",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\drmkaud\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\mcupdate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hkmsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iphlpsvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_sd",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{82676C49-21A7-4605-AA06-E04A067FB611}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sfloppy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURActivate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\megasas",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Appinfo",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TapiSrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\defragsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrSerWdm\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdpbus\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDIS",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{600F3312-A477-448A-936D-EB2DF977300B}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVEdrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAcd",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbehci",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sermouse\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dmvsc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPCSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Brserid\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_FC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wcncsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SessionEnv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sfloppy\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BITS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsata",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSDTC\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PolicyAgent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RACAgent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CompositeBus\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TBS\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wbengine\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupProvider\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5F5A18EB-DC73-4E45-A11C-B59043598412}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiSystemHost\\Parameters",
"HKEY_USERS\\.DEFAULT\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinRM\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HpSAMD",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbSer",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbFlt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cmdide",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BTHMODEM\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\udfs\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\THREADORDER\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ohci1394\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\MemUsageTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinHttpAutoProxySvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPAutoReg\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance\\WinSAT",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AFD",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCardSvr\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupProvider",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WbioSrvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupListener",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CertPropSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidIr",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrkWks",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volsnap\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SysMain",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\secdrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\scfilter\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arcsas\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\viaide\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecDD",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hidserv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DcomLaunch\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Beep",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSTEE",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CLFS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\atapi\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pciide",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WANARP\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lmhosts\\Parameters",
"HKEY_USERS\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdio",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vsmraid",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSTEE\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpu320",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdclass\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdpbus",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcSs",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adp94xx",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CmBatt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppIDSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PeerDistSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Fax\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tssecsrv",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2E941CB2-1B33-47C4-905B-8B4278819513}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpu320\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AsyncMac\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NlaSvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9979CB83-103A-4105-9E5D-C74B0AF6D198}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPCLOCK\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdbss",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RegisterSearch",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdPHost",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioSrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wcncsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Tcpip\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Rasl2tp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wbengine",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB07F7B4-BB95-4B74-9D32-4533D566453C}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rspndr",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hidserv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\napagent\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CmBatt\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PptpMiniport",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2pimsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAuto\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dhcp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsbs\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcEptMapper",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouclass",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SCSI\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPWD\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CD962721-73F1-4649-85D7-6884C1EF28D9}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gagp30kx\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PcaSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\napagent",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BTHMODEM",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ndisuio",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBth\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ehDRMInit",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDTCP\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinDefend\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Brserid",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis\\Scheduled",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wanarpv6",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdyboost\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netlogon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UI0Detect",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FDResPub",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KeyIso",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Themes\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HpSAMD\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcEptMapper\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bowser\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E3163C33-301D-4730-A266-5518C5ED3967}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nfrd960",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Psched",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVEdrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WcsPlugInService",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UxSms",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBT",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tdx",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cmdide\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBIOS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermService\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CryptSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PcaSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdhid",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcw\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CertPropSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wudfsvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{96137355-BC34-4BA7-81B7-47C87B556E7D}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WcsPlugInService\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\blbdrive\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pciide\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wuauserv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasPppoe\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swprv\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SensrSvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}",
"HKEY_CURRENT_USER\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_CURRENT_USER\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbhub\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wercplsupport",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\flpydisk\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkCards\\12",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stisvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netlogon\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SNMPTRAP\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouhid",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\upnphost\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nfrd960\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MMCSS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HTTP\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hwpolicy\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VgaSave",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IRENUM\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sbp2port\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tcpipreg",
"HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ws2ifsl",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioSrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiServiceHost\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2psvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcSs\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HTTP",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ebdrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisCap",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\W32Time",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{8C5ED038-CFAD-48A0-BB2F-D128286E49B3}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\atapi",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Power\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\E1G60",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPREFMP",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_sd\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvraid",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_64",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ntfs\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vwifibus",
"HKEY_CURRENT_USER\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pla\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPENCDD",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AxInstSV\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAgileVpn\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ALG\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b06bdrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VaultSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql2300\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Msfs\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sermouse",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanServer\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\i8042prt\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NativeWifiP",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdK8",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\PolicyConverter",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storflt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SstpSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wlansvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrustedInstaller\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC668097-4D6B-4093-AC14-014C09DBF820}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpsdrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPDBusEnum",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PerfHost\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\udfs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BE669C13-8165-4536-96D0-6D6C39292AAE}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{613612BA-897D-44CE-8DC1-8FC283F9FD51}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WebClient",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{448186F9-75B9-4FB7-A6E0-B19A2BADC1BE}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MRxDAV",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hkmsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Null\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AsyncMac",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpio\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbGD",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CNG",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mcx2Svc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdide\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tssecsrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CompositeBus",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\agp440\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermService",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9435F817-FED2-454E-88CD-7F78FDA62C48}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vmbus",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{268014E7-A27E-4FD7-89A6-A481DA222EC8}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BFE",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Tcpip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WudfPf\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdbss\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouclass\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iScsiPrt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmRdpService",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SDRSVC\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinRM",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DXGKrnl\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stisvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPBusEnum\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tunnel",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbuhci\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPDR\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06CD2154-751E-469F-8E4A-C3F118356423}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WSearch\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DcomLaunch",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hcw85cir",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehSched",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EventSystem\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\THREADORDER",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AxInstSV",
