What is vC36a100r.exe?

vC36a100r.exe is usually located in the 'c:\Windows\System32\' folder.

Some of the anti-virus scanners at VirusTotal detected vC36a100r.exe.

If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.

Vendor and version information [?]

vC36a100r.exe does not have any version or vendor information.

Digital signatures [?]

vC36a100r.exe is not signed.

VirusTotal report

49 of the 73 anti-virus programs at VirusTotal detected the vC36a100r.exe file. That's a 67% detection rate.

ScannerDetection Name
Acronis suspicious
Ad-Aware Gen:Variant.Johnnie.213038
AegisLab Trojan.Win32.Sdum.4!c
AhnLab-V3 Trojan/Win64.Agent.C3976447
Alibaba Trojan:Win32/amqsu.9bdc5eb4
ALYac Trojan.Agent.gen
Arcabit Trojan.Johnnie.D3402E
Avast Win64:Dropper-gen [Drp]
AVG Win64:Dropper-gen [Drp]
Avira TR/Drop.Agent.amqsu
BitDefender Gen:Variant.Johnnie.213038
CAT-QuickHeal Trojan.Sdum
Comodo ApplicUnwnt@#p664dsmzv3n5
CrowdStrike win/malicious_confidence_60% (W)
Cybereason malicious.0b5056
Cylance Unsafe
Cyren W64/Trojan.WAVL-2610
Emsisoft Gen:Variant.Johnnie.213038 (B)
Endgame malicious (high confidence)
ESET-NOD32 Win64/HackTool.Agent.E potentially unsafe
F-Secure Trojan.TR/Drop.Agent.amqsu
FireEye Generic.mg.20b50e68c813b2da
Fortinet W32/PossibleThreat
GData Gen:Variant.Johnnie.213038
Jiangmin Trojan.Sdum.v
K7AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Kaspersky HEUR:Trojan.Win32.Sdum.gen
MAX malware (ai score=89)
MaxSecure Trojan.Malware.74733560.susgen
McAfee RDN/Generic.dx
McAfee-GW-Edition BehavesLike.Win64.Generic.hc
Microsoft Trojan:Win32/Generic!rfn
MicroWorld-eScan Gen:Variant.Johnnie.213038
Paloalto generic.ml
Panda Trj/RnkBend.A
Qihoo-360 Win32/Trojan.10b
Sangfor Malware
SentinelOne DFI - Malicious PE
Sophos Generic PUA KM (PUA)
Symantec Trojan.Gen.MBT
Tencent Win32.Trojan.Sdum.Hqbt
TrendMicro TROJ_GEN.R002C0PAS20
TrendMicro-HouseCall TROJ_GEN.R002C0PAS20
VBA32 Trojan.Sdum
VIPRE Trojan.Win32.Generic!BT
Webroot W32.Dropper.Gen
Zillya Trojan.Sdum.Win32.132
ZoneAlarm HEUR:Trojan.Win32.Sdum.gen
49 of the 73 anti-virus programs detected the vC36a100r.exe file.

Sandbox Report

The following information was gathered by executing the file inside Cuckoo Sandbox.

Summary

Successfully executed process in sandbox.