"HKEY_USERS\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vdrvroot\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Psched\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FileInfo",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WMPNetworkSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAcd\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PptpMiniport\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Parport",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbohci\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisWan\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermDD",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DXGKrnl",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uagp35",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WerSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Disk",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSiSCSI",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PEAUTH\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serenum\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storvsc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteAccess\\Parameters",
"HKEY_USERS\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDIS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VSS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdide",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\AitAgent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5A40E926-9E86-4B89-9CFD-B12311724371}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{72DB7465-BC54-491B-A92A-4637A28C9BBF}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbGD\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SstpSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvstor\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache3.0.0.0",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\USBSTOR",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MsRPC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_mmc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\umbus",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecDD\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppID\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\flpydisk",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wecsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PolicyAgent\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stexstor",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2psvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\netprofm\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AcpiPmi\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\umbus\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WmiAcpi\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\elxstor\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_mmc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swenum\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ErrDev",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F18ED8A5-C696-4951-B068-CA8E83634C04}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{17F5B0DE-8DA9-4280-8CB8-91422B9A8CE1}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSDTC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\partmgr\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MozillaMaintenance\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPREFMP\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv2",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\elxstor",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore\\SR",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iScsiPrt\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MozillaMaintenance",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vdrvroot",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dnscache\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MMCSS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TCPIP6\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager\\Interactive",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adp94xx\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gpsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wmiApSrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProtectedStorage",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VgaSave\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b57nd60a",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CLFS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ndisuio\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wscsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB02381F-D652-4B1C-894A-712498C62C51}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dmvsc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsata\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b57nd60a\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FDResPub\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CSC\\Parameters",
"HKEY_CURRENT_USER\\SOFTWARE\\Classes\\exefile\\shell\\open\\command",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Rasl2tp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hcw85cir\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A48CABBF-24C8-4B87-B00F-9261807C3B43}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\scfilter",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mountmgr\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\OptinNotification",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ws2ifsl\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WIMMount",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storvsc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPQM\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Filetrace",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SENS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\partmgr",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serenum",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TBS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteAccess",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisWan",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fastfat\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WSearch",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql40xx",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EFS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ebdrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\secdrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vsmraid\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb20\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ksthunk\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D018DE2F-F02A-4BDB-BA74-56BCD427BE40}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MsRPC\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SysMain\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffdisk",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Smb\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Smb",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecPkg",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdio\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Winmgmt\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CDA5F4EE-8293-4A5D-8564-04CD067D1A85}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arcsas",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0004",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0007",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0006",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0001",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0000",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0003",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0002",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid4",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SamSs",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0009",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0008",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VMBusHID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb20",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0005",
"HKEY_USERS\\.DEFAULT\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\idsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI\\ResolutionHost",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpsdrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SENS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dnscache",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wudfsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\eventlog",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SamSs\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb10",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DfsC\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS2",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Compbatt\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FB3C354D-297A-4EB2-9B58-090F6361906B}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wuauserv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\COMSysApp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wdf01000",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iirsp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TCPIP6",
"HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gpsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbccgp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpahci",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDTCP",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\crcdisk\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mup\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\aliide",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\1394ohci\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetTcpPortSharing",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{551B3807-871F-4E48-A943-2330449F0615}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPNAT",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCPolicySvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCPolicySvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdrom\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\USBSTOR\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5BE46CE1-CA9B-4CAD-B2E9-8C3F7716AF90}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WANARP",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisCap\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SessionAgent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\spldr",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry\\RegIdleBackup",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmPass",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Beep\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pci\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ErrDev\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppIDSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\aliide\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupListener\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltLo",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msdsm",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SharedAccess\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RecordingRestart",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AeLookupSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Browser\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\netprofm",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdPHost\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcmcia\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SNMPTRAP",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\megasas\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CryptSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\luafv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\luafv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DfsC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbprint\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Modem\\Parameters",
"HKEY_USERS\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msahci",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netman",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Winmgmt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EFS",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A8B18D02-60CD-4305-90CC-7DAAC028BDCD}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdhid\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uliagpkx\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_FC\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsi",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UI0Detect\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KtmRm\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPCLOCK",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv2\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\COMSysApp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdrom",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ALG",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisTapi\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MpsSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\blbdrive",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltUp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HDAudBus",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\GadgetManager",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid4\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelide",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ACPI\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IKEEXT\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\seclogon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pla",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bthserv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProtectedStorage\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinHttpAutoProxySvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppMgmt\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehRecvr",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AeLookupSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bthserv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pci",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBT\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System\\ConvertLogEntries",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPAutoReg",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DPS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasSstp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcw",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmPass\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PEAUTH",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TabletInputService",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehRecvr\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Spooler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcmcia",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbehci\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