Summary

{
    "file_deleted": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp"
    ],
    "file_created": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe"
    ],
    "file_recreated": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
        "\\Device\\KsecDD"
    ],
    "regkey_written": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
        "HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns\\EulaAccepted",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\LanguageList"
    ],
    "dll_loaded": [
        "C:\\Windows\\system32\\bcryptprimitives.dll",
        "imagehlp.dll",
        "kernel32",
        "API-MS-Win-Security-LSALookup-L1-1-0.dll",
        "apphelp.dll",
        "api-ms-win-core-localization-l1-2-1",
        "CFGMGR32.dll",
        "kernel32.dll",
        "credssp.dll",
        "CRYPTBASE.dll",
        "C:\\Windows\\system32\\rsaenh.dll",
        "SensApi.dll",
        "ntdll.dll",
        "cryptsp.dll",
        "api-ms-win-core-synch-l1-2-0",
        "winhttp.dll",
        "ntmarta.dll",
        "bcrypt.dll",
        "API-MS-WIN-Service-Management-L1-1-0.dll",
        "cryptnet.dll",
        "setupapi.dll",
        "C:\\Windows\\System32\\wship6.dll",
        "api-ms-win-appmodel-runtime-l1-1-1",
        "API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
        "API-MS-WIN-Service-winsvc-L1-1-0.dll",
        "ole32.dll",
        "USERENV.dll",
        "CRYPTSP.dll",
        "USER32.dll",
        "C:\\Windows\\system32\\mswsock.dll",
        "API-MS-Win-Security-SDDL-L1-1-0.dll",
        "SspiCli.dll",
        "IPHLPAPI.DLL",
        "C:\\Windows\\system32\\Wintrust.dll",
        "ncrypt.dll",
        "WindowsCodecs.dll",
        "C:\\Windows\\system32\\CRYPT32.dll",
        "NSI.dll",
        "OLEAUT32.dll",
        "profapi.dll",
        "SHELL32.dll",
        "RPCRT4.dll",
        "DNSAPI.dll",
        "C:\\Windows\\System32\\wshtcpip.dll",
        "comctl32.dll",
        "ext-ms-win-kernel32-package-current-l1-1-0",
        "SHLWAPI.dll",
        "API-MS-WIN-Service-Management-L2-1-0.dll",
        "C:\\Windows\\system32\\advapi32.dll",
        "api-ms-win-core-fibers-l1-1-1",
        "WINTRUST.DLL",
        "C:\\Windows\\system32\\cryptnet.dll",
        "PROPSYS.dll",
        "C:\\Windows\\system32\\crypt32.dll",
        "DEVRTL.dll",
        "C:\\Windows\\system32\\Kernel32.dll",
        "ADVAPI32.dll",
        "advapi32",
        "SETUPAPI.dll",
        "WS2_32.dll",
        "Cabinet.dll",
        "WINHTTP.dll"
    ],
    "file_opened": [
        "",
        "C:\\Windows\\SysWOW64",
        "C:\\Windows\\System32\\drivers\\amdk8.sys",
        "C:\\Program Files\\Windows Media Player\\wmpnetwk.exe",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\",
        "c:\\Windows\\SysWOW64\\iedkcs32.dll",
        "C:\\Python27\\python.exe",
        "c:\\program files (x86)\\windows mail\\WinMail.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RegisterSearch",
        "C:\\Windows\\System32\\drivers\\ndisuio.sys",
        "C:\\Windows\\System32\\drivers\\monitor.sys",
        "C:\\Windows\\System32\\drivers\\WUDFPf.sys",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
        "C:\\Windows\\System32\\aepdu.dll",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
        "C:\\Windows\\System32\\drivers\\blbdrive.sys",
        "C:\\Windows\\System32\\clfs.sys",
        "C:\\Windows\\System32\\drivers\\netbios.sys",
        "C:\\Windows\\System32\\en-US\\KERNELBASE.dll.mui",
        "C:\\Windows\\System32\\drivers\\mstee.sys",
        "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\",
        "C:\\Windows\\System32\\drivers\\hidir.sys",
        "c:\\Windows\\SysWOW64\\regsvr32.exe",
        "C:\\Windows\\System32\\drivers\\rasl2tp.sys",
        "C:\\Windows\\System32\\drivers\\srvnet.sys",
        "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
        "C:\\Windows\\System32\\drivers\\asyncmac.sys",
        "C:\\Windows\\System32\\drivers\\flpydisk.sys",
        "C:\\Windows\\System32\\imageres.dll",
        "C:\\Windows\\System32\\drivers\\lsi_sas2.sys",
        "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727",
        "C:\\Windows\\System32\\drivers\\mrxdav.sys",
        "C:\\Windows\\System32\\drivers\\mountmgr.sys",
        "C:\\ProgramData\\Microsoft\\",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
        "C:\\Windows\\System32\\drivers\\rdyboost.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MobilePC\\HotStart",
        "C:\\Windows\\System32\\drivers\\wacompen.sys",
        "C:\\Users\\cuck\\Searches\\desktop.ini",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MUI\\LPRemove",
        "C:\\Windows\\System32\\catroot",
        "C:\\Windows\\System32\\drivers\\circlass.sys",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\",
        "C:\\Windows\\System32\\drivers\\CompositeBus.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
        "C:\\Windows\\System32\\drivers\\fdc.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SystemRestore\\SR",
        "C:\\Windows\\System32\\drivers\\bthmodem.sys",
        "C:\\Windows\\System32\\drivers\\compbatt.sys",
        "C:\\Windows\\System32\\drivers\\RDPCDD.sys",
        "C:\\Windows\\System32\\drivers\\filetrace.sys",
        "C:\\Windows\\System32\\mctadmin.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
        "C:\\Windows\\System32\\rsaenh.dll",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Location\\Notifications",
        "C:\\Windows\\System32\\drivers\\BrUsbSer.sys",
        "C:\\Windows\\System32\\drivers\\vdrvroot.sys",
        "C:\\Windows\\System32\\drivers\\stexstor.sys",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CRLs\\",
        "C:\\Windows\\System32\\drivers\\BrFiltUp.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
        "C:\\Windows\\System32\\drivers\\mshidkmdf.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\AitAgent",
        "C:\\Users\\cuck\\AppData\\LocalLow",
        "C:\\Windows\\System32\\drivers\\umbus.sys",
        "C:\\Windows\\System32\\drivers\\HpSAMD.sys",
        "C:\\Windows\\System32\\drivers\\E1G6032E.sys",
        "C:\\Windows\\System32\\drivers\\msdsm.sys",
        "C:\\Windows\\System32\\drivers\\lltdio.sys",
        "C:\\Windows\\System32\\drivers\\vhdmp.sys",
        "C:\\Windows\\System32\\drivers\\usbuhci.sys",
        "C:\\Windows\\System32\\drivers\\pciide.sys",
        "C:\\Windows\\System32\\dwm.exe",
        "C:\\Windows\\System32\\drivers\\fltMgr.sys",
        "C:\\Windows\\System32\\drivers\\rassstp.sys",
        "C:\\Users\\cuck\\Links\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\IPMIDrv.sys",
        "C:\\Windows\\System32\\raserver.exe",
        "C:\\Windows\\SysWOW64\\ie4uinit.exe",
        "C:\\Windows\\System32\\drivers\\ndis.sys",
        "C:\\tmpyzbctd\\",
        "C:\\Windows\\System32\\drivers\\tunnel.sys",
        "C:\\Windows\\System32\\drivers\\hwpolicy.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
        "C:\\Windows\\System32\\drivers\\sisraid4.sys",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Ras\\MobilityManager",
        "C:\\Windows\\System32\\drivers\\ndiscap.sys",
        "C:\\Program Files\\Windows Media Player\\",
        "c:\\Windows\\System32\\cmd.exe",
        "C:\\Windows\\System32\\drivers\\umpass.sys",
        "C:\\Users\\cuck\\AppData",
        "C:\\Windows\\System32\\drivers\\bowser.sys",
        "C:\\Windows\\System32\\drivers\\partmgr.sys",
        "C:\\Windows\\System32\\drivers\\iaStorV.sys",
        "C:\\Windows\\System32\\drivers\\usbccgp.sys",
        "C:\\Windows\\System32\\cmd.exe",
        "C:\\Windows\\System32\\drivers\\sffp_sd.sys",
        "C:\\Windows\\Microsoft.NET\\Framework",
        "C:\\Windows\\System32\\drivers\\volsnap.sys",
        "C:\\Windows\\ehome\\mcupdate.exe",
        "C:\\Windows\\System32\\drivers\\mpsdrv.sys",
        "C:\\Windows\\System32\\drivers\\wmiacpi.sys",
        "C:\\Windows\\System32\\drivers\\MegaSR.sys",
        "C:\\Windows\\System32\\drivers\\adpu320.sys",
        "C:\\Windows\\SysWOW64\\unregmp2.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Task Manager\\Interactive",
        "C:\\Windows\\System32\\drivers\\cdrom.sys",
        "c:\\Windows\\System32\\regsvr32.exe",
        "C:\\Windows\\System32\\drivers\\BrFiltLo.sys",
        "C:\\Users\\cuck\\AppData\\Local\\",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
        "C:\\Windows\\System32\\drivers\\pcw.sys",
        "C:\\Windows\\System32\\Defrag.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Registry\\RegIdleBackup",
        "C:\\Windows\\System32\\drivers\\megasas.sys",
        "C:\\Windows\\System32\\drivers\\modem.sys",
        "C:\\Windows\\System32\\unregmp2.exe",
        "C:\\Windows\\System32\\drivers\\adp94xx.sys",
        "C:\\Windows\\System32\\drivers\\iirsp.sys",
        "C:\\Windows\\System32\\userinit.exe",
        "C:\\Windows\\System32\\drivers\\rspndr.sys",
        "C:\\Windows\\System32\\drivers\\hdaudbus.sys",
        "C:\\Windows\\System32\\drivers\\vga.sys",
        "C:\\",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
        "C:\\Windows\\System32\\drivers\\wanarp.sys",
        "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe",
        "C:\\Windows\\System32\\drivers\\dmvsc.sys",
        "C:\\Windows\\System32\\drivers\\FsDepends.sys",
        "C:\\Windows\\System32\\EhStorShell.dll",
        "C:\\Windows\\System32\\conhost.exe",
        "c:\\Windows\\System32\\rundll32.exe",
        "C:\\Windows\\System32\\drivers\\sisraid2.sys",
        "C:\\Windows\\System32\\appidpolicyconverter.exe",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
        "C:\\Windows\\System32\\drivers\\ULIAGPKX.SYS",
        "c:\\Windows\\SysWOW64\\ie4uinit.exe",
        "C:\\Windows\\System32\\drivers\\rasacd.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Maintenance\\WinSAT",
        "C:\\Windows\\System32\\drivers\\hcw85cir.sys",
        "c:\\Windows\\System32\\iconcodecservice.dll",
        "C:\\Windows\\System32\\drivers\\VMBusHID.sys",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db",
        "C:\\Windows\\System32\\drivers\\intelide.sys",
        "C:\\Windows\\ehome",
        "C:\\Users\\cuck\\Favorites\\desktop.ini",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RAC\\RacTask",
        "C:\\Windows\\System32\\drivers\\vmstorfl.sys",
        "C:\\Windows\\System32\\drivers\\ipfltdrv.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
        "C:\\Windows\\System32\\drivers\\HdAudio.sys",
        "C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe",
        "c:\\Windows\\SysWOW64\\mscories.dll",
        "C:\\Windows\\System32\\drivers\\srv.sys",
        "C:\\Windows\\System32\\drivers\\msiscsi.sys",
        "C:\\Windows\\System32\\drivers\\CmBatt.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
        "C:\\Windows\\System32\\drivers\\bxvbda.sys",
        "C:\\Windows\\System32\\drivers\\vwifibus.sys",
        "C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\ntexe.cat",
        "C:\\Windows\\System32\\drivers\\drmkaud.sys",
        "C:\\Windows\\System32\\drivers\\fvevol.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
        "C:\\Windows\\System32\\ndfapi.dll",
        "C:\\Windows\\Microsoft.Net\\Framework64\\v3.0\\",
        "C:\\Windows\\System32\\drivers\\ksthunk.sys",
        "C:\\Windows\\System32\\drivers\\ipnat.sys",
        "C:\\Windows\\System32\\drivers\\kbdhid.sys",
        "C:\\Windows\\System32\\alg.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
        "C:\\Windows\\System32\\drivers\\disk.sys",
        "C:\\Program Files (x86)",
        "C:\\Windows\\System32\\lpremove.exe",
        "C:\\Windows\\System32\\lsass.exe",
        "C:\\Windows\\System32\\drivers\\kbdclass.sys",
        "C:\\Windows\\System32\\ntshrui.dll",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
        "C:\\Windows\\System32\\drivers\\smb.sys",
        "C:\\Windows\\System32\\drivers\\isapnp.sys",
        "C:\\Windows\\System32\\drivers\\amdsbs.sys",
        "C:\\Windows\\System32\\lsm.exe",
        "C:\\Windows",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Autochk\\Proxy",
        "C:\\Windows\\System32\\drivers\\usbcir.sys",
        "C:\\Windows\\System32\\drivers\\vmbus.sys",
        "C:\\Windows\\System32\\drivers\\tdpipe.sys",
        "C:\\Windows\\System32\\drivers\\appid.sys",
        "C:\\Windows\\System32\\drivers\\cng.sys",
        "c:\\Windows\\System32\\userinit.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
        "C:\\Windows\\System32\\drivers\\afd.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
        "C:\\Users\\cuck\\Videos\\desktop.ini",
        "C:\\Program Files\\Windows Mail",
        "C:\\Windows\\System32\\drivers\\tcpip.sys",
        "C:\\Windows\\System32\\services.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
        "C:\\Users\\cuck\\Documents\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\BrSerWdm.sys",
        "C:\\Windows\\System32\\drivers\\ndiswan.sys",
        "C:\\Users\\cuck\\Contacts\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\serial.sys",
        "C:\\Users\\cuck",
        "C:\\Windows\\System32\\drivers\\lsi_sas.sys",
        "C:\\Windows\\System32\\DFDWiz.exe",
        "C:\\Windows\\System32\\drivers\\dxgkrnl.sys",
        "C:\\Windows\\System32\\dfdts.dll",
        "C:\\Windows\\System32\\drivers\\nvstor.sys",
        "C:\\Windows\\System32\\LocationNotifications.exe",
        "C:\\Windows\\System32\\FXSSVC.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
        "C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat",
        "C:\\Program Files (x86)\\Windows Mail",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WDI\\ResolutionHost",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ehDRMInit",
        "C:\\Windows\\SysWOW64\\regsvr32.exe",
        "C:\\Windows\\System32\\drivers\\csc.sys",
        "C:\\Windows\\System32\\drivers\\i8042prt.sys",
        "C:\\Windows\\System32\\gatherNetworkInfo.vbs",
        "C:\\Windows\\System32\\drivers\\parport.sys",
        "C:\\Windows\\System32\\drivers\\nfrd960.sys",
        "C:\\Windows\\System32\\drivers\\msahci.sys",
        "C:\\Program Files\\Windows Media Player\\wmpnscfg.exe",
        "C:\\Windows\\System32\\winlogon.exe",
        "C:\\Windows\\System32\\drivers\\sfloppy.sys",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
        "C:\\Windows\\System32\\drivers\\RDPENCDD.sys",
        "C:\\Windows\\System32\\drivers\\nwifi.sys",
        "C:\\Windows\\System32\\drivers\\ws2ifsl.sys",
        "C:\\Windows\\System32\\drivers\\PEAuth.sys",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
        "C:\\Windows\\System32\\drivers\\NV_AGP.SYS",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
        "C:\\Windows\\System32\\drivers\\rdpdr.sys",
        "C:\\Users\\cuck\\Pictures\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\elxstor.sys",
        "C:\\Windows\\System32\\drivers\\hidusb.sys",
        "C:\\Windows\\System32\\drivers\\ql40xx.sys",
        "c:\\Windows\\System32\\ie4uinit.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft",
        "C:\\Windows\\System32\\",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
        "C:\\Windows\\System32\\drivers\\amdxata.sys",
        "C:\\ProgramData",
        "C:\\Windows\\System32\\drivers\\usbhub.sys",
        "C:\\Windows\\System32\\wininit.exe",
        "C:\\Windows\\System32\\drivers\\vms3cap.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
        "C:\\Windows\\SysWOW64\\en-US\\unregmp2.exe.mui",
        "C:\\Windows\\System32\\drivers\\nsiproxy.sys",
        "C:\\Windows\\System32\\drivers\\mup.sys",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
        "C:\\Windows\\SysWOW64\\",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\Certificates\\",
        "C:\\Windows\\System32\\BFE.DLL",
        "C:\\Windows\\explorer.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
        "C:\\Windows\\System32\\drivers\\netbt.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
        "C:\\Windows\\System32\\drivers\\atapi.sys",
        "C:\\Windows\\System32\\drivers\\storvsc.sys",
        "C:\\Program Files\\Windows Mail\\WinMail.exe",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs",
        "C:\\Windows\\System32\\drivers\\fileinfo.sys",
        "C:\\Windows\\System32\\drivers\\wd.sys",
        "C:\\Windows\\System32\\drivers\\RDPREFMP.sys",
        "C:\\Windows\\System32\\drivers\\pacer.sys",
        "C:\\Windows\\System32\\drivers\\dfsc.sys",
        "C:\\Windows\\System32\\drivers\\mrxsmb10.sys",
        "c:\\program files\\windows mail\\WinMail.exe",
        "C:\\Windows\\System32\\drivers\\mrxsmb20.sys",