"HKEY_USERS\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidUsb",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk\\Proxy",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSiSCSI\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsbs",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MpsSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BITS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrustedInstaller",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VSS\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B43033E6-1453-4AD6-AFBA-C03CFC178286}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteRegistry\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B78DBF96-841E-4336-BFE9-1C4975F9DA60}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelppm",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid2",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Spooler\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gagp30kx",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasMan",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelide\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bowser",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPDBusEnum\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MpIdleTask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WacomPen",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_64\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dot3svc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wd",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\agp440",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WmiAcpi",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{874CFED9-D01D-4D16-9775-B8A7A05004BF}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msiserver\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serial\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\defragsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecPkg\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FsDepends",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\monitor\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPWD",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgrx",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IpFilterDriver",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb10\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location\\Notifications",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MTConfig",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPCSvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MegaSR\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PerfHost",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srvnet",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7F9C951C-D364-4B70-8D07-D2C9B7F76E35}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Null",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\s3cap",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPCDD\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC\\HotStart",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vga",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPMIDRV",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hwpolicy",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EapHost",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\AutoWake",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsiproxy\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Npfs\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dhcp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\StorSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\upnphost",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volsnap",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\StorSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vmbus\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wlansvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CSC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0010",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0011",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A7C73732-9F11-4281-8D19-764D4EC9D94D}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7DC691A2-CB15-44DB-853C-19938051BB22}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ntfs",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wanarpv6\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SSDPSRV\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{994C86AD-A929-4B2C-88A0-4E25A107A029}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VMBusHID\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSKSSRV",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrSerWdm",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBatt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WebClient\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-32-544",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCardSvr",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbuhci",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mshidkmdf",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SDRSVC",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KeyIso\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasPppoe",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_32",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPQM",
"HKEY_LOCAL_MACHINE\\Software\\Classes\\htmlfile\\shell\\open\\command",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdPPM",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\idsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\spldr\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras\\MobilityManager",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgr\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbprint",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FsDepends\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioEndpointBuilder",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanWorkstation\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msisadrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDPIPE\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ShellHWDetection",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbhub",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbcir",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uliagpkx",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsi\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vwifibus\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iphlpsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vds\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbccgp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WfpLwf\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MTConfig\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tcpipreg\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AFD\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{28011108-68DF-4C73-B91B-57427D501BBA}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sbp2port",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdfs\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\exfat\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpio",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiServiceHost",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WfpLwf",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WwanSvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasMan\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Appinfo\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iaStorV\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fvevol\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WudfPf",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dot3svc\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WerSvc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI\\LPRemove",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiSystemHost",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2pimsvc\\Parameters",
"HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AcpiPmi",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PlugPlay\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HdAudAddService\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkCards",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PeerDistSvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsiproxy",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppMgmt",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HDAudBus\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b06bdrv\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FileInfo\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPMIDRV\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Fax",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WwanSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wmiApSrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPBusEnum",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TapiSrv",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SharedAccess",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql40xx\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CscService",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SensrSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisTapi",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbMdm",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDProxy",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mcx2Svc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PlugPlay",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdPPM\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B936B1AF-0C7E-4C4D-84F1-CF67453259A1}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\circlass\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVE\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vhdmp\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\seclogon\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SCSI",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Processor",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uagp35\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPENCDD\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Themes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msiserver",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ksthunk",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ShellHWDetection\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iirsp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\W32Time\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CNG\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\crcdisk",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Parport\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Msfs",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrkWks\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WacomPen\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidIr\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IRENUM",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppuinotify",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HdAudAddService",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Compbatt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F6B1AFFE-48F0-4340-9F59-C73DDA17C17D}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mssmbios\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swprv",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{40DD7C5E-DA67-4A78-B96C-582A4CBAEDF3}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdxata\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\eventlog\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProfSvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msdsm\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBIOS\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mssmbios",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltLo\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvstor",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvraid\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasSstp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPsvc\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSKSSRV\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C016366B-7126-46CA-B36B-592A3D95A60B}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IpFilterDriver\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mup",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgr",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vhdmp",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TabletInputService\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdyboost",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdfs",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wscsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioEndpointBuilder\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wecsvc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffdisk\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAuto",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Disk\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdclass",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\circlass"
],
"file_written": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe"
],
"regkey_deleted": [
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Sidebar",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\mctadmin"
],
"connects_ip": [
"103.114.163.252"
],
"file_exists": [
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
"C:\\Windows\\System32\\drivers\\hdaudbus.sys",
"C:\\Windows\\System32\\drivers\\hwpolicy.sys",
"C:\\Windows\\System32\\drivers\\vga.sys",
"C:\\Windows\\System32\\drivers\\filetrace.sys",
"C:\\Windows\\System32\\drivers\\amdxata.sys",
"C:\\Windows\\System32\\drivers\\pacer.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
"C:\\Windows\\System32\\drivers\\lsi_fc.sys",
"C:\\Windows\\System32\\drivers\\USBSTOR.SYS",
"C:\\Windows\\System32\\drivers\\amdk8.sys",
"C:\\Program Files\\Windows Media Player\\wmpnetwk.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURActivate",
"C:\\Windows\\System32\\drivers\\dxgkrnl.sys",
"C:\\Windows\\System32\\drivers\\usbhub.sys",
"C:\\Windows\\System32\\drivers\\wmiacpi.sys",
"C:\\Windows\\System32\\drivers\\Wdf01000.sys",
"C:\\Windows\\System32\\conhost.exe",
"C:\\Windows\\System32\\drivers\\fvevol.sys",
"C:\\Windows\\System32\\NOTEPAD.EXE %1",
"C:\\Windows\\System32\\drivers\\BrUsbSer.sys",
"C:\\Windows\\System32\\drivers\\MegaSR.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RegisterSearch",
"C:\\Windows\\System32\\wininit.exe",
"C:\\Windows\\System32\\drivers\\ksecpkg.sys",
"C:\\Windows\\System32\\drivers\\ndisuio.sys",
"C:\\Windows\\System32\\drivers\\rasacd.sys",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\",
"C:\\Windows\\System32\\drivers\\monitor.sys",
"C:\\Windows\\System32\\drivers\\ndistapi.sys",
"C:\\Windows\\System32\\drivers\\nsiproxy.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Diagnosis\\Scheduled",
"C:\\Windows\\System32\\drivers\\hcw85cir.sys",
"C:\\Windows\\System32\\drivers\\scfilter.sys",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf",
"C:\\Windows\\System32\\drivers\\discache.sys",
"C:\\Windows\\System32\\drivers\\tssecsrv.sys",
"C:\\Windows\\System32\\drivers\\volmgr.sys",
"C:\\Windows\\System32\\drivers\\wfplwf.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
"C:\\Windows\\System32\\drivers\\blbdrive.sys",
"C:\\Windows\\System32\\clfs.sys",
"C:\\Windows\\System32\\drivers\\mskssrv.sys",
"C:\\Windows\\System32\\drivers\\netbios.sys",
"C:\\Windows\\explorer.exe",
"C:\\Windows\\System32\\drivers\\tunnel.sys",
"C:\\Windows\\System32\\drivers\\wanarp.sys",
"C:\\Windows\\System32\\drivers\\adpu320.sys",
"C:\\Windows\\System32\\drivers\\intelide.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
"C:\\Windows\\System32\\drivers\\errdev.sys",
"C:\\Windows\\System32\\drivers\\ksthunk.sys",
"C:\\Windows\\System32\\drivers\\mspclock.sys",
"C:\\Windows\\System32\\drivers\\netbt.sys",
"C:\\Windows\\System32\\drivers\\hidir.sys",
"C:\\Windows\\System32\\drivers\\rdpbus.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
"C:\\Windows\\System32\\drivers\\WUDFPf.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
"C:\\Windows\\System32\\drivers\\mouclass.sys",
"C:\\Windows\\System32\\drivers\\rasl2tp.sys",
"C:\\Windows\\System32\\drivers\\atapi.sys",
"C:\\Windows\\System32\\drivers\\ipfltdrv.sys",
"C:\\Windows\\System32\\drivers\\aliide.sys",
"C:\\Windows\\System32\\drivers\\mpio.sys",
"C:\\Windows\\System32\\drivers\\fileinfo.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SystemRestore\\SR",
"C:\\Windows\\System32\\drivers\\RDPREFMP.sys",
"C:\\Windows\\System32\\drivers\\evbda.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\mcupdate",
"C:\\Windows\\System32\\drivers\\vmstorfl.sys",
"C:\\Windows\\System32\\smss.exe",
"C:\\Windows\\System32\\drivers\\flpydisk.sys",
"C:\\Windows\\System32\\drivers\\kbdhid.sys",
"C:\\Windows\\System32\\drivers\\lsi_sas2.sys",
"C:\\Windows\\System32\\drivers\\mrxdav.sys",
"C:\\Windows\\System32\\drivers\\mountmgr.sys",