        "C:\\Windows\\System32\\appidcertstorecheck.exe",
        "C:\\Windows\\System32\\drivers\\pci.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
        "C:\\Windows\\Microsoft.NET\\Framework64\\",
        "C:\\Windows\\Microsoft.NET",
        "C:\\Users\\cuck\\AppData\\Roaming",
        "C:\\Windows\\System32\\drivers\\b57nd60a.sys",
        "C:\\Windows\\System32\\drivers\\wimmount.sys",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
        "C:\\Program Files (x86)\\Windows Mail\\",
        "C:\\Windows\\System32\\drivers\\TsUsbFlt.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
        "C:\\Program Files",
        "C:\\Windows\\System32\\drivers\\acpi.sys",
        "C:\\Windows\\System32\\drivers\\udfs.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\AutoWake",
        "C:\\Windows\\System32\\drivers\\raspppoe.sys",
        "C:\\Users\\cuck\\Saved Games\\desktop.ini",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
        "C:\\Windows\\System32\\drivers\\hidbth.sys",
        "c:\\Windows\\SysWOW64\\rundll32.exe",
        "C:\\Windows\\System32\\drivers\\irenum.sys",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
        "C:\\Windows\\System32\\drivers\\srv2.sys",
        "C:\\Windows\\System32\\SearchIndexer.exe",
        "C:\\Windows\\System32\\drivers\\serenum.sys",
        "C:\\Windows\\System32\\drivers\\intelppm.sys",
        "C:\\ProgramData\\Microsoft\\Windows",
        "C:\\Windows\\System32\\drivers\\mskssrv.sys",
        "C:\\Windows\\System32\\drivers\\mssmbios.sys",
        "C:\\Windows\\System32\\drivers\\BrSerId.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
        "C:\\Users\\",
        "c:\\Windows\\explorer.exe",
        "C:\\Windows\\System32\\drivers\\agilevpn.sys",
        "C:\\Users",
        "C:\\Windows\\System32\\drivers\\usbohci.sys",
        "C:\\Windows\\System32\\drivers\\vsmraid.sys",
        "C:\\Program Files (x86)\\Windows Mail\\WinMail.exe",
        "C:\\Windows\\System32\\catroot2\\",
        "C:\\Windows\\System32\\drivers\\amdppm.sys",
        "C:\\Windows\\System32\\drivers\\pcmcia.sys",
        "C:\\Windows\\System32\\svchost.exe",
        "C:\\Users\\cuck\\",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
        "C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\WPF",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SessionAgent",
        "C:\\Windows\\System32\\drivers\\mspqm.sys",
        "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\",
        "C:\\Windows\\System32\\drivers\\msisadrv.sys",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs",
        "C:\\Windows\\System32\\catroot2",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
        "C:\\Windows\\Microsoft.NET\\Framework64\\v3.0",
        "C:\\Users\\cuck\\AppData\\",
        "C:\\Windows\\System32\\drivers\\nvraid.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
        "c:\\Windows\\System32\\unregmp2.exe",
        "C:\\Windows\\ehome\\ehPrivJob.exe",
        "C:\\Windows\\System32",
        "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727",
        "C:\\Windows\\System32\\regsvr32.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
        "C:\\Windows\\System32\\drivers\\mouclass.sys",
        "C:\\Windows\\System32\\drivers\\vgapnp.sys",
        "C:\\Windows\\System32\\ie4uinit.exe",
        "C:\\Windows\\System32\\drivers\\volmgrx.sys",
        "C:\\Windows\\System32\\drivers\\arcsas.sys",
        "C:\\Windows\\System32\\drivers\\amdide.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
        "C:\\Windows\\System32\\powercfg.exe",
        "C:\\Windows\\System32\\drivers\\termdd.sys",
        "C:\\Program Files\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\swenum.sys",
        "C:\\Windows\\System32\\taskhost.exe",
        "C:\\Windows\\System32\\drivers\\luafv.sys",
        "C:\\Windows\\System32\\drivers\\tdx.sys",
        "C:\\Windows\\System32\\drivers\\cmdide.sys",
        "C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\infocard.exe",
        "C:\\Windows\\System32\\drivers\\sbp2port.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\PolicyConverter",
        "C:\\Windows\\System32\\drivers\\hidbatt.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
        "C:\\Windows\\System32\\drivers\\lsi_fc.sys",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
        "C:\\Windows\\System32\\drivers\\ksecpkg.sys",
        "C:\\Windows\\System32\\drivers\\USBSTOR.SYS",
        "C:\\Windows\\ehome\\",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURActivate",
        "C:\\Users\\cuck\\Music\\desktop.ini",
        "C:\\Windows\\System32\\SystemPropertiesPerformance.exe",
        "C:\\Windows\\ehome\\ehrecvr.exe",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
        "C:\\Windows\\System32\\drivers\\tssecsrv.sys",
        "C:\\Windows\\System32\\en-US\\WINHTTP.dll.mui",
        "C:\\Windows\\Microsoft.Net\\Framework64\\",
        "C:\\Windows\\System32\\drivers\\ndistapi.sys",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Diagnosis\\Scheduled",
        "C:\\Windows\\System32\\drivers\\Wdf01000.sys",
        "C:\\Windows\\System32\\drivers\\discache.sys",
        "C:\\Users\\cuck\\Desktop\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\usbprint.sys",
        "C:\\Windows\\System32\\drivers\\rdbss.sys",
        "C:\\Windows\\System32\\drivers\\errdev.sys",
        "C:\\Windows\\System32\\drivers\\processr.sys",
        "C:\\Windows\\System32\\dllhost.exe",
        "C:\\Windows\\System32\\drivers\\rdpbus.sys",
        "C:\\Windows\\System32\\sc.exe",
        "C:\\Windows\\System32\\drivers\\mspclock.sys",
        "C:\\Windows\\System32\\drivers\\aliide.sys",
        "C:\\Windows\\System32\\drivers\\mpio.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
        "C:\\Windows\\System32\\drivers\\evbda.sys",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\mcupdate",
        "C:\\Users\\cuck\\Downloads\\desktop.ini",
        "C:\\Program Files\\Windows Mail\\",
        "c:\\Windows\\System32\\systempropertiesperformance.exe",
        "C:\\Windows\\System32\\wermgr.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\",
        "C:\\Windows\\System32\\drivers\\ql2300.sys",
        "C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation",
        "C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\",
        "C:\\Windows\\System32\\drivers\\TsUsbGD.sys",
        "C:\\Windows\\System32\\drivers\\tdtcp.sys",
        "C:\\Windows\\System32\\drivers\\acpipmi.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\UAGP35.SYS",
        "C:\\Windows\\System32\\drivers\\adpahci.sys",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu",
        "C:\\Windows\\System32\\drivers\\sffdisk.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
        "C:\\Windows\\System32\\notepad.exe",
        "C:\\Windows\\System32\\drivers\\arc.sys",
        "C:\\Windows\\System32\\rdpclip.exe",
        "C:\\Program Files (x86)\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\ohci1394.sys",
        "C:\\Windows\\Microsoft.NET\\Framework64",
        "C:\\Windows\\System32\\drivers\\wfplwf.sys",
        "C:\\Python27\\",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RecordingRestart",
        "C:\\Windows\\System32\\drivers\\volmgr.sys",
        "\\Device\\NamedPipe\\",
        "C:\\Windows\\System32\\drivers\\cdfs.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
        "C:\\Windows\\System32\\drivers\\GAGP30KX.SYS",
        "c:\\Windows\\System32\\imageres.dll",
        "C:\\Windows\\ehome\\ehsched.exe",
        "C:\\Windows\\System32\\csrss.exe",
        "c:\\program files\\windows defender\\MpCmdRun.exe",
        "C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\WPF\\PresentationFontCache.exe",
        "C:\\Windows\\System32\\drivers\\1394ohci.sys",
        "C:\\Windows\\System32\\shdocvw.dll",
        "C:\\Windows\\System32\\drivers\\ksecdd.sys",
        "C:\\Windows\\System32\\drivers\\usbehci.sys",
        "C:\\Users\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\amdsata.sys",
        "c:\\Windows\\System32\\rdpclip.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\GadgetManager",
        "C:\\Windows\\System32\\drivers\\MTConfig.sys",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\crcdisk.sys",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\",
        "C:\\Windows\\System32\\drivers\\mouhid.sys",
        "C:\\Windows\\System32\\drivers\\BrUsbMdm.sys",
        "C:\\Windows\\System32\\drivers\\lsi_scsi.sys",
        "c:\\Windows\\System32\\iedkcs32.dll",
        "C:\\Windows\\System32\\drivers\\sermouse.sys",
        "C:\\Windows\\System32\\spoolsv.exe",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CTLs\\",
        "C:\\Windows\\System32\\drivers\\scfilter.sys",
        "C:\\Windows\\System32\\sdclt.exe",
        "C:\\Windows\\System32\\en-US\\unregmp2.exe.mui",
        "C:\\Windows\\System32\\cscui.dll",
        "C:\\Windows\\",
        "C:\\Windows\\System32\\drivers\\http.sys",
        "C:\\Windows\\System32\\drivers\\raspptp.sys",
        "C:\\ProgramData\\Microsoft",
        "C:\\Windows\\System32\\drivers\\viaide.sys",
        "C:\\Windows\\System32\\drivers\\tcpipreg.sys",
        "C:\\Windows\\System32\\drivers\\qwavedrv.sys",
        "C:\\Windows\\System32\\drivers\\mrxsmb.sys",
        "C:\\Windows\\System32\\drivers\\AGP440.sys",
        "C:\\Windows\\System32\\wsqmcons.exe",
        "c:\\Windows\\SysWOW64\\unregmp2.exe",
        "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe",
        "c:\\Windows\\System32\\mscories.dll",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
        "C:\\Windows\\System32\\drivers\\sffp_mmc.sys"
    ],
    "regkey_opened": [
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\isapnp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Modem",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srvnet\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06308A56-69E7-4844-A784-8509C25B6C62}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Filetrace\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CC35D2E9-B9E1-4ADC-9DA5-71487D9E9EB5}",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VaultSvc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lmhosts",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4DE0CAB9-ECFE-4AA9-B95A-FE815A2EAA4E}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FltMgr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_32\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBth",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcLocator",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wdf01000\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehSched\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDProxy\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iaStorV",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D0250F3F-6480-484F-B719-42F659AC64D5}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Schedule",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPDR",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vga\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MegaSR",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\discache",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2470470F-2634-478E-B181-571E98A789BB}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vds",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WbioSrvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbcir\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BDESVC\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache3.0.0.0\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WMPNetworkSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDPIPE",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rspndr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WIMMount\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mshidkmdf\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1BB08CFD-C6AD-44C7-BD0B-8F23035A5731}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BDESVC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProfSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouhid\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B81A55E6-C03C-4EF0-B86F-A80A89DF468D}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Npfs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbFlt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppuinotify\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\1394ohci",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EventSystem",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stexstor\\Parameters",
        "HKEY_CURRENT_USER\\Software\\Classes\\htmlfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAgileVpn",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CompositeBus\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVE",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NlaSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nv_agp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{3307E641-F5EE-49E6-A1FE-BFB5D671441C}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\monitor",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinDefend",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidUsb\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Processor\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgrx\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Schedule\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IKEEXT",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A656BBE1-4E3E-4C8A-BD79-A8CA56782753}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection\\NAPStatus UI",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdK8\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{87F56B34-044E-4A48-8FDD-087BFABD5ECF}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UxSms\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltUp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\drmkaud",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fvevol",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CscService\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MRxDAV\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\s3cap\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ACPI",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\viaide",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\i8042prt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{00BB5F5C-4A20-4FD6-8900-4699F989BF01}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\discache\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanServer",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid2\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\exfat",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbohci",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Power",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mountmgr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\CrawlStartPages",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4D19A151-A712-4920-AC6D-6C6FD81C8CDB}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteRegistry",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wercplsupport\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BFE\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPNAT\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storflt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A132EB1D-A1EA-48EF-8B69-9358EADF5BD3}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql2300",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swenum",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\E1G60\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpahci\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcLocator\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DPS",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msahci\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SessionEnv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serial",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanWorkstation",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netman\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NativeWifiP\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdxata",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelppm\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tunnel\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SSDPSRV",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C4375D81-FA72-45AC-85F2-3B86A11CCC7D}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RacTask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbSer\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4FDEA3B5-7CDE-48F7-940C-43CDBB18FB20}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wd\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nv_agp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmRdpService\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tdx\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Browser",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ohci1394",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPCDD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msisadrv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS2\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBatt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\isapnp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermDD\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KtmRm",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetTcpPortSharing\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FltMgr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fastfat",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\drmkaud\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\mcupdate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hkmsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iphlpsvc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_sd",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{82676C49-21A7-4605-AA06-E04A067FB611}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sfloppy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURActivate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\megasas",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Appinfo",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TapiSrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\defragsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrSerWdm\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdpbus\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDIS",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{600F3312-A477-448A-936D-EB2DF977300B}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVEdrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAcd",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbehci",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sermouse\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dmvsc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPCSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Brserid\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_FC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wcncsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SessionEnv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sfloppy\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BITS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsata",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSDTC\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PolicyAgent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RACAgent",
        "HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TBS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbMdm\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wbengine\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupProvider\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5F5A18EB-DC73-4E45-A11C-B59043598412}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiSystemHost\\Parameters",
        "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinRM\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HpSAMD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbSer",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbFlt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cmdide",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BTHMODEM\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\udfs\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\THREADORDER\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ohci1394\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\MemUsageTask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinHttpAutoProxySvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPAutoReg\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance\\WinSAT",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AFD",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCardSvr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupProvider",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WbioSrvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupListener",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CertPropSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidIr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrkWks",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volsnap\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SysMain",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\secdrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\scfilter\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arcsas\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\viaide\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecDD",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hidserv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DcomLaunch\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Beep",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSTEE",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CLFS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\atapi\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pciide",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WANARP\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lmhosts\\Parameters",
        "HKEY_USERS\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdio",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vsmraid",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSTEE\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpu320",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdclass\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdpbus",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcSs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adp94xx",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CmBatt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppIDSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PeerDistSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Fax\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tssecsrv",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2E941CB2-1B33-47C4-905B-8B4278819513}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpu320\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AsyncMac\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NlaSvc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9979CB83-103A-4105-9E5D-C74B0AF6D198}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPCLOCK\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdbss",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RegisterSearch",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdPHost",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioSrv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wcncsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Tcpip\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Rasl2tp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wbengine",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB07F7B4-BB95-4B74-9D32-4533D566453C}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rspndr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hidserv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\napagent\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CmBatt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PptpMiniport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2pimsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAuto\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dhcp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsbs\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcEptMapper",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouclass",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SCSI\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPWD\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CD962721-73F1-4649-85D7-6884C1EF28D9}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gagp30kx\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PcaSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\napagent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BTHMODEM",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ndisuio",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBth\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ehDRMInit",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDTCP\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinDefend\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Brserid",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis\\Scheduled",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wanarpv6",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdyboost\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netlogon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UI0Detect",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FDResPub",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KeyIso",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Themes\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HpSAMD\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcEptMapper\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bowser\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E3163C33-301D-4730-A266-5518C5ED3967}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nfrd960",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Psched",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVEdrv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WcsPlugInService",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
        "HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBT",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HTTP",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tdx",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cmdide\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBIOS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermService\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CryptSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PcaSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdhid",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcw\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CertPropSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wudfsvc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{96137355-BC34-4BA7-81B7-47C87B556E7D}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WcsPlugInService\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\blbdrive\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pciide\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wuauserv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasPppoe\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swprv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SensrSvc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}",
        "HKEY_CURRENT_USER\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
        "HKEY_CURRENT_USER\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbhub\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wercplsupport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\flpydisk\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkCards\\12",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stisvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netlogon\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SNMPTRAP\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouhid",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\upnphost\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nfrd960\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MMCSS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HTTP\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hwpolicy\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VgaSave",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IRENUM\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sbp2port\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tcpipreg",
        "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ws2ifsl",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioSrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiServiceHost\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2psvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcSs\\Parameters",
        "HKEY_LOCAL_MACHINE\\Software\\Sysinternals",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ebdrv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisCap",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\W32Time",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{8C5ED038-CFAD-48A0-BB2F-D128286E49B3}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\atapi",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Power\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\E1G60",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPREFMP",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_sd\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvraid",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_64",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ntfs\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vwifibus",
        "HKEY_CURRENT_USER\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pla\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPENCDD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AxInstSV\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAgileVpn\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ALG\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b06bdrv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VaultSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql2300\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Msfs\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sermouse",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanServer\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\i8042prt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NativeWifiP",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdK8",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\PolicyConverter",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storflt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SstpSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wlansvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrustedInstaller\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC668097-4D6B-4093-AC14-014C09DBF820}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpsdrv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPDBusEnum",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PerfHost\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\udfs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BE669C13-8165-4536-96D0-6D6C39292AAE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{613612BA-897D-44CE-8DC1-8FC283F9FD51}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WebClient",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{448186F9-75B9-4FB7-A6E0-B19A2BADC1BE}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MRxDAV",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hkmsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Null\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AsyncMac",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpio\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbGD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CNG",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mcx2Svc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdide\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tssecsrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CompositeBus",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\agp440\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermService",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9435F817-FED2-454E-88CD-7F78FDA62C48}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vmbus",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{268014E7-A27E-4FD7-89A6-A481DA222EC8}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BFE",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Tcpip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WudfPf\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdbss\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouclass\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iScsiPrt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmRdpService",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SDRSVC\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinRM",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DXGKrnl\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stisvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPBusEnum\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tunnel",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbuhci\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPDR\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06CD2154-751E-469F-8E4A-C3F118356423}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WSearch\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DcomLaunch",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hcw85cir",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehSched",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EventSystem\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\THREADORDER",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AxInstSV",