"C:\\Windows\\System32\\drivers\\mrxsmb10.sys",
"C:\\Windows\\System32\\drivers\\srv.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
"C:\\Windows\\System32\\drivers\\CmBatt.sys",
"C:\\Windows\\System32\\drivers\\volmgrx.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
"C:\\Windows\\System32\\drivers\\PEAuth.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MobilePC\\HotStart",
"C:\\Windows\\System32\\drivers\\wacompen.sys",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MUI\\LPRemove",
"C:\\Windows\\System32\\drivers\\ULIAGPKX.SYS",
"C:\\Windows\\System32\\drivers\\pci.sys",
"C:\\Windows\\System32\\drivers\\circlass.sys",
"C:\\Windows\\System32\\drivers\\GAGP30KX.SYS",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
"C:\\Windows\\System32\\drivers\\CompositeBus.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
"C:\\Windows\\System32\\drivers\\drmkaud.sys",
"C:\\Windows\\System32\\drivers\\fdc.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
"C:\\Python27\\python.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe",
"C:\\Users\\cuck\\AppData\\Roaming",
"C:\\Windows\\System32\\drivers\\b57nd60a.sys",
"C:\\Windows\\System32\\drivers\\nwifi.sys",
"C:\\Windows\\System32\\drivers\\sffp_sd.sys",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
"C:\\Windows\\System32\\drivers\\bthmodem.sys",
"C:\\Windows\\System32\\drivers\\HdAudio.sys",
"C:\\Windows\\System32\\drivers\\compbatt.sys",
"C:\\Program Files\\Windows Sidebar\\Sidebar.exe \\autoRun",
"C:\\Windows\\System32\\drivers\\dfsc.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
"C:\\Windows\\System32\\drivers\\sisraid2.sys",
"C:\\Windows\\System32\\drivers\\BrUsbMdm.sys",
"C:\\Windows\\System32\\drivers\\usbuhci.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
"C:\\Windows\\System32\\drivers\\storvsc.sys",
"C:\\Windows\\System32\\drivers\\acpipmi.sys",
"C:\\Windows\\System32\\drivers\\disk.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
"C:\\Windows\\System32\\drivers\\BrFiltLo.sys",
"C:\\Windows\\System32\\drivers\\acpi.sys",
"C:\\Windows\\System32\\drivers\\udfs.sys",
"C:\\Windows\\System32\\lsass.exe",
"C:\\Windows\\System32\\drivers\\MTConfig.sys",
"C:\\Windows\\System32\\drivers\\kbdclass.sys",
"C:\\Windows\\System32\\drivers\\fltMgr.sys",
"C:\\Windows\\System32\\drivers\\viaide.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\AutoWake",
"C:\\Windows\\System32\\drivers\\raspppoe.sys",
"C:\\Windows\\System32\\drivers\\adpahci.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
"C:\\Windows\\System32\\drivers\\rdpdr.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
"C:\\Windows\\System32\\drivers\\BrFiltUp.sys",
"C:\\Windows\\System32\\drivers\\hidbth.sys",
"C:\\Windows\\System32\\drivers\\isapnp.sys",
"C:\\Windows\\System32\\drivers\\tdtcp.sys",
"C:\\Windows\\System32\\drivers\\sffdisk.sys",
"C:\\Windows\\System32\\drivers\\amdsbs.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
"C:\\Windows\\System32\\drivers\\arc.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
"C:\\Windows\\System32\\drivers\\irenum.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Location\\Notifications",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Autochk\\Proxy",
"C:\\Windows\\System32\\drivers\\ipnat.sys",
"C:\\Windows\\System32\\drivers\\tcpip.sys",
"C:\\Windows\\System32\\drivers\\usbcir.sys",
"C:\\Windows\\System32\\drivers\\srv2.sys",
"C:\\Windows\\System32\\SearchIndexer.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RecordingRestart",
"C:\\Windows\\System32\\drivers\\tdpipe.sys",
"C:\\Windows\\System32\\drivers\\vms3cap.sys",
"C:\\Windows\\System32\\drivers\\stexstor.sys",
"C:\\Windows\\System32\\drivers\\appid.sys",
"C:\\Windows\\System32\\drivers\\cng.sys",
"C:\\Windows\\System32\\drivers\\serenum.sys",
"C:\\Windows\\System32\\drivers\\intelppm.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RAC\\RacTask",
"C:\\Windows\\System32\\drivers\\bowser.sys",
"C:\\Windows\\System32\\drivers\\mssmbios.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
"C:\\Windows\\System32\\drivers\\agilevpn.sys",
"C:\\Windows\\System32\\drivers\\BrSerId.sys",
"C:\\Windows\\System32\\drivers\\mshidkmdf.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
"C:\\Windows\\System32\\drivers\\afd.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\AitAgent",
"C:\\Windows\\System32\\drivers\\usbprint.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Maintenance\\WinSAT",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
"C:\\Windows\\System32\\drivers\\TsUsbGD.sys",
"C:\\Windows\\System32\\drivers\\HpSAMD.sys",
"C:\\Windows\\System32\\drivers\\E1G6032E.sys",
"C:\\Windows\\System32\\drivers\\cdfs.sys",
"C:\\Windows\\System32\\drivers\\msdsm.sys",
"C:\\Windows\\System32\\drivers\\lltdio.sys",
"C:\\Windows\\System32\\csrss.exe",
"C:\\Windows\\System32\\services.exe",
"C:\\Windows\\System32\\drivers\\vhdmp.sys",
"C:\\Windows\\System32\\drivers\\mpsdrv.sys",
"C:\\Windows\\System32\\drivers\\usbohci.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
"C:\\Windows\\System32\\drivers\\rspndr.sys",
"C:\\Windows\\System32\\drivers\\pciide.sys",
"C:\\Windows\\System32\\dwm.exe",
"C:\\Windows\\System32\\drivers\\asyncmac.sys",
"C:\\Windows\\System32\\drivers\\raspptp.sys",
"C:\\Windows\\System32\\drivers\\mrxsmb20.sys",
"C:\\Windows\\System32\\drivers\\1394ohci.sys",
"C:\\Windows\\System32\\drivers\\BrSerWdm.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
"C:\\Windows\\System32\\drivers\\FsDepends.sys",
"C:\\Windows\\System32\\drivers\\usbehci.sys",
"C:\\Windows\\System32\\drivers\\vwifibus.sys",
"C:\\Windows\\System32\\drivers\\amdsata.sys",
"C:\\Windows\\System32\\drivers\\vdrvroot.sys",
"C:\\Windows\\System32\\drivers\\serial.sys",
"C:\\Windows\\System32\\drivers\\pcmcia.sys",
"C:\\Windows\\System32\\taskhost.exe",
"C:\\Windows\\System32\\drivers\\ndis.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
"C:\\Windows\\System32\\drivers\\lsi_sas.sys",
"C:\\Windows\\System32\\drivers\\mup.sys",
"C:\\Windows\\System32\\svchost.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
"C:\\Windows\\System32\\drivers\\nvstor.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SessionAgent",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\GadgetManager",
"C:\\Windows\\System32\\drivers\\bxvbda.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
"C:\\Windows\\System32\\drivers\\sisraid4.sys",
"C:\\Windows\\System32\\drivers\\rdyboost.sys",
"C:\\Windows\\System32\\drivers\\crcdisk.sys",
"C:\\Windows\\System32\\drivers\\msisadrv.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Ras\\MobilityManager",
"C:\\Windows\\System32\\drivers\\wd.sys",
"C:\\Windows\\System32\\drivers\\rdbss.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WDI\\ResolutionHost",
"C:\\Windows\\System32\\drivers\\mouhid.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
"C:\\Windows\\System32\\mctadmin.exe",
"C:\\Windows\\System32\\drivers\\RDPCDD.sys",
"C:\\Windows\\System32\\drivers\\ndiscap.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ehDRMInit",
"C:\\Windows\\System32\\drivers\\UAGP35.SYS",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
"C:\\Windows\\System32\\drivers\\lsi_scsi.sys",
"C:\\Windows\\System32\\drivers\\nvraid.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
"C:\\Windows\\System32\\drivers\\TsUsbFlt.sys",
"C:\\Windows\\System32\\drivers\\umpass.sys",
"C:\\Windows\\System32\\drivers\\ql2300.sys",
"C:\\Windows\\System32\\drivers\\sermouse.sys",
"C:\\Windows\\System32\\drivers\\partmgr.sys",
"C:\\Windows\\System32\\spoolsv.exe",
"C:\\Windows\\System32\\drivers\\csc.sys",
"C:\\Windows\\System32\\drivers\\rassstp.sys",
"C:\\Windows\\System32\\drivers\\i8042prt.sys",
"C:\\Windows\\System32\\drivers\\tdx.sys",
"C:\\Windows\\System32\\drivers\\iaStorV.sys",
"C:\\Windows\\System32\\drivers\\parport.sys",
"C:\\Windows\\System32\\drivers\\ndiswan.sys",
"C:\\Windows\\System32\\drivers\\nfrd960.sys",
"C:\\Windows\\System32\\drivers\\msahci.sys",
"C:\\Windows\\System32\\cmd.exe",
"C:\\Windows\\System32\\drivers\\processr.sys",
"C:\\Windows\\System32\\drivers\\mspqm.sys",
"C:\\Windows\\System32\\drivers\\ksecdd.sys",
"C:\\Windows\\System32\\drivers\\http.sys",
"C:\\Windows\\System32\\lsm.exe",
"C:\\Windows\\System32\\drivers\\volsnap.sys",
"C:\\Windows\\System32\\winlogon.exe",
"C:\\Windows\\System32\\drivers\\sfloppy.sys",
"C:\\Windows\\System32\\drivers\\amdppm.sys",
"C:\\Windows\\System32\\drivers\\umbus.sys",
"C:\\Windows\\System32\\drivers\\dmvsc.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
"C:\\Windows\\System32\\drivers\\IPMIDrv.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
"C:\\Windows\\System32\\drivers\\RDPENCDD.sys",
"C:\\Windows\\System32\\drivers\\usbccgp.sys",
"C:\\Windows\\System32\\drivers\\wimmount.sys",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
"C:\\Windows\\System32\\drivers\\megasas.sys",
"C:\\Windows\\System32\\drivers\\ws2ifsl.sys",
"C:\\Windows\\System32\\drivers\\vgapnp.sys",
"C:\\Windows\\inf\\",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Task Manager\\Interactive",
"C:\\Windows\\System32\\drivers\\VMBusHID.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
"C:\\Windows\\System32\\drivers\\NV_AGP.SYS",
"C:\\Windows\\System32\\drivers\\arcsas.sys",
"C:\\Windows\\System32\\drivers\\cdrom.sys",
"C:\\Windows\\System32\\drivers\\amdide.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
"C:\\Windows\\System32\\drivers\\srvnet.sys",
"C:\\Windows\\System32\\drivers\\msiscsi.sys",
"C:\\Windows\\System32\\drivers\\vmbus.sys",
"C:\\Windows\\System32\\drivers\\vsmraid.sys",
"C:\\Windows\\System32\\drivers\\elxstor.sys",
"C:\\Windows\\System32\\drivers\\tcpipreg.sys",
"C:\\Windows\\System32\\drivers\\hidusb.sys",
"C:\\Windows\\System32\\drivers\\termdd.sys",
"C:\\Windows\\System32\\drivers\\ql40xx.sys",
"C:\\Windows\\System32\\drivers\\qwavedrv.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
"C:\\Windows\\System32\\drivers\\pcw.sys",
"C:\\Windows\\System32\\drivers\\swenum.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Registry\\RegIdleBackup",
"C:\\Windows\\System32\\drivers\\mrxsmb.sys",
"C:\\Windows\\System32\\drivers\\AGP440.sys",
"C:\\Windows\\System32\\drivers\\ohci1394.sys",
"C:\\Windows\\System32\\drivers\\luafv.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
"C:\\tmpyzbctd\\bin\\inject-x64.exe",
"C:\\Windows\\System32\\drivers\\modem.sys",
"C:\\Windows\\System32\\drivers\\cmdide.sys",
"C:\\Windows\\System32\\drivers\\mstee.sys",
"C:\\Windows\\System32\\drivers\\adp94xx.sys",
"C:\\Windows\\System32\\drivers\\sbp2port.sys",
"C:\\Windows\\System32\\drivers\\smb.sys",
"C:\\Windows\\System32\\drivers\\iirsp.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
"C:\\Windows\\System32\\drivers\\sffp_mmc.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\PolicyConverter",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
"C:\\Windows\\System32\\drivers\\hidbatt.sys"
],
"file_failed": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\aitagent",
"C:\\Windows\\ehome\\ehrec",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\BthUdTask.exe",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\%1",
"C:\\Program",
"C:\\Windows\\ehome\\mcupdate",
"C:\\Windows\\System32\\d",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\sc.exe"
],
"command_line": [
"\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe\" -accepteula",
"\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe\" -a s -ct -m -h *",
"\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe\" -accepteula"
],
"file_read": [
"C:\\Windows\\System32\\drivers\\amdk8.sys",
"C:\\Program Files\\Windows Media Player\\wmpnetwk.exe",
"C:\\Python27\\python.exe",
"C:\\Windows\\System32\\drivers\\filetrace.sys",
"C:\\Windows\\System32\\drivers\\ndisuio.sys",
"C:\\Windows\\System32\\drivers\\monitor.sys",
"C:\\Windows\\System32\\drivers\\WUDFPf.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
"C:\\Windows\\System32\\aepdu.dll",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
"C:\\Windows\\System32\\drivers\\blbdrive.sys",
"C:\\Windows\\System32\\clfs.sys",
"C:\\Windows\\System32\\drivers\\netbios.sys",
"C:\\Windows\\System32\\drivers\\mstee.sys",
"C:\\Windows\\System32\\drivers\\hidir.sys",
"C:\\Windows\\System32\\drivers\\rasl2tp.sys",
"C:\\Windows\\System32\\drivers\\srvnet.sys",
"C:\\Windows\\System32\\drivers\\ipfltdrv.sys",
"C:\\Windows\\System32\\drivers\\asyncmac.sys",
"C:\\Windows\\System32\\drivers\\flpydisk.sys",
"C:\\Windows\\System32\\drivers\\lsi_sas2.sys",
"C:\\Windows\\System32\\drivers\\mrxdav.sys",
"C:\\Windows\\System32\\drivers\\mountmgr.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
"C:\\Windows\\System32\\drivers\\rdyboost.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MobilePC\\HotStart",
"C:\\Windows\\System32\\drivers\\wacompen.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MUI\\LPRemove",
"C:\\Windows\\System32\\drivers\\circlass.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
"C:\\Windows\\System32\\drivers\\CompositeBus.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
"C:\\Windows\\System32\\drivers\\fdc.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SystemRestore\\SR",
"C:\\Windows\\System32\\drivers\\bthmodem.sys",
"C:\\Windows\\System32\\drivers\\compbatt.sys",
"C:\\Windows\\System32\\drivers\\RDPCDD.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RegisterSearch",
"C:\\Windows\\System32\\mctadmin.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Location\\Notifications",
"C:\\Windows\\System32\\drivers\\BrUsbSer.sys",
"C:\\Windows\\System32\\drivers\\vdrvroot.sys",
"C:\\Windows\\System32\\drivers\\stexstor.sys",
"C:\\Windows\\System32\\drivers\\BrFiltUp.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
"C:\\Windows\\System32\\drivers\\mshidkmdf.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\AitAgent",
"C:\\Windows\\System32\\drivers\\TsUsbGD.sys",
"C:\\Windows\\System32\\drivers\\HpSAMD.sys",
"C:\\Windows\\System32\\drivers\\E1G6032E.sys",
"C:\\Windows\\System32\\drivers\\msdsm.sys",
"C:\\Windows\\System32\\drivers\\lltdio.sys",
"C:\\Windows\\System32\\drivers\\vhdmp.sys",
"C:\\Windows\\System32\\drivers\\usbuhci.sys",
"C:\\Windows\\System32\\drivers\\pciide.sys",
"C:\\Windows\\System32\\dwm.exe",
"C:\\Windows\\System32\\drivers\\rassstp.sys",
"C:\\Windows\\System32\\drivers\\IPMIDrv.sys",
"C:\\Windows\\System32\\raserver.exe",
"C:\\Windows\\System32\\drivers\\ndis.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
"C:\\Windows\\System32\\drivers\\tunnel.sys",
"C:\\Windows\\System32\\drivers\\hwpolicy.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
"C:\\Windows\\System32\\drivers\\sisraid4.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Ras\\MobilityManager",
"C:\\Windows\\System32\\drivers\\ndiscap.sys",
"C:\\Windows\\System32\\drivers\\umpass.sys",
"C:\\Windows\\System32\\drivers\\bowser.sys",
"C:\\Windows\\System32\\drivers\\partmgr.sys",
"C:\\Windows\\System32\\drivers\\iaStorV.sys",
"C:\\Windows\\System32\\drivers\\wfplwf.sys",
"C:\\Windows\\System32\\drivers\\usbccgp.sys",
"C:\\Windows\\System32\\cmd.exe",
"C:\\Windows\\System32\\drivers\\sffp_sd.sys",
"C:\\Windows\\System32\\drivers\\volsnap.sys",
"C:\\Windows\\ehome\\mcupdate.exe",
"C:\\Windows\\System32\\drivers\\mpsdrv.sys",
"C:\\Windows\\System32\\drivers\\wmiacpi.sys",
"C:\\Windows\\System32\\drivers\\MegaSR.sys",
"C:\\Windows\\System32\\drivers\\adpu320.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Task Manager\\Interactive",
"C:\\Windows\\System32\\drivers\\cdrom.sys",
"C:\\Windows\\System32\\drivers\\BrFiltLo.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
"C:\\Windows\\System32\\drivers\\pcw.sys",
"C:\\Windows\\System32\\Defrag.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Registry\\RegIdleBackup",
"C:\\Windows\\System32\\drivers\\megasas.sys",
"C:\\Windows\\System32\\drivers\\modem.sys",
"C:\\Windows\\System32\\drivers\\adp94xx.sys",
"C:\\Windows\\System32\\drivers\\iirsp.sys",
"C:\\Windows\\System32\\drivers\\rspndr.sys",
"C:\\Windows\\System32\\drivers\\hdaudbus.sys",
"C:\\Windows\\System32\\drivers\\vga.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
"C:\\Windows\\System32\\drivers\\wanarp.sys",
"C:\\Windows\\System32\\drivers\\dmvsc.sys",
"C:\\Windows\\System32\\drivers\\FsDepends.sys",
"C:\\Windows\\System32\\conhost.exe",
"C:\\Windows\\System32\\drivers\\sisraid2.sys",
"C:\\Windows\\System32\\appidpolicyconverter.exe",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