        "HKEY_USERS\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vdrvroot\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Psched\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FileInfo",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WMPNetworkSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAcd\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PptpMiniport\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Parport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbohci\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisWan\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermDD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DXGKrnl",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uagp35",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WerSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Disk",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSiSCSI",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PEAUTH\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serenum\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storvsc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteAccess\\Parameters",
        "HKEY_USERS\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDIS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VSS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdide",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\AitAgent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5A40E926-9E86-4B89-9CFD-B12311724371}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{72DB7465-BC54-491B-A92A-4637A28C9BBF}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbGD\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SstpSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvstor\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache3.0.0.0",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\USBSTOR",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MsRPC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_mmc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\umbus",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecDD\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppID\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\flpydisk",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wecsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PolicyAgent\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stexstor",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2psvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\netprofm\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AcpiPmi\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\umbus\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WmiAcpi\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\elxstor\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_mmc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swenum\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ErrDev",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F18ED8A5-C696-4951-B068-CA8E83634C04}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{17F5B0DE-8DA9-4280-8CB8-91422B9A8CE1}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSDTC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\partmgr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MozillaMaintenance\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPREFMP\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv2",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\elxstor",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore\\SR",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iScsiPrt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MozillaMaintenance",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vdrvroot",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dnscache\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MMCSS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TCPIP6\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager\\Interactive",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adp94xx\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gpsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wmiApSrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProtectedStorage",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VgaSave\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b57nd60a",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CLFS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ndisuio\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wscsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB02381F-D652-4B1C-894A-712498C62C51}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dmvsc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsata\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b57nd60a\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FDResPub\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CSC\\Parameters",
        "HKEY_CURRENT_USER\\SOFTWARE\\Classes\\exefile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Rasl2tp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hcw85cir\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A48CABBF-24C8-4B87-B00F-9261807C3B43}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\scfilter",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mountmgr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\OptinNotification",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ws2ifsl\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WIMMount",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storvsc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPQM\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Filetrace",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SENS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\partmgr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serenum",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TBS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteAccess",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisWan",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fastfat\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WSearch",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql40xx",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EFS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ebdrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\secdrv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vsmraid\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb20\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ksthunk\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D018DE2F-F02A-4BDB-BA74-56BCD427BE40}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MsRPC\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SysMain\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffdisk",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Smb\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Smb",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecPkg",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdio\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Winmgmt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CDA5F4EE-8293-4A5D-8564-04CD067D1A85}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arcsas",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0004",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0007",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0006",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0001",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0000",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0003",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0002",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid4",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SamSs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0009",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0008",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VMBusHID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb20",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0005",
        "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\idsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI\\ResolutionHost",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpsdrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SENS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dnscache",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wudfsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\eventlog",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SamSs\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb10",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DfsC\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS2",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Compbatt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FB3C354D-297A-4EB2-9B58-090F6361906B}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wuauserv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\COMSysApp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wdf01000",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iirsp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TCPIP6",
        "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gpsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbccgp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpahci",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDTCP",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\crcdisk\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mup\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\aliide",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\1394ohci\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetTcpPortSharing",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{551B3807-871F-4E48-A943-2330449F0615}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPNAT",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCPolicySvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCPolicySvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdrom\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\USBSTOR\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5BE46CE1-CA9B-4CAD-B2E9-8C3F7716AF90}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WANARP",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisCap\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SessionAgent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\spldr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry\\RegIdleBackup",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmPass",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Beep\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pci\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ErrDev\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppIDSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\aliide\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupListener\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltLo",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uliagpkx\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msdsm",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SharedAccess\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RecordingRestart",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AeLookupSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Browser\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\netprofm",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdPHost\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcmcia\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SNMPTRAP",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\megasas\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CryptSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\luafv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\luafv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DfsC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbprint\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Modem\\Parameters",
        "HKEY_USERS\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msahci",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netman",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Winmgmt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EFS",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A8B18D02-60CD-4305-90CC-7DAAC028BDCD}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdhid\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CNG\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_FC\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsi",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UI0Detect\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KtmRm\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPCLOCK",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv2\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\COMSysApp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdrom",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ALG",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisTapi\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MpsSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\blbdrive",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltUp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HDAudBus",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\GadgetManager",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid4\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelide",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ACPI\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IKEEXT\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\seclogon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pla",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bthserv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProtectedStorage\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinHttpAutoProxySvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppMgmt\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehRecvr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AeLookupSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bthserv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pci",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBT\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System\\ConvertLogEntries",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPAutoReg",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DPS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasSstp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcw",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmPass\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PEAUTH",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TabletInputService",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehRecvr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Spooler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcmcia",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbehci\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft",
        "HKEY_USERS\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidUsb",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk\\Proxy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSiSCSI\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsbs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MpsSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BITS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrustedInstaller",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VSS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B43033E6-1453-4AD6-AFBA-C03CFC178286}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteRegistry\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B78DBF96-841E-4336-BFE9-1C4975F9DA60}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelppm",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid2",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Spooler\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gagp30kx",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasMan",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelide\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bowser",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPDBusEnum\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MpIdleTask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WacomPen",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_64\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dot3svc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wd",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\agp440",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WmiAcpi",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{874CFED9-D01D-4D16-9775-B8A7A05004BF}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msiserver\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serial\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\defragsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecPkg\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FsDepends",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\monitor\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPWD",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgrx",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IpFilterDriver",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb10\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location\\Notifications",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MTConfig",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPCSvc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MegaSR\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PerfHost",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srvnet",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7F9C951C-D364-4B70-8D07-D2C9B7F76E35}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Null",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\s3cap",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPCDD\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC\\HotStart",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vga",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPMIDRV",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hwpolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EapHost",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\AutoWake",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsiproxy\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Npfs\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dhcp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\StorSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\upnphost",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volsnap",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\StorSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vmbus\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wlansvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CSC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0010",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0011",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A7C73732-9F11-4281-8D19-764D4EC9D94D}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7DC691A2-CB15-44DB-853C-19938051BB22}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ntfs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wanarpv6\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SSDPSRV\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{994C86AD-A929-4B2C-88A0-4E25A107A029}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VMBusHID\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSKSSRV",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrSerWdm",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBatt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WebClient\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-32-544",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCardSvr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbuhci",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mshidkmdf",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SDRSVC",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KeyIso\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasPppoe",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_32",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPQM",
        "HKEY_LOCAL_MACHINE\\Software\\Classes\\htmlfile\\shell\\open\\command",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdPPM",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\idsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\spldr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras\\MobilityManager",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbprint",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FsDepends\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioEndpointBuilder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanWorkstation\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msisadrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDPIPE\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ShellHWDetection",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbhub",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbcir",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uliagpkx",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsi\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vwifibus\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EapHost\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iphlpsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vds\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbccgp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WfpLwf\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MTConfig\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tcpipreg\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AFD\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{28011108-68DF-4C73-B91B-57427D501BBA}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sbp2port",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdfs\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\exfat\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpio",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiServiceHost",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WfpLwf",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WwanSvc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasMan\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Appinfo\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iaStorV\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fvevol\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WudfPf",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dot3svc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WerSvc",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI\\LPRemove",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiSystemHost",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2pimsvc\\Parameters",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AcpiPmi",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PlugPlay\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HdAudAddService\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkCards",
        "HKEY_CURRENT_USER\\Software\\Sysinternals",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PeerDistSvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsiproxy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppMgmt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HDAudBus\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b06bdrv\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FileInfo\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPMIDRV\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Fax",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WwanSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wmiApSrv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPBusEnum",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TapiSrv",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SharedAccess",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql40xx\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CscService",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SensrSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisTapi",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbMdm",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDProxy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UxSms",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mcx2Svc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PlugPlay",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdPPM\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B936B1AF-0C7E-4C4D-84F1-CF67453259A1}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\circlass\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVE\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vhdmp\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\seclogon\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SCSI",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Processor",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uagp35\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPENCDD\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Themes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msiserver",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ksthunk",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ShellHWDetection\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iirsp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\W32Time\\Parameters",
        "HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance\\Disabled",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\crcdisk",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Parport\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Msfs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrkWks\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WacomPen\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidIr\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IRENUM",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppuinotify",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HdAudAddService",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Compbatt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F6B1AFFE-48F0-4340-9F59-C73DDA17C17D}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mssmbios\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swprv",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{40DD7C5E-DA67-4A78-B96C-582A4CBAEDF3}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdxata\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\eventlog\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProfSvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msdsm\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBIOS\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mssmbios",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltLo\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvstor",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvraid\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasSstp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPsvc\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSKSSRV\\Parameters",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C016366B-7126-46CA-B36B-592A3D95A60B}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IpFilterDriver\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mup",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgr",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vhdmp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TabletInputService\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdyboost",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdfs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wscsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioEndpointBuilder\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wecsvc",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffdisk\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAuto",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Disk\\Parameters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdclass",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\circlass"
    ],
    "command_line": [
        "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe\" -accepteula",
        "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe\"  -a s -ct -m -h *",
        "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe\" -accepteula"
    ],
    "file_written": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe"
    ],
    "regkey_deleted": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Sidebar",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\mctadmin"
    ],
    "connects_ip": [
        "103.114.163.252"
    ],
    "file_exists": [
        "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\rdpclip",
        "C:\\Windows\\System32\\drivers\\amdk8.sys",
        "C:\\Program Files\\Windows Media Player\\wmpnetwk.exe",
        "C:\\Python27\\python.exe",
        "C:\\Windows\\System32\\drivers\\filetrace.sys",
        "C:\\Windows\\SysWOW64\\rundll32.exe",
        "C:\\Windows\\System32\\certprop.dll",
        "C:\\Windows\\System32\\drivers\\ndisuio.sys",
        "C:\\Windows\\System32\\drivers\\monitor.sys",
        "C:\\Windows\\System32\\drivers\\WUDFPf.sys",
        "C:\\Windows\\System32\\svchost.exe -k netsvcs.dll",
        "C:\\Windows\\SysWOW64\\iedkcs32.dll",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf",
        "C:\\Windows\\System32\\drivers\\wfplwf.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
        "C:\\Windows\\System32\\drivers\\blbdrive.sys",
        "C:\\Windows\\System32\\clfs.sys",
        "C:\\Windows\\System32\\drivers\\netbios.sys",
        "C:\\Windows\\System32\\drivers\\mstee.sys",
        "C:\\Windows\\System32\\drivers\\hidir.sys",
        "C:\\Windows\\System32\\drivers\\rasl2tp.sys",
        "C:\\Windows\\System32\\drivers\\srvnet.sys",
        "C:\\Python27\\Scripts\\rdpclip.exe",
        "C:\\Windows\\System32\\drivers\\asyncmac.sys",
        "C:\\Windows\\System32\\svchost.exe -k bthsvcs",
        "C:\\Windows\\System32\\KMSVC.DLL",
        "C:\\Windows\\System32\\drivers\\flpydisk.sys",
        "C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation.dll",
        "C:\\Windows\\System32\\drivers\\lsi_sas2.sys",
        "C:\\Windows\\System32\\drivers\\mrxdav.sys",
        "C:\\Windows\\System32\\drivers\\mountmgr.sys",
        "C:\\Windows\\System32\\svchost.exe -k NetworkService",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
        "C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation.dll",
        "C:\\Windows\\System32\\drivers\\rdyboost.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MobilePC\\HotStart",
        "C:\\Windows\\System32\\drivers\\wacompen.sys",
        "C:\\Windows\\System32\\FDResPub.dll",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MUI\\LPRemove",
        "C:\\Windows\\System32\\drivers\\circlass.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
        "C:\\Windows\\System32\\drivers\\CompositeBus.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
        "C:\\Windows\\System32\\drivers\\fdc.sys",
        "C:\\Windows\\System32\\svchost.exe -k NetSvcs.dll",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SystemRestore\\SR",
        "C:\\Windows\\System32\\drivers\\bthmodem.sys",
        "C:\\Windows\\System32\\drivers\\compbatt.sys",
        "C:\\Program Files\\Windows Sidebar\\Sidebar.exe \\autoRun",