"C:\\Windows\\System32\\drivers\\ULIAGPKX.SYS",
"C:\\Windows\\System32\\drivers\\rasacd.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Maintenance\\WinSAT",
"C:\\Windows\\System32\\drivers\\hcw85cir.sys",
"C:\\Windows\\System32\\drivers\\VMBusHID.sys",
"C:\\Windows\\System32\\drivers\\intelide.sys",
"C:\\Windows\\System32\\drivers\\vmstorfl.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
"C:\\Windows\\System32\\drivers\\HdAudio.sys",
"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe",
"C:\\Windows\\System32\\drivers\\srv.sys",
"C:\\Windows\\System32\\drivers\\msiscsi.sys",
"C:\\Windows\\System32\\drivers\\CmBatt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
"C:\\Windows\\System32\\drivers\\bxvbda.sys",
"C:\\Windows\\System32\\drivers\\vwifibus.sys",
"C:\\Windows\\System32\\drivers\\drmkaud.sys",
"C:\\Windows\\System32\\drivers\\fvevol.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
"C:\\Windows\\System32\\ndfapi.dll",
"C:\\Windows\\System32\\drivers\\ksthunk.sys",
"C:\\Windows\\System32\\drivers\\ipnat.sys",
"C:\\Windows\\System32\\drivers\\kbdhid.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
"C:\\Windows\\System32\\drivers\\disk.sys",
"C:\\Windows\\System32\\lpremove.exe",
"C:\\Windows\\System32\\lsass.exe",
"C:\\Windows\\System32\\drivers\\kbdclass.sys",
"C:\\Windows\\System32\\drivers\\fltMgr.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
"C:\\Windows\\System32\\drivers\\smb.sys",
"C:\\Windows\\System32\\drivers\\isapnp.sys",
"C:\\Windows\\System32\\drivers\\amdsbs.sys",
"C:\\Windows\\System32\\lsm.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Autochk\\Proxy",
"C:\\Windows\\System32\\drivers\\usbcir.sys",
"C:\\Windows\\System32\\drivers\\vmbus.sys",
"C:\\Windows\\System32\\drivers\\tdpipe.sys",
"C:\\Windows\\System32\\drivers\\appid.sys",
"C:\\Windows\\System32\\drivers\\cng.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
"C:\\Windows\\System32\\drivers\\afd.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
"C:\\Windows\\System32\\drivers\\tcpip.sys",
"C:\\Windows\\System32\\services.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
"C:\\Windows\\System32\\drivers\\BrSerWdm.sys",
"C:\\Windows\\System32\\drivers\\ndiswan.sys",
"C:\\Windows\\System32\\drivers\\serial.sys",
"C:\\Windows\\System32\\drivers\\lsi_sas.sys",
"C:\\Windows\\System32\\DFDWiz.exe",
"C:\\Windows\\System32\\drivers\\dxgkrnl.sys",
"C:\\Windows\\System32\\dfdts.dll",
"C:\\Windows\\System32\\drivers\\nvstor.sys",
"C:\\Windows\\System32\\LocationNotifications.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WDI\\ResolutionHost",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ehDRMInit",
"C:\\Windows\\System32\\drivers\\csc.sys",
"C:\\Windows\\System32\\drivers\\i8042prt.sys",
"C:\\Windows\\System32\\gatherNetworkInfo.vbs",
"C:\\Windows\\System32\\drivers\\parport.sys",
"C:\\Windows\\System32\\drivers\\nfrd960.sys",
"C:\\Windows\\System32\\drivers\\msahci.sys",
"C:\\Program Files\\Windows Media Player\\wmpnscfg.exe",
"C:\\Windows\\System32\\winlogon.exe",
"C:\\Windows\\System32\\drivers\\sfloppy.sys",
"C:\\Windows\\System32\\drivers\\RDPENCDD.sys",
"C:\\Windows\\System32\\wininit.exe",
"C:\\Windows\\System32\\drivers\\nwifi.sys",
"C:\\Windows\\System32\\drivers\\ws2ifsl.sys",
"C:\\Windows\\System32\\drivers\\PEAuth.sys",
"C:\\Windows\\System32\\drivers\\NV_AGP.SYS",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
"C:\\Windows\\System32\\drivers\\rdpdr.sys",
"C:\\Windows\\System32\\drivers\\elxstor.sys",
"C:\\Windows\\System32\\drivers\\hidusb.sys",
"C:\\Windows\\System32\\drivers\\ql40xx.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
"C:\\Windows\\System32\\drivers\\amdxata.sys",
"C:\\Windows\\System32\\drivers\\usbhub.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
"C:\\Windows\\System32\\drivers\\vms3cap.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
"C:\\Windows\\System32\\drivers\\nsiproxy.sys",
"C:\\Windows\\System32\\drivers\\mup.sys",
"C:\\Windows\\System32\\BFE.DLL",
"C:\\Windows\\explorer.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
"C:\\Windows\\System32\\drivers\\netbt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
"C:\\Windows\\System32\\drivers\\atapi.sys",
"C:\\Windows\\System32\\drivers\\storvsc.sys",
"C:\\Windows\\System32\\drivers\\fileinfo.sys",
"C:\\Windows\\System32\\drivers\\wd.sys",
"C:\\Windows\\System32\\drivers\\RDPREFMP.sys",
"C:\\Windows\\System32\\drivers\\pacer.sys",
"C:\\Windows\\System32\\drivers\\dfsc.sys",
"C:\\Windows\\System32\\drivers\\mrxsmb10.sys",
"C:\\Windows\\System32\\drivers\\mrxsmb20.sys",
"C:\\Windows\\System32\\appidcertstorecheck.exe",
"C:\\Windows\\System32\\drivers\\pci.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
"C:\\Windows\\System32\\drivers\\b57nd60a.sys",
"C:\\Windows\\System32\\drivers\\wimmount.sys",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
"C:\\Windows\\System32\\drivers\\TsUsbFlt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
"C:\\Windows\\System32\\drivers\\acpi.sys",
"C:\\Windows\\System32\\drivers\\udfs.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\AutoWake",
"C:\\Windows\\System32\\drivers\\raspppoe.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
"C:\\Windows\\System32\\drivers\\hidbth.sys",
"C:\\Windows\\System32\\drivers\\irenum.sys",
"C:\\Windows\\System32\\drivers\\srv2.sys",
"C:\\Windows\\System32\\SearchIndexer.exe",
"C:\\Windows\\System32\\drivers\\serenum.sys",
"C:\\Windows\\System32\\drivers\\intelppm.sys",
"C:\\Windows\\System32\\drivers\\mskssrv.sys",
"C:\\Windows\\System32\\drivers\\mssmbios.sys",
"C:\\Windows\\System32\\drivers\\BrSerId.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
"C:\\Windows\\System32\\drivers\\agilevpn.sys",
"C:\\Windows\\System32\\drivers\\usbohci.sys",
"C:\\Windows\\System32\\drivers\\vsmraid.sys",
"C:\\Windows\\System32\\drivers\\amdppm.sys",
"C:\\Windows\\System32\\drivers\\pcmcia.sys",
"C:\\Windows\\System32\\svchost.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SessionAgent",
"C:\\Windows\\System32\\drivers\\mspqm.sys",
"C:\\Windows\\System32\\drivers\\msisadrv.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
"C:\\Windows\\System32\\drivers\\nvraid.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
"C:\\Windows\\ehome\\ehPrivJob.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
"C:\\Windows\\System32\\drivers\\mouclass.sys",
"C:\\Windows\\System32\\drivers\\vgapnp.sys",
"C:\\Windows\\System32\\drivers\\volmgrx.sys",
"C:\\Windows\\System32\\drivers\\arcsas.sys",
"C:\\Windows\\System32\\drivers\\amdide.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
"C:\\Windows\\System32\\powercfg.exe",
"C:\\Windows\\System32\\drivers\\termdd.sys",
"C:\\Windows\\System32\\drivers\\swenum.sys",
"C:\\Windows\\System32\\taskhost.exe",
"C:\\Windows\\System32\\drivers\\luafv.sys",
"C:\\Windows\\System32\\drivers\\tdx.sys",
"C:\\Windows\\System32\\drivers\\cmdide.sys",
"C:\\Windows\\System32\\drivers\\sbp2port.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\PolicyConverter",
"C:\\Windows\\System32\\drivers\\hidbatt.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
"C:\\Windows\\System32\\drivers\\lsi_fc.sys",
"C:\\Windows\\System32\\drivers\\ksecpkg.sys",
"C:\\Windows\\System32\\drivers\\USBSTOR.SYS",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURActivate",
"C:\\Windows\\System32\\drivers\\tssecsrv.sys",
"C:\\Windows\\System32\\drivers\\ndistapi.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Diagnosis\\Scheduled",
"C:\\Windows\\System32\\drivers\\Wdf01000.sys",
"C:\\Windows\\System32\\drivers\\discache.sys",
"C:\\Windows\\System32\\drivers\\usbprint.sys",
"C:\\Windows\\System32\\drivers\\rdbss.sys",
"C:\\Windows\\System32\\drivers\\errdev.sys",
"C:\\Windows\\System32\\drivers\\processr.sys",
"C:\\Windows\\System32\\drivers\\rdpbus.sys",
"C:\\Windows\\System32\\sc.exe",
"C:\\Windows\\System32\\drivers\\mspclock.sys",
"C:\\Windows\\System32\\drivers\\aliide.sys",
"C:\\Windows\\System32\\drivers\\mpio.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
"C:\\Windows\\System32\\drivers\\evbda.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\mcupdate",
"C:\\Windows\\System32\\wermgr.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
"C:\\Windows\\System32\\drivers\\ql2300.sys",
"C:\\Windows\\System32\\drivers\\umbus.sys",
"C:\\Windows\\System32\\drivers\\tdtcp.sys",
"C:\\Windows\\System32\\drivers\\acpipmi.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
"C:\\Windows\\System32\\drivers\\UAGP35.SYS",
"C:\\Windows\\System32\\drivers\\adpahci.sys",
"C:\\Windows\\System32\\drivers\\sffdisk.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
"C:\\Windows\\System32\\notepad.exe",
"C:\\Windows\\System32\\drivers\\arc.sys",
"C:\\Windows\\System32\\drivers\\ohci1394.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RecordingRestart",
"C:\\Windows\\System32\\drivers\\volmgr.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RAC\\RacTask",
"C:\\Windows\\System32\\drivers\\cdfs.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
"C:\\Windows\\System32\\drivers\\GAGP30KX.SYS",
"C:\\Windows\\System32\\csrss.exe",
"c:\\program files\\windows defender\\MpCmdRun.exe",
"C:\\Windows\\System32\\drivers\\1394ohci.sys",
"C:\\Windows\\System32\\drivers\\ksecdd.sys",
"C:\\Windows\\System32\\drivers\\usbehci.sys",
"C:\\Windows\\System32\\drivers\\amdsata.sys",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\GadgetManager",
"C:\\Windows\\System32\\drivers\\MTConfig.sys",
"C:\\Windows\\System32\\drivers\\crcdisk.sys",
"C:\\Windows\\System32\\drivers\\mouhid.sys",
"C:\\Windows\\System32\\drivers\\BrUsbMdm.sys",
"C:\\Windows\\System32\\drivers\\lsi_scsi.sys",
"C:\\Windows\\System32\\drivers\\sermouse.sys",
"C:\\Windows\\System32\\spoolsv.exe",
"C:\\Windows\\System32\\drivers\\scfilter.sys",
"C:\\Windows\\System32\\sdclt.exe",
"C:\\Windows\\System32\\drivers\\http.sys",
"C:\\Windows\\System32\\drivers\\raspptp.sys",
"C:\\Windows\\System32\\drivers\\viaide.sys",
"C:\\Windows\\System32\\drivers\\tcpipreg.sys",
"C:\\Windows\\System32\\drivers\\qwavedrv.sys",
"C:\\Windows\\System32\\drivers\\mrxsmb.sys",
"C:\\Windows\\System32\\drivers\\AGP440.sys",
"C:\\Windows\\System32\\wsqmcons.exe",
"C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
"C:\\Windows\\System32\\drivers\\sffp_mmc.sys"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{3307E641-F5EE-49E6-A1FE-BFB5D671441C}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{448186F9-75B9-4FB7-A6E0-B19A2BADC1BE}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D0250F3F-6480-484F-B719-42F659AC64D5}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MpIdleTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location\\Notifications\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0003\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI\\ResolutionHost\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB02381F-D652-4B1C-894A-712498C62C51}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2470470F-2634-478E-B181-571E98A789BB}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A656BBE1-4E3E-4C8A-BD79-A8CA56782753}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D018DE2F-F02A-4BDB-BA74-56BCD427BE40}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A7C73732-9F11-4281-8D19-764D4EC9D94D}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager\\Interactive\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP\\UPnPHostConfig\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore\\SR\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FB3C354D-297A-4EB2-9B58-090F6361906B}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB02381F-D652-4B1C-894A-712498C62C51}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B81A55E6-C03C-4EF0-B86F-A80A89DF468D}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06308A56-69E7-4844-A784-8509C25B6C62}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SessionAgent\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Logon Synchronization\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06308A56-69E7-4844-A784-8509C25B6C62}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{87F56B34-044E-4A48-8FDD-087BFABD5ECF}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB07F7B4-BB95-4B74-9D32-4533D566453C}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControls\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5BE46CE1-CA9B-4CAD-B2E9-8C3F7716AF90}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7DC691A2-CB15-44DB-853C-19938051BB22}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F18ED8A5-C696-4951-B068-CA8E83634C04}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CC35D2E9-B9E1-4ADC-9DA5-71487D9E9EB5}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BE669C13-8165-4536-96D0-6D6C39292AAE}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E3163C33-301D-4730-A266-5518C5ED3967}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4DE0CAB9-ECFE-4AA9-B95A-FE815A2EAA4E}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{40DD7C5E-DA67-4A78-B96C-582A4CBAEDF3}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{551B3807-871F-4E48-A943-2330449F0615}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B78DBF96-841E-4336-BFE9-1C4975F9DA60}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\MemUsageTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4D19A151-A712-4920-AC6D-6C6FD81C8CDB}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\PolicyConverter\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{268014E7-A27E-4FD7-89A6-A481DA222EC8}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4FDEA3B5-7CDE-48F7-940C-43CDBB18FB20}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A8B18D02-60CD-4305-90CC-7DAAC028BDCD}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RegisterSearch\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI\\LPRemove\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0004\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1BB08CFD-C6AD-44C7-BD0B-8F23035A5731}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{17F5B0DE-8DA9-4280-8CB8-91422B9A8CE1}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C016366B-7126-46CA-B36B-592A3D95A60B}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\AitAgent\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C016366B-7126-46CA-B36B-592A3D95A60B}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag\\ScheduledDefrag\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0001\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC668097-4D6B-4093-AC14-014C09DBF820}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrScheduleTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{96137355-BC34-4BA7-81B7-47C87B556E7D}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0005\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9979CB83-103A-4105-9E5D-C74B0AF6D198}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06CD2154-751E-469F-8E4A-C3F118356423}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B78DBF96-841E-4336-BFE9-1C4975F9DA60}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{8C5ED038-CFAD-48A0-BB2F-D128286E49B3}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ehDRMInit\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{72DB7465-BC54-491B-A92A-4637A28C9BBF}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\InstallPlayReady\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{82676C49-21A7-4605-AA06-E04A067FB611}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia\\SystemSoundsService\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{40DD7C5E-DA67-4A78-B96C-582A4CBAEDF3}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{96137355-BC34-4BA7-81B7-47C87B556E7D}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F6B1AFFE-48F0-4340-9F59-C73DDA17C17D}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk\\Proxy\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FB3C354D-297A-4EB2-9B58-090F6361906B}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{8C5ED038-CFAD-48A0-BB2F-D128286E49B3}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SystemDataProviders\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{72DB7465-BC54-491B-A92A-4637A28C9BBF}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RacTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4DE0CAB9-ECFE-4AA9-B95A-FE815A2EAA4E}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0002\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{994C86AD-A929-4B2C-88A0-4E25A107A029}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9435F817-FED2-454E-88CD-7F78FDA62C48}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{448186F9-75B9-4FB7-A6E0-B19A2BADC1BE}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0008\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7DC691A2-CB15-44DB-853C-19938051BB22}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CDA5F4EE-8293-4A5D-8564-04CD067D1A85}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CDA5F4EE-8293-4A5D-8564-04CD067D1A85}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{268014E7-A27E-4FD7-89A6-A481DA222EC8}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{613612BA-897D-44CE-8DC1-8FC283F9FD51}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection\\NAPStatus UI\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B43033E6-1453-4AD6-AFBA-C03CFC178286}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2E941CB2-1B33-47C4-905B-8B4278819513}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CC35D2E9-B9E1-4ADC-9DA5-71487D9E9EB5}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5F5A18EB-DC73-4E45-A11C-B59043598412}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\OptinNotification\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A7C73732-9F11-4281-8D19-764D4EC9D94D}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4D19A151-A712-4920-AC6D-6C6FD81C8CDB}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance\\WinSAT\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0010\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\mcupdate\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\GadgetManager\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC668097-4D6B-4093-AC14-014C09DBF820}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{874CFED9-D01D-4D16-9775-B8A7A05004BF}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0000\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{17F5B0DE-8DA9-4280-8CB8-91422B9A8CE1}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{87F56B34-044E-4A48-8FDD-087BFABD5ECF}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC\\HotStart\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\CrawlStartPages\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{551B3807-871F-4E48-A943-2330449F0615}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{3307E641-F5EE-49E6-A1FE-BFB5D671441C}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A48CABBF-24C8-4B87-B00F-9261807C3B43}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4FDEA3B5-7CDE-48F7-940C-43CDBB18FB20}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0009\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A48CABBF-24C8-4B87-B00F-9261807C3B43}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F6B1AFFE-48F0-4340-9F59-C73DDA17C17D}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A656BBE1-4E3E-4C8A-BD79-A8CA56782753}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2E941CB2-1B33-47C4-905B-8B4278819513}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D0250F3F-6480-484F-B719-42F659AC64D5}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5A40E926-9E86-4B89-9CFD-B12311724371}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0007\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras\\MobilityManager\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A8B18D02-60CD-4305-90CC-7DAAC028BDCD}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0006\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{28011108-68DF-4C73-B91B-57427D501BBA}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5A40E926-9E86-4B89-9CFD-B12311724371}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RecordingRestart\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D018DE2F-F02A-4BDB-BA74-56BCD427BE40}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Background Synchronization\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BE669C13-8165-4536-96D0-6D6C39292AAE}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RACAgent\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB07F7B4-BB95-4B74-9D32-4533D566453C}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{28011108-68DF-4C73-B91B-57427D501BBA}\\Actions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F18ED8A5-C696-4951-B068-CA8E83634C04}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{994C86AD-A929-4B2C-88A0-4E25A107A029}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkCards\\12\\ServiceName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURActivate\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis\\Scheduled\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{82676C49-21A7-4605-AA06-E04A067FB611}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B81A55E6-C03C-4EF0-B86F-A80A89DF468D}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURDiscovery\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CD962721-73F1-4649-85D7-6884C1EF28D9}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\shell\\open\\command\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System\\ConvertLogEntries\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\UpdateRecordPath\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2470470F-2634-478E-B181-571E98A789BB}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1BB08CFD-C6AD-44C7-BD0B-8F23035A5731}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0011\\NetCfgInstanceId",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0011\\MatchingDeviceId",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9979CB83-103A-4105-9E5D-C74B0AF6D198}\\Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\AutoWake\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscovery\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{874CFED9-D01D-4D16-9775-B8A7A05004BF}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5BE46CE1-CA9B-4CAD-B2E9-8C3F7716AF90}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B43033E6-1453-4AD6-AFBA-C03CFC178286}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5F5A18EB-DC73-4E45-A11C-B59043598412}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06CD2154-751E-469F-8E4A-C3F118356423}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CD962721-73F1-4649-85D7-6884C1EF28D9}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E3163C33-301D-4730-A266-5518C5ED3967}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)\\Id",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry\\RegIdleBackup\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}\\Actions",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9435F817-FED2-454E-88CD-7F78FDA62C48}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{613612BA-897D-44CE-8DC1-8FC283F9FD51}\\Path",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Parameters\\ServiceDll",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector\\Id",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\Description"
],
"regkey_written": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)"
]
},
"first_seen": 1589777586.59375,
"ppid": 2724
},
{
"process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
"process_name": "autorunsc64.exe",
"pid": 2096,
"summary": {
"file_created": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp"
],
"file_recreated": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
"\\Device\\KsecDD"
],
"regkey_written": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
"HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns\\EulaAccepted",
"HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\LanguageList"
],
"dll_loaded": [
"PROPSYS.dll",
"imagehlp.dll",
"kernel32",
"API-MS-Win-Security-LSALookup-L1-1-0.dll",
"apphelp.dll",
"api-ms-win-core-localization-l1-2-1",
"CFGMGR32.dll",
"kernel32.dll",
"credssp.dll",
"CRYPTBASE.dll",
"C:\\Windows\\system32\\rsaenh.dll",
"SensApi.dll",
"ntdll.dll",
"cryptsp.dll",
"api-ms-win-core-synch-l1-2-0",
"winhttp.dll",
"ntmarta.dll",
"bcrypt.dll",
"API-MS-WIN-Service-Management-L1-1-0.dll",
"cryptnet.dll",
"setupapi.dll",
"api-ms-win-appmodel-runtime-l1-1-1",
"API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
"API-MS-WIN-Service-winsvc-L1-1-0.dll",
"ole32.dll",
"USERENV.dll",
"CRYPTSP.dll",
"USER32.dll",
"DEVRTL.dll",
"C:\\Windows\\system32\\mswsock.dll",
"API-MS-Win-Security-SDDL-L1-1-0.dll",
"SspiCli.dll",
"IPHLPAPI.DLL",
"C:\\Windows\\system32\\Wintrust.dll",
"ncrypt.dll",
"WindowsCodecs.dll",
"C:\\Windows\\system32\\CRYPT32.dll",
"NSI.dll",
"OLEAUT32.dll",
"profapi.dll",
"SHELL32.dll",
"RPCRT4.dll",
"DNSAPI.dll",
"C:\\Windows\\System32\\wship6.dll",
"comctl32.dll",
"ext-ms-win-kernel32-package-current-l1-1-0",
"SHLWAPI.dll",
"API-MS-WIN-Service-Management-L2-1-0.dll",
"C:\\Windows\\system32\\advapi32.dll",
"api-ms-win-core-fibers-l1-1-1",
"WINTRUST.DLL",
"C:\\Windows\\system32\\cryptnet.dll",
"C:\\Windows\\system32\\crypt32.dll",
"C:\\Windows\\system32\\bcryptprimitives.dll",
"C:\\Windows\\system32\\Kernel32.dll",
"ADVAPI32.dll",
"C:\\Windows\\System32\\wshtcpip.dll",
"SETUPAPI.dll",
"WS2_32.dll",
"Cabinet.dll",
"WINHTTP.dll"
],
"file_opened": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
"C:\\Windows\\SysWOW64",
"C:\\",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\",
"C:\\Windows\\System32\\EhStorShell.dll",
"C:\\Windows\\System32\\SystemPropertiesPerformance.exe",
"C:\\ProgramData",
"c:\\Windows\\System32\\rundll32.exe",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
"c:\\program files (x86)\\windows mail\\WinMail.exe",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
"c:\\Windows\\SysWOW64\\ie4uinit.exe",
"C:\\Windows\\System32\\en-US\\WINHTTP.dll.mui",
"C:\\Windows\\SysWOW64\\en-US\\unregmp2.exe.mui",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
"c:\\Windows\\SysWOW64\\mscories.dll",
"c:\\Windows\\System32\\iconcodecservice.dll",
"C:\\Users\\cuck\\Desktop\\desktop.ini",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\Certificates\\",
"C:\\Windows\\explorer.exe",
"C:\\Windows\\System32\\en-US\\KERNELBASE.dll.mui",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
"C:\\Users\\cuck\\Music\\desktop.ini",
"C:\\Windows\\SysWOW64\\regsvr32.exe",
"c:\\Windows\\SysWOW64\\regsvr32.exe",
"C:\\Users\\cuck\\Favorites\\desktop.ini",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
"C:\\Program Files\\Windows Mail\\WinMail.exe",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
"C:\\Users\\cuck\\Downloads\\desktop.ini",
"C:\\Windows\\System32\\imageres.dll",
"C:\\ProgramData\\Microsoft\\",
"C:\\Program Files\\Windows Mail\\",
"c:\\program files\\windows mail\\WinMail.exe",
"c:\\Windows\\SysWOW64\\iedkcs32.dll",
"C:\\Users\\cuck\\Searches\\desktop.ini",
"C:\\Users\\cuck\\Links\\desktop.ini",
"c:\\Windows\\SysWOW64\\unregmp2.exe",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\",
"C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\ntexe.cat",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
"C:\\Users\\cuck\\AppData\\Roaming",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\",
"C:\\Program Files (x86)\\Windows Mail\\",
"C:\\Program Files (x86)\\Windows Mail\\WinMail.exe",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\",
"C:\\Program Files",
"C:\\Program Files (x86)",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
"C:\\ProgramData\\Microsoft\\Windows",
"C:\\Windows\\System32\\ntshrui.dll",
"C:\\Users\\cuck\\Saved Games\\desktop.ini",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu",
"C:\\Program Files\\Windows Mail",
"c:\\Windows\\SysWOW64\\rundll32.exe",
"C:\\Windows\\System32\\rsaenh.dll",
"C:\\Windows",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
"C:\\Program Files (x86)\\desktop.ini",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CRLs\\",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db",
"c:\\Windows\\System32\\userinit.exe",
"c:\\Windows\\System32\\systempropertiesperformance.exe",
"c:\\Windows\\System32\\imageres.dll",
"C:\\Users\\",
"c:\\Windows\\explorer.exe",
"C:\\Users\\cuck\\Videos\\desktop.ini",
"C:\\Users",
"C:\\Users\\cuck\\Documents\\desktop.ini",
"C:\\Windows\\System32\\shdocvw.dll",
"C:\\Users\\cuck\\Contacts\\desktop.ini",
"C:\\Users\\desktop.ini",
"C:\\Windows\\SysWOW64\\ie4uinit.exe",
"C:\\Users\\cuck",
"c:\\Windows\\System32\\rdpclip.exe",
"C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db",
"C:\\Windows\\System32\\catroot",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs",
"C:\\Windows\\System32\\catroot2",
"C:\\Users\\cuck\\AppData\\",
"c:\\Windows\\System32\\cmd.exe",
"c:\\Windows\\System32\\iedkcs32.dll",
"C:\\Users\\cuck\\AppData\\LocalLow",
"C:\\Users\\cuck\\AppData",
"C:\\Windows\\SysWOW64\\",
"C:\\Windows\\System32\\catroot2\\",
"C:\\Users\\cuck\\",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CTLs\\",
"c:\\Windows\\System32\\unregmp2.exe",
"C:\\Windows\\System32\\en-US\\unregmp2.exe.mui",
"C:\\Windows\\System32\\cscui.dll",
"C:\\Windows\\System32",
"C:\\Windows\\System32\\cmd.exe",
"C:\\Windows\\",
"C:\\Windows\\System32\\regsvr32.exe",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\",
"C:\\ProgramData\\Microsoft",
"C:\\Windows\\SysWOW64\\unregmp2.exe",
"C:\\Windows\\System32\\ie4uinit.exe",
"C:\\Program Files (x86)\\Windows Mail",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\",
"c:\\Windows\\System32\\regsvr32.exe",
"C:\\Users\\cuck\\Pictures\\desktop.ini",
"C:\\Windows\\System32\\rdpclip.exe",
"C:\\Program Files\\desktop.ini",
"c:\\Windows\\System32\\ie4uinit.exe",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft",
"C:\\Windows\\System32\\",
"C:\\Windows\\System32\\unregmp2.exe",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs",
"c:\\Windows\\System32\\mscories.dll",
"C:\\Windows\\System32\\userinit.exe"
],
"regkey_opened": [
"HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance\\Disabled",
"HKEY_CURRENT_USER\\Software\\Sysinternals",
"HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance",
"HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}",
"HKEY_LOCAL_MACHINE\\Software\\Sysinternals"
],
"resolves_host": [
"crl.microsoft.com",
"www.microsoft.com"
],
"file_written": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp"
],
"regkey_deleted": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE"
],
"file_deleted": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp"
],
"file_exists": [
"C:\\Windows\\System32\\rundll32.exe",
"C:\\Windows\\System32\\rdpclip.com",
"C:\\Windows\\System32\\explorer.exe",
"C:\\Users\\cuck\\AppData\\LocalLow",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled",
"C:\\Windows\\System32\\regsvr32.exe",
"C:\\Python27\\cmd.exe",
"C:\\Windows\\SysWOW64\\regsvr32.exe",
"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\rdpclip",
"C:\\Windows\\SysWOW64\\rundll32.exe",
"C:\\Python27\\explorer.exe",
"C:\\Windows\\System32\\SystemPropertiesPerformance.exe",
"C:\\Python27\\Scripts\\explorer.exe",
"C:\\Windows\\System32\\cmd.exe",
"C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\ntexe.cat",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
"C:\\Python27\\IconCodecService.dll",
"C:\\Python27\\Scripts\\SystemPropertiesPerformance.exe",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
"C:\\Python27\\rdpclip.com",
"C:\\Python27\\Scripts\\cmd.exe",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
"C:\\Windows\\System32\\rdpclip",
"C:\\Windows\\System32\\p2pcollab.dll",
"C:\\Python27\\Scripts\\IconCodecService.dll",
"C:\\Windows\\SysWOW64\\iedkcs32.dll",
"C:\\Windows\\System32\\catroot\\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\\",
"C:\\Windows\\SysWOW64\\unregmp2.exe",
"C:\\Windows\\System32\\ie4uinit.exe",
"C:\\Windows\\inf\\",
"C:\\Windows\\System32\\fveui.dll",
"C:\\Program Files (x86)\\Windows Mail\\WinMail.exe",
"C:\\Windows\\System32\\QAGENTRT.DLL",
"C:\\Windows\\System32\\mscories.dll",
"C:\\Windows\\explorer.exe",
"C:\\Python27\\SystemPropertiesPerformance.exe",
"C:\\Windows\\System32\\catroot2\\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\\",
"C:\\Windows\\SysWOW64\\ie4uinit.exe",
"C:\\Windows\\System32\\wbem\\rdpclip",
"C:\\Windows\\System32\\dnsapi.dll",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
"C:\\Windows\\rdpclip",
"C:\\Windows\\System32\\rdpclip.exe",
"C:\\Python27\\Scripts\\rdpclip.com",
"C:\\Windows\\rdpclip.com",
"C:\\Windows\\SysWOW64\\mscories.dll",
"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\rdpclip.com",
"C:\\Windows\\System32\\iedkcs32.dll",