        "C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation",
        "C:\\Windows\\System32\\QAGENTRT.DLL",
        "C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation.com",
        "C:\\Python27\\cmd.exe",
        "C:\\Windows\\System32\\wevtsvc.dll",
        "C:\\Windows\\System32\\iedkcs32.dll",
        "C:\\Windows\\System32\\drivers\\RDPCDD.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RegisterSearch",
        "C:\\Windows\\System32\\mctadmin.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Location\\Notifications",
        "C:\\Windows\\System32\\rundll32.exe",
        "C:\\Windows\\System32\\drivers\\BrUsbSer.sys",
        "C:\\Windows\\System32\\drivers\\vms3cap.sys",
        "C:\\Windows\\System32\\drivers\\stexstor.sys",
        "C:\\Windows\\System32\\drivers\\BrFiltUp.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
        "C:\\Windows\\System32\\drivers\\mshidkmdf.sys",
        "C:\\Windows\\System32\\dhcpcore.dll",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\AitAgent",
        "C:\\Users\\cuck\\AppData\\LocalLow",
        "C:\\Windows\\System32\\drivers\\TsUsbGD.sys",
        "C:\\Windows\\System32\\drivers\\HpSAMD.sys",
        "C:\\Windows\\System32\\drivers\\E1G6032E.sys",
        "C:\\Windows\\System32\\drivers\\msdsm.sys",
        "C:\\Windows\\System32\\drivers\\lltdio.sys",
        "C:\\Windows\\System32\\drivers\\vhdmp.sys",
        "C:\\tmpyzbctd\\bin\\inject-x64.exe",
        "C:\\Windows\\System32\\drivers\\usbuhci.sys",
        "C:\\Windows\\System32\\drivers\\pciide.sys",
        "C:\\Windows\\System32\\dwm.exe",
        "C:\\Windows\\System32\\drivers\\rassstp.sys",
        "C:\\Windows\\System32\\rpcss.dll",
        "C:\\Windows\\System32\\drivers\\IPMIDrv.sys",
        "C:\\Windows\\SysWOW64\\ie4uinit.exe",
        "C:\\Windows\\System32\\drivers\\ndis.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
        "C:\\Windows\\System32\\ListSvc.dll",
        "C:\\Windows\\System32\\drivers\\tunnel.sys",
        "C:\\Windows\\System32\\drivers\\hwpolicy.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
        "C:\\Windows\\System32\\bthserv.dll",
        "C:\\Windows\\System32\\drivers\\sisraid4.sys",
        "C:\\Windows\\System32\\iphlpsvc.dll",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Ras\\MobilityManager",
        "C:\\Users\\cuck\\AppData\\Local\\Temp",
        "C:\\Windows\\System32\\drivers\\ndiscap.sys",
        "C:\\Windows\\System32\\drivers\\umpass.sys",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled",
        "C:\\Windows\\System32\\drivers\\bowser.sys",
        "C:\\Windows\\System32\\drivers\\partmgr.sys",
        "C:\\Windows\\System32\\drivers\\iaStorV.sys",
        "C:\\Windows\\System32\\drivers\\usbccgp.sys",
        "C:\\Windows\\System32\\cmd.exe",
        "C:\\Windows\\System32\\drivers\\sffp_sd.sys",
        "C:\\Windows\\System32\\drivers\\volsnap.sys",
        "C:\\Windows\\System32\\svchost.exe -k LocalService.exe",
        "C:\\Windows\\System32\\drivers\\mpsdrv.sys",
        "C:\\Windows\\System32\\drivers\\wmiacpi.sys",
        "C:\\Windows\\System32\\drivers\\MegaSR.sys",
        "C:\\Windows\\System32\\drivers\\adpu320.sys",
        "C:\\Windows\\SysWOW64\\unregmp2.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Task Manager\\Interactive",
        "C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation",
        "C:\\Windows\\System32\\drivers\\cdrom.sys",
        "C:\\Windows\\System32\\drivers\\BrFiltLo.sys",
        "C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork.dll",
        "C:\\Windows\\System32\\AxInstSv.dll",
        "C:\\Windows\\SysWOW64\\mscories.dll",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
        "C:\\Windows\\System32\\drivers\\pcw.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Registry\\RegIdleBackup",
        "C:\\Windows\\System32\\svchost.exe -k DcomLaunch.com",
        "C:\\Windows\\System32\\drivers\\megasas.sys",
        "C:\\Windows\\System32\\drivers\\modem.sys",
        "C:\\Windows\\System32\\unregmp2.exe",
        "C:\\Windows\\System32\\drivers\\adp94xx.sys",
        "C:\\Windows\\System32\\drivers\\iirsp.sys",
        "C:\\Windows\\System32\\userinit.exe",
        "C:\\Windows\\System32\\drivers\\rspndr.sys",
        "C:\\Windows\\System32\\drivers\\hdaudbus.sys",
        "C:\\Windows\\System32\\drivers\\vga.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
        "C:\\Windows\\System32\\drivers\\wanarp.sys",
        "C:\\Windows\\System32\\bdesvc.dll",
        "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe",
        "C:\\Windows\\System32\\drivers\\dmvsc.sys",
        "C:\\Windows\\System32\\drivers\\FsDepends.sys",
        "C:\\Windows\\System32\\conhost.exe",
        "C:\\Windows\\System32\\drivers\\sisraid2.sys",
        "C:\\Windows\\System32\\drivers\\ULIAGPKX.SYS",
        "C:\\Windows\\System32\\drivers\\rasacd.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Maintenance\\WinSAT",
        "C:\\Windows\\System32\\drivers\\hcw85cir.sys",
        "C:\\Windows\\System32\\drivers\\VMBusHID.sys",
        "C:\\Windows\\System32\\svchost.exe -k defragsvc",
        "C:\\Windows\\System32\\drivers\\intelide.sys",
        "C:\\Windows\\System32\\mscories.dll",
        "C:\\Windows\\System32\\drivers\\vmstorfl.sys",
        "C:\\Windows\\System32\\svchost.exe -k.dll",
        "C:\\Windows\\System32\\drivers\\ipfltdrv.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
        "C:\\Windows\\System32\\drivers\\HdAudio.sys",
        "C:\\Windows\\System32\\smss.exe",
        "C:\\Windows\\System32\\drivers\\srv.sys",
        "C:\\Windows\\System32\\drivers\\msiscsi.sys",
        "C:\\Windows\\System32\\drivers\\CmBatt.sys",
        "C:\\Windows\\System32\\svchost.exe -k LocalService.dll",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
        "C:\\Windows\\System32\\svchost.exe -k NetworkService.com",
        "C:\\Windows\\System32\\drivers\\bxvbda.sys",
        "C:\\Python27\\Scripts\\explorer.exe",
        "C:\\Python27\\IconCodecService.dll",
        "C:\\Windows\\System32\\drivers\\vwifibus.sys",
        "C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\ntexe.cat",
        "C:\\Windows\\System32\\drivers\\drmkaud.sys",
        "C:\\Windows\\System32\\appidsvc.dll",
        "C:\\Windows\\System32\\drivers\\fvevol.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
        "C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork.com",
        "C:\\Windows\\System32\\es.dll",
        "C:\\Windows\\System32\\drivers\\ksthunk.sys",
        "C:\\Windows\\System32\\drivers\\ipnat.sys",
        "C:\\Windows\\System32\\drivers\\kbdhid.sys",
        "C:\\Windows\\System32\\alg.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
        "C:\\Windows\\System32\\drivers\\disk.sys",
        "C:\\Windows\\System32\\svchost.exe -k DcomLaunch.dll",
        "C:\\Windows\\System32\\lsass.exe",
        "C:\\Windows\\System32\\drivers\\kbdclass.sys",
        "C:\\Windows\\System32\\p2pcollab.dll",
        "C:\\Windows\\System32\\drivers\\fltMgr.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
        "C:\\Windows\\System32\\drivers\\smb.sys",
        "C:\\Windows\\System32\\drivers\\isapnp.sys",
        "C:\\Windows\\System32\\drivers\\amdsbs.sys",
        "C:\\Windows\\System32\\lsm.exe",
        "C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Autochk\\Proxy",
        "C:\\Windows\\System32\\drivers\\usbcir.sys",
        "C:\\Windows\\System32\\drivers\\vmbus.sys",
        "C:\\Windows\\System32\\drivers\\tdpipe.sys",
        "C:\\Windows\\System32\\drivers\\appid.sys",
        "C:\\Windows\\System32\\drivers\\cng.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
        "C:\\Windows\\System32\\drivers\\afd.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
        "C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup.dll",
        "C:\\Windows\\System32\\gpsvc.dll",
        "C:\\Windows\\System32\\svchost.exe -k.exe",
        "C:\\Windows\\System32\\drivers\\tcpip.sys",
        "C:\\Windows\\System32\\services.exe",
        "C:\\Windows\\System32\\dot3svc.dll",
        "C:\\Windows\\System32\\svchost.exe -k defragsvc.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
        "C:\\Windows\\System32\\drivers\\BrSerWdm.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
        "C:\\Windows\\System32\\catroot2\\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\\",
        "C:\\Windows\\System32\\drivers\\serial.sys",
        "C:\\Windows\\System32\\drivers\\lsi_sas.sys",
        "C:\\Windows\\System32\\fdPHost.dll",
        "C:\\Windows\\System32\\drivers\\dxgkrnl.sys",
        "C:\\Windows\\System32\\drivers\\nvstor.sys",
        "C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup.com",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc",
        "C:\\Windows\\System32\\FXSSVC.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
        "C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WDI\\ResolutionHost",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ehDRMInit",
        "C:\\Windows\\System32\\IKEEXT.DLL",
        "C:\\Windows\\SysWOW64\\regsvr32.exe",
        "C:\\Windows\\System32\\drivers\\csc.sys",
        "C:\\Windows\\System32\\drivers\\i8042prt.sys",
        "C:\\Windows\\System32\\drivers\\parport.sys",
        "C:\\Windows\\System32\\drivers\\nfrd960.sys",
        "C:\\Windows\\System32\\drivers\\msahci.sys",
        "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe",
        "C:\\Windows\\System32\\ipbusenum.dll",
        "C:\\Windows\\System32\\winlogon.exe",
        "C:\\Windows\\System32\\drivers\\sfloppy.sys",
        "C:\\Windows\\System32\\drivers\\ndiswan.sys",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
        "C:\\Windows\\System32\\drivers\\RDPENCDD.sys",
        "C:\\Windows\\System32\\drivers\\nwifi.sys",
        "C:\\Windows\\System32\\drivers\\ws2ifsl.sys",
        "C:\\Windows\\System32\\drivers\\PEAuth.sys",
        "C:\\Windows\\System32\\drivers\\NV_AGP.SYS",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
        "C:\\Windows\\System32\\drivers\\rdpdr.sys",
        "C:\\Windows\\System32\\drivers\\elxstor.sys",
        "C:\\Windows\\System32\\drivers\\hidusb.sys",
        "C:\\Windows\\System32\\drivers\\ql40xx.sys",
        "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\rdpclip.com",
        "C:\\Windows\\System32\\msdtckrm.dll",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
        "C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork",
        "C:\\Python27\\Scripts\\rdpclip",
        "C:\\Python27\\Scripts\\cmd.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
        "C:\\Windows\\System32\\drivers\\amdxata.sys",
        "C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted.dll",
        "C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted",
        "C:\\Windows\\System32\\NOTEPAD.EXE %1",
        "C:\\Windows\\System32\\drivers\\usbhub.sys",
        "C:\\Windows\\System32\\wininit.exe",
        "C:\\Python27\\rdpclip.com",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\",
        "C:\\Windows\\System32\\aelupsvc.dll",
        "C:\\Windows\\System32\\drivers\\nsiproxy.sys",
        "C:\\Windows\\System32\\drivers\\mup.sys",
        "C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation.exe",
        "C:\\Windows\\System32\\BFE.DLL",
        "C:\\Windows\\explorer.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
        "C:\\Python27\\Scripts\\rdpclip.com",
        "C:\\Windows\\System32\\drivers\\netbt.sys",
        "C:\\Windows\\System32\\svchost.exe -k LocalService",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
        "C:\\Windows\\System32\\drivers\\atapi.sys",
        "C:\\Windows\\System32\\audiosrv.dll",
        "C:\\Windows\\System32\\drivers\\storvsc.sys",
        "C:\\Program Files\\Windows Mail\\WinMail.exe",
        "C:\\Windows\\System32\\drivers\\fileinfo.sys",
        "C:\\Windows\\System32\\drivers\\wd.sys",
        "C:\\Windows\\System32\\drivers\\RDPREFMP.sys",
        "C:\\Windows\\System32\\drivers\\pacer.sys",
        "C:\\Windows\\System32\\drivers\\dfsc.sys",
        "C:\\Windows\\System32\\svchost.exe -k bthsvcs.exe",
        "C:\\Windows\\System32\\drivers\\mrxsmb10.sys",
        "C:\\Windows\\System32\\cscsvc.dll",
        "C:\\Windows\\System32\\drivers\\mrxsmb20.sys",
        "C:\\Windows\\System32\\drivers\\pci.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
        "C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation.exe",
        "C:\\Windows\\System32\\appmgmts.dll",
        "C:\\Windows\\Microsoft.Net\\Framework64\\v3.0\\WPF\\PresentationFontCache.exe",
        "C:\\Users\\cuck\\AppData\\Roaming",
        "C:\\Windows\\System32\\drivers\\b57nd60a.sys",
        "C:\\Windows\\System32\\drivers\\wimmount.sys",
        "C:\\Python27\\Scripts\\IconCodecService.dll",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
        "C:\\Windows\\System32\\drivers\\TsUsbFlt.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
        "C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup.exe",
        "C:\\Windows\\System32\\svchost.exe -k NetSvcs",
        "C:\\Python27\\SystemPropertiesPerformance.exe",
        "C:\\Windows\\rdpclip",
        "C:\\Windows\\System32\\drivers\\acpi.sys",
        "C:\\Windows\\System32\\drivers\\udfs.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\AutoWake",
        "C:\\Windows\\System32\\drivers\\raspppoe.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
        "C:\\Windows\\System32\\drivers\\hidbth.sys",
        "C:\\Python27\\Scripts\\regsvr32.exe",
        "C:\\Windows\\System32\\drivers\\irenum.sys",
        "C:\\Windows\\System32\\cryptsvc.dll",
        "C:\\Windows\\System32\\drivers\\srv2.sys",
        "C:\\Windows\\System32\\SearchIndexer.exe",
        "C:\\Windows\\System32\\drivers\\serenum.sys",
        "C:\\Windows\\System32\\drivers\\intelppm.sys",
        "C:\\Windows\\System32\\drivers\\mskssrv.sys",
        "C:\\Windows\\System32\\drivers\\mssmbios.sys",
        "C:\\Windows\\System32\\drivers\\BrSerId.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
        "C:\\Windows\\System32\\provsvc.dll",
        "C:\\Windows\\System32\\drivers\\cdfs.sys",
        "C:\\Windows\\System32\\svchost.exe -k defragsvc.com",
        "C:\\Windows\\System32\\drivers\\usbohci.sys",
        "C:\\Windows\\System32\\catroot\\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\\",
        "C:\\Windows\\System32\\drivers\\vsmraid.sys",
        "C:\\Program Files (x86)\\Windows Mail\\WinMail.exe",
        "C:\\Windows\\System32\\drivers\\amdppm.sys",
        "C:\\Windows\\System32\\drivers\\vdrvroot.sys",
        "C:\\Windows\\System32\\drivers\\pcmcia.sys",
        "C:\\Windows\\System32\\hidserv.dll",
        "C:\\Windows\\System32\\svchost.exe",
        "C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted.dll",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
        "C:\\Windows\\System32\\svchost.exe -k netsvcs.com",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SessionAgent",
        "C:\\Windows\\System32\\drivers\\mspqm.sys",
        "C:\\Windows\\System32\\drivers\\msisadrv.sys",
        "C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
        "C:\\Windows\\System32\\IconCodecService.dll",
        "C:\\Windows\\System32\\drivers\\nvraid.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
        "C:\\Windows\\System32\\rdpclip.com",
        "C:\\Windows\\System32\\dnsrslvr.dll",
        "C:\\Windows\\System32\\rdpclip",
        "C:\\Windows\\System32\\eapsvc.dll",
        "C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted.com",
        "C:\\Windows\\System32\\regsvr32.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
        "C:\\Windows\\System32\\drivers\\mouclass.sys",
        "C:\\Windows\\System32\\drivers\\vgapnp.sys",
        "C:\\Windows\\System32\\ie4uinit.exe",
        "C:\\Windows\\System32\\drivers\\volmgrx.sys",
        "C:\\Windows\\System32\\svchost.exe -k defragsvc.dll",
        "C:\\Windows\\System32\\drivers\\arcsas.sys",
        "C:\\Windows\\System32\\drivers\\amdide.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
        "C:\\Windows\\System32\\browser.dll",
        "C:\\Windows\\System32\\drivers\\termdd.sys",
        "C:\\Windows\\System32\\svchost.exe -k NetSvcs.com",
        "C:\\Windows\\System32\\drivers\\swenum.sys",
        "C:\\Windows\\System32\\taskhost.exe",
        "C:\\Windows\\System32\\drivers\\luafv.sys",
        "C:\\Python27\\rdpclip",
        "C:\\Windows\\System32\\drivers\\tdx.sys",
        "C:\\Windows\\System32\\drivers\\cmdide.sys",
        "C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\infocard.exe",