"C:\\Python27\\Scripts\\rdpclip.exe",
"C:\\Python27\\Scripts\\rdpclip",
"C:\\Program Files\\Windows Mail\\WinMail.exe",
"C:\\Python27\\rdpclip.exe",
"C:\\Python27\\rdpclip",
"C:\\Windows\\System32\\wbem\\rdpclip.com",
"C:\\Windows\\System32\\unregmp2.exe",
"C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat",
"C:\\Windows\\System32\\IconCodecService.dll",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled",
"C:\\Users\\cuck\\AppData\\Local\\Temp",
"C:\\Windows\\System32\\userinit.exe",
"C:\\Python27\\regsvr32.exe",
"C:\\Python27\\Scripts\\regsvr32.exe"
],
"file_failed": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\%USERPROFILE%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\%USERPROFILE%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\F90F18257CBB4D84216AC1E1F3BB2C76",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\%USERPROFILE%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\",
"C:\\ProgramData\\Microsoft\\desktop.ini",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\C24EC5BDAF13613245B4CECC3DE91DC6",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled\\",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\B8CC409ACDBF2A2FE04C56F2875B1FD6",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\696F3DE637E6DE85B458996D49D759AD",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\desktop.ini",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled\\"
],
"guid": [
"{add8ba80-002b-11d0-8f0f-00c04fd7d062}",
"{08244ee6-92f0-47f2-9fc9-929baa2e7235}",
"{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
"{4e77131d-3629-431c-9818-c5679dc83e81}",
"{d9144dcd-e998-4eca-ab6a-dcd83ccba16d}",
"{dffacdc5-679f-4156-8947-c5c76bc0b67f}",
"{0c6c4200-c589-11d0-999a-00c04fd655e1}",
"{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}"
],
"file_read": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
"C:\\Users\\cuck\\Documents\\desktop.ini",
"C:\\Users\\cuck\\Searches\\desktop.ini",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
"C:\\Users\\cuck\\Links\\desktop.ini",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
"C:\\Users\\cuck\\Videos\\desktop.ini",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
"C:\\Users\\cuck\\Desktop\\desktop.ini",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
"C:\\Users\\cuck\\Contacts\\desktop.ini",
"C:\\Users\\desktop.ini",
"C:\\Users\\cuck\\Pictures\\desktop.ini",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
"C:\\Users\\cuck\\Music\\desktop.ini",
"C:\\Program Files\\desktop.ini",
"C:\\Users\\cuck\\Favorites\\desktop.ini",
"C:\\Users\\cuck\\Saved Games\\desktop.ini",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
"C:\\Users\\cuck\\Downloads\\desktop.ini",
"C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
"C:\\Program Files (x86)\\desktop.ini"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\RelativePath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Favorites",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\ProfileImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\Content Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Comment",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\StubPath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Load",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Roamable",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Name",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\ProfileImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\StorageDelegate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoWebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\StreamResourceType",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Pictures",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Version",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.44.3.4!7\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Stream",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HideOnDesktopPerUser",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HideFolderVerbs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DefaultIcon\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MaxSockaddrLength",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\SuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\RelativePath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\Safety Warning Level",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\CryptnetPreFetchTriggerPeriodSeconds",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Stream",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\Content Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsAliasedNotifications",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Max Cached Icons",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\WinStations\\RDP-Tcp\\InitialProgram",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\WinHttpSettings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsFORDISPLAY",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Cryptography\\PrivKeyCacheMaxItems",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\GlobalSession",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\AppSetup",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\DefaultIcon\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\LoadWithoutCOM",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\LoadWithoutCOM",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HideInWebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip6\\WinSock 2.0 Provider ID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledProcesses\\78ED498",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-18\\Flags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\StorageDelegateSuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxUrlRetrievalByteCount",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Stream",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\PerceivedType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Security",
"HKEY_CURRENT_USER\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\Mapping",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\\SuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DiagMatchAnyMask",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Stream",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\AltStartup",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\MapNetDriveVerbs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableUnsupportedCriticalExtensions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ini\\PerceivedType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\PublishExpandedPath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Name",
"HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\system32\\p2pcollab.dll,-8042",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Personal",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\MaxSockaddrLength",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Stream",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsFORPARSING",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\IconServiceLib",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\PreCreate",
"HKEY_CURRENT_USER\\Environment\\UserInitMprLogonScript",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SeparateProcess",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\97817950D81C9670CC34D809CF794431367EF474\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCountPerChain",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PreCreate",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\ChainCacheResyncFiletime",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\MachineThrottling",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\StreamResourceType",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Music",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\PublishExpandedPath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Video",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\Shell",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\DefaultIcon\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalRedirectOnly",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Startup",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\ParentFolder",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Roamable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip\\WinSock 2.0 Provider ID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\ShellComponent",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\RpcId",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InfoTip",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\Flags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsUniversalDelegate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ShareCredsWithWinHttp",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Parameters\\Transports",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\Enabled",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Icon",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Local AppData",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\SafeProcessSearchMode",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\HelperDllName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableMandatoryBasicConstraints",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetCrawling",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\LsaExtensionConfig\\SspiCli\\CheckSignatureRoutine",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\MinSockaddrLength",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\LsaExtensionConfig\\SspiCli\\CheckSignatureDll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\SuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\LoadWithoutCOM",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsParseDisplayName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\ShellComponent",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\UseDelayedAcceptance",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\Wds\\rdpwd\\StartupPrograms",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClassicShell",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\UseDropHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\ShellComponent",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.67.1.1!7\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableCANameConstraints",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\\InProcServer32\\LoadWithoutCOM",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp\\DisableBranchCache",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\PinToNameSpaceTree",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCertCount",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\Flags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\PreCreate",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{4E77131D-3629-431C-9818-C5679DC83E81} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\QueryForInfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\VmApplet",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Security",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Category",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DiagLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\MaximumAllowedAllocationSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InitFolderHandler",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\StreamResourceType",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Startup",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugFlags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Defaults\\Provider\\Microsoft Enhanced RSA and AES Cryptographic Provider\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Common Startup",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\StubPath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlCountInCert",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\RestrictedAttributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Attributes",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Taskman",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxySettingsPerUser",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Attributes",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates\\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Defaults\\Provider\\Microsoft Enhanced RSA and AES Cryptographic Provider\\Image Path",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.67.1.2!7\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Capabilities",
"HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\System32\\fveui.dll,-844",
"HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\System32\\fveui.dll,-843",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\RelativePath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Run",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\PreventItemCreationInUsersFilesFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.47.1.1!7\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\Flags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\MachineGuid",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\CallForAttributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MinSockaddrLength",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\InfoTip",
"HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\system32\\dnsapi.dll,-103",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\NoFileFolderJunction",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp\\Tracing\\Enabled",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResource",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F} {ADD8BA80-002B-11D0-8F0F-00C04FD7D062} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableWeakSignatureFlags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Serial_Access_Num",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Icon",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\SecurityProviders",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\SuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Security",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Stream",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\UseDelayedAcceptance",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates\\7D7F4414CCEF168ADF6BF40753B5BECD78375931\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\LocalRedirectOnly",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Name",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SafeBoot\\AlternateShell",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\TokenSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\RelativePath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\QueryForOverlay",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Cryptography\\PrivKeyCachePurgeIntervalSeconds",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParentFolder",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\ShellComponent",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ini\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Security",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\IsShortcut",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadOverride",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Common AltStartup",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\InfoTip",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{374DE290-123F-4565-9164-39C4925E467B}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\RelativePath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Desktop",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\InfoTip",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResource",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing\\State",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\StubPath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{56784854-C6CB-462B-8169-88E350ACB882}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Stream",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ini\\Content Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\HelperDllName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DontShowSuperHidden",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\FolderTypeID",
"HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\system32\\qagentrt.dll,-10",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\\Blob",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalRedirectOnly",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Attributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\Mapping",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\PerceivedType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalByteCount",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Cryptography\\PrivateKeyLifetimeSeconds",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Name",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Category",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableInetUnknownAuth",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSimpleStartMenu",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\SuppressionPolicy",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\ShellComponent",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\StubPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HasNavigationEnum",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\InitFolderHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Roamable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\FolderTypeID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\InfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\ParsingName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\LocalizedName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Name",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalRedirectOnly",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Stream",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\RelativePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\ParentFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\PreCreate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PublishExpandedPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Attributes",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\StreamResourceType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResource",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Name"
],
"directory_created": [
"C:\\Windows\\System32\\catroot2",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches",
"C:\\Windows\\System32\\catroot"
]
},
"first_seen": 1589777599.264999,
"ppid": 1268
}
][
{
"markcount": 1,
"families": [],
"description": "Collects information to fingerprint the system (MachineGuid, DigitalProductId, SystemBiosDate)",
"severity": 1,
"marks": [
{
"category": "registry",
"ioc": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\MachineGuid",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "recon_fingerprint"
},
{
"markcount": 1,
"families": [],
"description": "This executable has a PDB path",
"severity": 1,
"marks": [
{
"category": "pdb_path",
"ioc": "E:\\MyProjects\\SVN_PROJECT\\trunk\\XMR\\GetuserInfoClient\\SuperKillX\\x64\\Release\\SuperKillX.pdb",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "has_pdb"
},
{
"markcount": 1,
"families": [],
"description": "The file contains an unknown PE resource name possibly indicative of a packer",
"severity": 1,
"marks": [
{
"category": "resource name",
"ioc": "IMAGE_LIST",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "pe_unknown_resource_name"
},
{
"markcount": 1,
"families": [],
"description": "Foreign language identified in PE resource",
"severity": 2,
"marks": [
{
"name": "IMAGE_LIST",
"language": "LANG_CHINESE",
"offset": "0x000490c0",
"filetype": "Microsoft Cabinet archive data, 331565 bytes, 1 file",
"sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
"type": "generic",
"size": "0x00050f2d"
}
],
"references": [],
"name": "origin_langid"
},
{
"markcount": 1,
"families": [],
"description": "Searches running processes potentially to identify processes for sandbox evasion, code injection or memory dumping",
"severity": 2,
"marks": [
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "Process32NextW",
"return_value": 1,
"arguments": {
"process_name": "conhost.exe",
"snapshot_handle": "0x0000000000000190",
"process_identifier": 300
},
"time": 1589777673.46875,
"tid": 2740,
"flags": {}
},
"pid": 1268,
"type": "call",
"cid": 5049
}
],
"references": [],
"name": "injection_process_search"
},
{
"markcount": 1,
"families": [],
"description": "Checks adapter addresses which can be used to detect virtual network interfaces",
"severity": 2,
"marks": [
{
"call": {
"category": "network",
"status": 0,
"stacktrace": [],
"last_error": 0,
"nt_status": -1073741772,
"api": "GetAdaptersAddresses",
"return_value": 111,
"arguments": {
"flags": 15,
"family": 0
},
"time": 1589777604.295999,
"tid": 3020,
"flags": {}
},
"pid": 2096,
"type": "call",
"cid": 5281
}
],
"references": [],
"name": "antivm_network_adapters"
},
{
"markcount": 2,
"families": [],
"description": "The binary likely contains encrypted or compressed data indicative of a packer",
"severity": 2,
"marks": [
{
"entropy": 7.996078958553206,
"section": {
"size_of_data": "0x00051200",
"virtual_address": "0x00049000",
"entropy": 7.996078958553206,
"name": ".rsrc",
"virtual_size": "0x00051170"
},
"type": "generic",
"description": "A section with a high entropy has been found"
},
{
"entropy": 0.5481418918918919,
"type": "generic",
"description": "Overall entropy of this PE file is high"
}
],
"references": [
"http:\/\/www.forensickb.com\/2013\/03\/file-entropy-explained.html",
"http:\/\/virii.es\/U\/Using%20Entropy%20Analysis%20to%20Find%20Encrypted%20and%20Packed%20Malware.pdf"
],
"name": "packer_entropy"
},
{
"markcount": 16,
"families": [],
"description": "Checks for the Locally Unique Identifier on the system for a suspicious privilege",
"severity": 2,
"marks": [
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeDebugPrivilege"
},
"time": 1589777586.76575,
"tid": 2740,
"flags": {}
},
"pid": 1268,
"type": "call",
"cid": 65
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeDebugPrivilege"
},
"time": 1589777599.420999,
"tid": 2260,
"flags": {}
},
"pid": 2096,
"type": "call",
"cid": 85
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeSecurityPrivilege"
},
"time": 1589777599.436999,
"tid": 2260,
"flags": {}
},
"pid": 2096,
"type": "call",
"cid": 98
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeDebugPrivilege"
},
"time": 1589777599.436999,
"tid": 2260,
"flags": {}
},
"pid": 2096,
"type": "call",
"cid": 100
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeBackupPrivilege"
},
"time": 1589777599.436999,
"tid": 2260,
"flags": {}
},
"pid": 2096,
"type": "call",
"cid": 102
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeRestorePrivilege"
},
"time": 1589777599.436999,
"tid": 2260,
"flags": {}
},
"pid": 2096,
"type": "call",
"cid": 145
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeDebugPrivilege"
},
"time": 1589777255.627645,
"tid": 2328,
"flags": {}
},
"pid": 144,
"type": "call",
"cid": 92
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeSecurityPrivilege"
},
"time": 1589777255.627645,
"tid": 2328,
"flags": {}
},
"pid": 144,
"type": "call",
"cid": 105
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeDebugPrivilege"
},
"time": 1589777255.627645,
"tid": 2328,
"flags": {}
},
"pid": 144,
"type": "call",
"cid": 107
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeBackupPrivilege"
},
"time": 1589777255.627645,
"tid": 2328,
"flags": {}
},
"pid": 144,
"type": "call",
"cid": 109
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeRestorePrivilege"
},
"time": 1589777255.643645,
"tid": 2328,
"flags": {}
},
"pid": 144,
"type": "call",
"cid": 152
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeDebugPrivilege"
},
"time": 1589777273.45502,
"tid": 1432,
"flags": {}
},
"pid": 2716,
"type": "call",
"cid": 85
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeSecurityPrivilege"
},
"time": 1589777273.45502,
"tid": 1432,
"flags": {}
},
"pid": 2716,
"type": "call",
"cid": 98
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeDebugPrivilege"
},
"time": 1589777273.45502,
"tid": 1432,
"flags": {}
},
"pid": 2716,
"type": "call",
"cid": 100
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeBackupPrivilege"
},
"time": 1589777273.45502,
"tid": 1432,
"flags": {}
},
"pid": 2716,
"type": "call",
"cid": 102
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeRestorePrivilege"
},
"time": 1589777273.45502,
"tid": 1432,
"flags": {}
},
"pid": 2716,
"type": "call",
"cid": 145
}
],
"references": [],
"name": "privilege_luid_check"
},
{
"markcount": 2,
"families": [],
"description": "Terminates another process",
"severity": 2,
"marks": [
{
"call": {
"category": "process",
"status": 0,
"stacktrace": [],
"last_error": 109,
"nt_status": -1073741493,
"api": "NtTerminateProcess",
"return_value": 0,
"arguments": {
"status_code": "0x00000000",
"process_identifier": 2096,
"process_handle": "0x0000000000000184"
},
"time": 1589777684.54675,
"tid": 2204,
"flags": {}
},
"pid": 1268,
"type": "call",
"cid": 20241
},
{
"call": {
"category": "process",
"status": 0,
"stacktrace": [],
"last_error": 109,
"nt_status": -1073741493,
"api": "NtTerminateProcess",
"return_value": -1073741558,
"arguments": {
"status_code": "0x00000000",
"process_identifier": 2096,
"process_handle": "0x0000000000000184"
},
"time": 1589777684.54675,
"tid": 2204,
"flags": {}
},
"pid": 1268,
"type": "call",
"cid": 20242
}
],
"references": [],
"name": "terminates_remote_process"
},
{
"markcount": 2,
"families": [],
"description": "Installs itself for autorun at Windows startup",
"severity": 3,
"marks": [
{
"type": "generic",
"reg_key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
"reg_value": "\"%1\" %*"
},
{
"type": "generic",
"reg_key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
"reg_value": "\"%1\" %*"
}
],
"references": [],
"name": "persistence_autorun"
},
{
"markcount": 1,
"families": [],
"description": "Attempts to create or modify system certificates",
"severity": 3,
"marks": [
{
"category": "registry",
"ioc": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "modifies_certificates"
},
{
"markcount": 2,
"families": [],
"description": "Expresses interest in specific running processes",
"severity": 3,
"marks": [
{
"category": "process: potential process injection target",
"ioc": "winlogon.exe",
"type": "ioc",
"description": null
},
{
"category": "process: potential process injection target",
"ioc": "explorer.exe",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "process_interest"
},
{
"markcount": 3,
"families": [],
"description": "Uses Sysinternals tools in order to add additional command line functionality",
"severity": 3,
"marks": [
{
"category": "cmdline",
"ioc": "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe\" -accepteula",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe\" -a s -ct -m -h *",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe\" -accepteula",
"type": "ioc",
"description": null
}
],
"references": [
"docs.microsoft.com\/en-us\/sysinternals\/downloads\/"
],
"name": "sysinternals_tools_usage"
}
]The Yara rules did not detect anything in the file.
{
"tls": [],
"udp": [
{
"src": "192.168.56.101",
"dst": "192.168.56.255",
"offset": 546,
"time": 3.1348209381103516,
"dport": 137,
"sport": 137
},
{
"src": "192.168.56.101",
"dst": "192.168.56.255",
"offset": 20778,
"time": 9.134487867355347,
"dport": 138,
"sport": 138
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 22622,
"time": 56.30344295501709,
"dport": 5355,
"sport": 49556
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 22942,
"time": 21.353087902069092,
"dport": 5355,
"sport": 49840
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 23262,
"time": 51.51863384246826,
"dport": 5355,
"sport": 50202
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 23582,
"time": 75.48181700706482,
"dport": 5355,
"sport": 50952
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 23902,
"time": 3.0604028701782227,
"dport": 5355,
"sport": 51001
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 24230,
"time": 26.76778793334961,
"dport": 5355,
"sport": 52259
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 24550,
"time": 1.0994529724121094,
"dport": 5355,
"sport": 53595
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 24878,
"time": 3.0721728801727295,
"dport": 5355,
"sport": 53848
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 25206,
"time": 67.58376288414001,
"dport": 5355,
"sport": 54025
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 25526,
"time": 40.885679960250854,
"dport": 5355,
"sport": 54237
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 25846,
"time": 1.621513843536377,
"dport": 5355,
"sport": 54255
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 26174,
"time": 32.015684843063354,
"dport": 5355,
"sport": 54335
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 26494,
"time": -0.04454994201660156,
"dport": 5355,
"sport": 55314
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 26822,
"time": 18.686545848846436,
"dport": 5355,
"sport": 55880
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 27142,
"time": 62.19700789451599,
"dport": 5355,
"sport": 56347
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 27462,
"time": 54.1380410194397,
"dport": 5355,
"sport": 56353
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 27782,
"time": 72.86210989952087,
"dport": 5355,
"sport": 56388
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 28102,
"time": 80.28118896484375,
"dport": 5355,
"sport": 58056
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 28422,
"time": 70.20402193069458,
"dport": 5355,
"sport": 58651
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 28742,
"time": 36.9695508480072,
"dport": 5355,
"sport": 58989
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 29062,
"time": 64.85789394378662,
"dport": 5355,
"sport": 59490
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 29382,
"time": 34.310001850128174,
"dport": 5355,
"sport": 59548
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 29702,
"time": 46.238972902297974,
"dport": 5355,
"sport": 60071
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 30022,
"time": 58.924113035202026,
"dport": 5355,
"sport": 60575
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 30342,
"time": 48.889102935791016,
"dport": 5355,
"sport": 62601
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 30662,
"time": 77.65541005134583,
"dport": 5355,
"sport": 63089
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 30982,
"time": 29.395230054855347,
"dport": 5355,
"sport": 63506
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 31302,
"time": 43.52337884902954,
"dport": 5355,
"sport": 63646
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 31622,
"time": 24.109850883483887,
"dport": 5355,
"sport": 64017
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 31942,
"time": 1.837514877319336,
"dport": 1900,
"sport": 1900
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 51352,
"time": 1.3428828716278076,
"dport": 3702,
"sport": 49152
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 59736,
"time": 3.182492971420288,
"dport": 1900,
"sport": 53598
}
],
"dns_servers": [],
"http": [],
"icmp": [],
"smtp": [],
"tcp": [],
"smtp_ex": [],
"mitm": [],
"hosts": [],
"pcap_sha256": "71fd7cc32ce49b83814ae4736515de2543bfadfea16cdcdfdbfabb6e8fcbd218",
"dns": [],
"http_ex": [],
"domains": [],
"dead_hosts": [],
"sorted_pcap_sha256": "57fc36e0f94245cb89e0c2efdb4b10bc77b5c3642de3f1afcb7f1b5d1fd7ee8c",
"irc": [],
"https_ex": []
}


The instructions below shows how to remove vC36a100r.exe with help from the FreeFixer removal tool. Basically, you install FreeFixer, scan your computer, check the vC36a100r.exe file for removal, restart your computer and scan it again to verify that vC36a100r.exe has been successfully removed. Here are the removal instructions in more detail:
| Property | Value |
|---|---|
| MD5 | 20b50e68c813b2da91cca0cc28f0b9a0 |
| SHA256 | 6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a |
These are some of the error messages that can appear related to vc36a100r.exe:
vc36a100r.exe has encountered a problem and needs to close. We are sorry for the inconvenience.
vc36a100r.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.
vc36a100r.exe has stopped working.
End Program - vc36a100r.exe. This program is not responding.
vc36a100r.exe is not a valid Win32 application.
vc36a100r.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.
To help other users, please let us know what you will do with vC36a100r.exe:
Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.
I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.
No comments posted yet.