        "C:\\Windows\\System32\\drivers\\sbp2port.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\PolicyConverter",
        "C:\\Windows\\System32\\drivers\\hidbatt.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
        "C:\\Windows\\System32\\drivers\\lsi_fc.sys",
        "C:\\Windows\\System32\\drivers\\ksecpkg.sys",
        "C:\\Windows\\System32\\drivers\\USBSTOR.SYS",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURActivate",
        "C:\\Windows\\System32\\SystemPropertiesPerformance.exe",
        "C:\\Windows\\ehome\\ehrecvr.exe",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
        "C:\\Python27\\Scripts\\SystemPropertiesPerformance.exe",
        "C:\\Windows\\System32\\drivers\\tssecsrv.sys",
        "C:\\Windows\\System32\\drivers\\ndistapi.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Diagnosis\\Scheduled",
        "C:\\Windows\\System32\\drivers\\Wdf01000.sys",
        "C:\\Windows\\System32\\drivers\\discache.sys",
        "C:\\Windows\\System32\\svchost.exe -k bthsvcs.dll",
        "C:\\Windows\\System32\\drivers\\usbprint.sys",
        "C:\\Windows\\System32\\drivers\\rdbss.sys",
        "C:\\Windows\\System32\\drivers\\errdev.sys",
        "C:\\Windows\\System32\\drivers\\processr.sys",
        "C:\\Windows\\System32\\dllhost.exe",
        "C:\\Windows\\System32\\drivers\\rdpbus.sys",
        "C:\\Windows\\System32\\drivers\\mspclock.sys",
        "C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted.exe",
        "C:\\Windows\\System32\\drivers\\aliide.sys",
        "C:\\Windows\\System32\\drivers\\mpio.sys",
        "C:\\Python27\\rdpclip.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
        "C:\\Windows\\System32\\drivers\\evbda.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\mcupdate",
        "C:\\Windows\\System32\\svchost.exe -k NetworkService.exe",
        "C:\\Windows\\System32\\qmgr.dll",
        "C:\\Windows\\System32\\defragsvc.dll",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
        "C:\\Windows\\System32\\FntCache.dll",
        "C:\\Windows\\System32\\drivers\\ql2300.sys",
        "C:\\Windows\\System32\\drivers\\umbus.sys",
        "C:\\Windows\\System32\\drivers\\tdtcp.sys",
        "C:\\Windows\\System32\\drivers\\acpipmi.sys",
        "C:\\Windows\\System32\\svchost.exe -k netsvcs",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\UAGP35.SYS",
        "C:\\Windows\\System32\\svchost.exe -k NetworkService.dll",
        "C:\\Windows\\System32\\drivers\\adpahci.sys",
        "C:\\Python27\\regsvr32.exe",
        "C:\\Windows\\System32\\drivers\\sffdisk.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
        "C:\\Windows\\System32\\drivers\\arc.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
        "C:\\Windows\\System32\\dnsapi.dll",
        "C:\\Windows\\System32\\rdpclip.exe",
        "C:\\Windows\\System32\\drivers\\ohci1394.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RecordingRestart",
        "C:\\Windows\\System32\\svchost.exe -k netsvcs.exe",
        "C:\\Windows\\System32\\drivers\\volmgr.sys",
        "C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RAC\\RacTask",
        "C:\\Windows\\System32\\drivers\\agilevpn.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
        "C:\\Windows\\System32\\drivers\\GAGP30KX.SYS",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe",
        "C:\\Windows\\rdpclip.com",
        "C:\\Windows\\System32\\svchost.exe -k bthsvcs.com",
        "C:\\Windows\\System32\\dps.dll",
        "C:\\Windows\\ehome\\ehsched.exe",
        "C:\\Windows\\System32\\csrss.exe",
        "C:\\Windows\\System32\\svchost.exe -k.com",
        "C:\\Windows\\System32\\drivers\\1394ohci.sys",
        "C:\\Windows\\System32\\drivers\\ksecdd.sys",
        "C:\\Windows\\System32\\drivers\\usbehci.sys",
        "C:\\Windows\\System32\\drivers\\amdsata.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\GadgetManager",
        "C:\\Windows\\System32\\drivers\\MTConfig.sys",
        "C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted.com",
        "C:\\Windows\\System32\\drivers\\mrxsmb.sys",
        "C:\\Windows\\System32\\drivers\\crcdisk.sys",
        "C:\\Windows\\System32\\drivers\\mouhid.sys",
        "C:\\Windows\\System32\\drivers\\BrUsbMdm.sys",
        "C:\\Windows\\System32\\drivers\\lsi_scsi.sys",
        "C:\\Windows\\System32\\svchost.exe -k NetSvcs.exe",
        "C:\\Windows\\System32\\drivers\\sermouse.sys",
        "C:\\Windows\\System32\\spoolsv.exe",
        "C:\\Windows\\System32\\drivers\\scfilter.sys",
        "C:\\Windows\\System32\\drivers\\http.sys",
        "C:\\Windows\\System32\\appinfo.dll",
        "C:\\Windows\\System32\\drivers\\raspptp.sys",
        "C:\\Windows\\inf\\",
        "C:\\Windows\\System32\\svchost.exe -k LocalService.com",
        "C:\\Windows\\System32\\fveui.dll",
        "C:\\Windows\\System32\\svchost.exe -k DcomLaunch.exe",
        "C:\\Windows\\System32\\drivers\\viaide.sys",
        "C:\\Python27\\explorer.exe",
        "C:\\Windows\\System32\\drivers\\tcpipreg.sys",
        "C:\\Windows\\System32\\drivers\\qwavedrv.sys",
        "C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation.com",
        "C:\\Windows\\System32\\wbem\\rdpclip",
        "C:\\Windows\\System32\\drivers\\AGP440.sys",
        "C:\\Windows\\System32\\svchost.exe -k DcomLaunch",
        "C:\\Windows\\System32\\explorer.exe",
        "C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork.exe",
        "C:\\Windows\\System32\\wbem\\rdpclip.com",
        "C:\\Windows\\System32\\svchost.exe -k",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
        "C:\\Windows\\System32\\drivers\\sffp_mmc.sys"
    ],
    "file_failed": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\%USERPROFILE%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\aitagent",
        "C:\\ProgramData\\Microsoft\\desktop.ini",
        "C:\\Windows\\ehome\\ehrec",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\B8CC409ACDBF2A2FE04C56F2875B1FD6",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\BthUdTask.exe",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\F90F18257CBB4D84216AC1E1F3BB2C76",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\C24EC5BDAF13613245B4CECC3DE91DC6",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\%1",
        "C:\\Program",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\696F3DE637E6DE85B458996D49D759AD",
        "C:\\Windows\\ehome\\mcupdate",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\%USERPROFILE%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\desktop.ini",
        "C:\\Windows\\System32\\d",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\sc.exe",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\%USERPROFILE%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup"
    ],
    "resolves_host": [
        "crl.microsoft.com",
        "www.microsoft.com"
    ],
    "guid": [
        "{add8ba80-002b-11d0-8f0f-00c04fd7d062}",
        "{08244ee6-92f0-47f2-9fc9-929baa2e7235}",
        "{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
        "{4e77131d-3629-431c-9818-c5679dc83e81}",
        "{d9144dcd-e998-4eca-ab6a-dcd83ccba16d}",
        "{dffacdc5-679f-4156-8947-c5c76bc0b67f}",
        "{0c6c4200-c589-11d0-999a-00c04fd655e1}",
        "{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}"
    ],
    "file_read": [
        "C:\\Windows\\System32\\drivers\\amdk8.sys",
        "C:\\Program Files\\Windows Media Player\\wmpnetwk.exe",
        "C:\\Python27\\python.exe",
        "C:\\Windows\\System32\\drivers\\filetrace.sys",
        "C:\\Windows\\System32\\drivers\\ndisuio.sys",
        "C:\\Windows\\System32\\drivers\\monitor.sys",
        "C:\\Windows\\System32\\drivers\\WUDFPf.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
        "C:\\Windows\\System32\\aepdu.dll",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
        "C:\\Windows\\System32\\drivers\\blbdrive.sys",
        "C:\\Windows\\System32\\clfs.sys",
        "C:\\Windows\\System32\\drivers\\netbios.sys",
        "C:\\Windows\\System32\\drivers\\mstee.sys",
        "C:\\Windows\\System32\\drivers\\hidir.sys",
        "C:\\Windows\\System32\\drivers\\rasl2tp.sys",
        "C:\\Windows\\System32\\drivers\\srvnet.sys",
        "C:\\Windows\\System32\\drivers\\ipfltdrv.sys",
        "C:\\Windows\\System32\\drivers\\asyncmac.sys",
        "C:\\Windows\\System32\\drivers\\flpydisk.sys",
        "C:\\Windows\\System32\\drivers\\lsi_sas2.sys",
        "C:\\Windows\\System32\\drivers\\mrxdav.sys",
        "C:\\Windows\\System32\\drivers\\mountmgr.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
        "C:\\Windows\\System32\\drivers\\rdyboost.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MobilePC\\HotStart",
        "C:\\Windows\\System32\\drivers\\wacompen.sys",
        "C:\\Users\\cuck\\Searches\\desktop.ini",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MUI\\LPRemove",
        "C:\\Windows\\System32\\drivers\\circlass.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
        "C:\\Windows\\System32\\drivers\\CompositeBus.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
        "C:\\Windows\\System32\\drivers\\fdc.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SystemRestore\\SR",
        "C:\\Windows\\System32\\drivers\\bthmodem.sys",
        "C:\\Windows\\System32\\drivers\\compbatt.sys",
        "C:\\Windows\\System32\\drivers\\RDPCDD.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RegisterSearch",
        "C:\\Windows\\System32\\mctadmin.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Location\\Notifications",
        "C:\\Windows\\System32\\drivers\\BrUsbSer.sys",
        "C:\\Windows\\System32\\drivers\\vdrvroot.sys",
        "C:\\Windows\\System32\\drivers\\stexstor.sys",
        "C:\\Windows\\System32\\drivers\\BrFiltUp.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
        "C:\\Windows\\System32\\drivers\\mshidkmdf.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\AitAgent",
        "C:\\Windows\\System32\\drivers\\TsUsbGD.sys",
        "C:\\Windows\\System32\\drivers\\HpSAMD.sys",
        "C:\\Windows\\System32\\drivers\\E1G6032E.sys",
        "C:\\Windows\\System32\\drivers\\msdsm.sys",
        "C:\\Windows\\System32\\drivers\\lltdio.sys",
        "C:\\Windows\\System32\\drivers\\vhdmp.sys",
        "C:\\Windows\\System32\\drivers\\usbuhci.sys",
        "C:\\Windows\\System32\\drivers\\pciide.sys",
        "C:\\Windows\\System32\\dwm.exe",
        "C:\\Windows\\System32\\drivers\\rassstp.sys",
        "C:\\Windows\\System32\\drivers\\IPMIDrv.sys",
        "C:\\Windows\\System32\\raserver.exe",
        "C:\\Windows\\System32\\drivers\\ndis.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
        "C:\\Windows\\System32\\drivers\\tunnel.sys",
        "C:\\Windows\\System32\\drivers\\hwpolicy.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
        "C:\\Windows\\System32\\drivers\\sisraid4.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Ras\\MobilityManager",
        "C:\\Windows\\System32\\drivers\\ndiscap.sys",
        "C:\\Windows\\System32\\drivers\\umpass.sys",
        "C:\\Windows\\System32\\drivers\\bowser.sys",
        "C:\\Windows\\System32\\drivers\\partmgr.sys",
        "C:\\Windows\\System32\\drivers\\iaStorV.sys",
        "C:\\Windows\\System32\\drivers\\wfplwf.sys",
        "C:\\Windows\\System32\\drivers\\usbccgp.sys",
        "C:\\Windows\\System32\\cmd.exe",
        "C:\\Windows\\System32\\drivers\\sffp_sd.sys",
        "C:\\Windows\\System32\\drivers\\volsnap.sys",
        "C:\\Windows\\ehome\\mcupdate.exe",
        "C:\\Windows\\System32\\drivers\\mpsdrv.sys",
        "C:\\Windows\\System32\\drivers\\wmiacpi.sys",
        "C:\\Windows\\System32\\drivers\\MegaSR.sys",
        "C:\\Windows\\System32\\drivers\\adpu320.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Task Manager\\Interactive",
        "C:\\Windows\\System32\\drivers\\cdrom.sys",
        "C:\\Windows\\System32\\drivers\\BrFiltLo.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
        "C:\\Windows\\System32\\drivers\\pcw.sys",
        "C:\\Windows\\System32\\Defrag.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Registry\\RegIdleBackup",
        "C:\\Windows\\System32\\drivers\\megasas.sys",
        "C:\\Windows\\System32\\drivers\\modem.sys",
        "C:\\Windows\\System32\\drivers\\adp94xx.sys",
        "C:\\Windows\\System32\\drivers\\iirsp.sys",
        "C:\\Windows\\System32\\drivers\\rspndr.sys",
        "C:\\Windows\\System32\\drivers\\hdaudbus.sys",
        "C:\\Windows\\System32\\drivers\\vga.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
        "C:\\Windows\\System32\\drivers\\wanarp.sys",
        "C:\\Windows\\System32\\drivers\\dmvsc.sys",
        "C:\\Windows\\System32\\drivers\\FsDepends.sys",
        "C:\\Windows\\System32\\conhost.exe",
        "C:\\Windows\\System32\\drivers\\sisraid2.sys",
        "C:\\Windows\\System32\\appidpolicyconverter.exe",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
        "C:\\Windows\\System32\\drivers\\ULIAGPKX.SYS",
        "C:\\Windows\\System32\\drivers\\rasacd.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Maintenance\\WinSAT",
        "C:\\Windows\\System32\\drivers\\hcw85cir.sys",
        "C:\\Windows\\System32\\drivers\\VMBusHID.sys",
        "C:\\Windows\\System32\\drivers\\intelide.sys",
        "C:\\Users\\cuck\\Favorites\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\vmstorfl.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
        "C:\\Windows\\System32\\drivers\\HdAudio.sys",
        "C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe",
        "C:\\Windows\\System32\\drivers\\srv.sys",
        "C:\\Windows\\System32\\drivers\\msiscsi.sys",
        "C:\\Windows\\System32\\drivers\\CmBatt.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
        "C:\\Windows\\System32\\drivers\\bxvbda.sys",
        "C:\\Windows\\System32\\drivers\\vwifibus.sys",
        "C:\\Windows\\System32\\drivers\\drmkaud.sys",
        "C:\\Windows\\System32\\drivers\\fvevol.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
        "C:\\Windows\\System32\\ndfapi.dll",
        "C:\\Windows\\System32\\drivers\\ksthunk.sys",
        "C:\\Windows\\System32\\drivers\\ipnat.sys",
        "C:\\Windows\\System32\\drivers\\kbdhid.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
        "C:\\Windows\\System32\\drivers\\disk.sys",
        "C:\\Windows\\System32\\lpremove.exe",
        "C:\\Windows\\System32\\lsass.exe",
        "C:\\Windows\\System32\\drivers\\kbdclass.sys",
        "C:\\Windows\\System32\\drivers\\fltMgr.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
        "C:\\Windows\\System32\\drivers\\smb.sys",
        "C:\\Windows\\System32\\drivers\\isapnp.sys",
        "C:\\Windows\\System32\\drivers\\amdsbs.sys",
        "C:\\Windows\\System32\\lsm.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Autochk\\Proxy",
        "C:\\Windows\\System32\\drivers\\usbcir.sys",
        "C:\\Windows\\System32\\drivers\\vmbus.sys",
        "C:\\Windows\\System32\\drivers\\tdpipe.sys",
        "C:\\Windows\\System32\\drivers\\appid.sys",
        "C:\\Windows\\System32\\drivers\\cng.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
        "C:\\Windows\\System32\\drivers\\afd.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
        "C:\\Users\\cuck\\Videos\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\tcpip.sys",
        "C:\\Windows\\System32\\services.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
        "C:\\Windows\\System32\\drivers\\BrSerWdm.sys",
        "C:\\Windows\\System32\\drivers\\ndiswan.sys",
        "C:\\Users\\cuck\\Contacts\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\serial.sys",
        "C:\\Windows\\System32\\drivers\\lsi_sas.sys",
        "C:\\Windows\\System32\\DFDWiz.exe",
        "C:\\Windows\\System32\\drivers\\dxgkrnl.sys",
        "C:\\Windows\\System32\\dfdts.dll",
        "C:\\Windows\\System32\\drivers\\nvstor.sys",
        "C:\\Windows\\System32\\LocationNotifications.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WDI\\ResolutionHost",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ehDRMInit",
        "C:\\Windows\\System32\\drivers\\csc.sys",
        "C:\\Windows\\System32\\drivers\\i8042prt.sys",
        "C:\\Windows\\System32\\gatherNetworkInfo.vbs",
        "C:\\Windows\\System32\\drivers\\parport.sys",
        "C:\\Windows\\System32\\drivers\\nfrd960.sys",
        "C:\\Windows\\System32\\drivers\\msahci.sys",
        "C:\\Program Files\\Windows Media Player\\wmpnscfg.exe",
        "C:\\Windows\\System32\\winlogon.exe",
        "C:\\Windows\\System32\\drivers\\sfloppy.sys",
        "C:\\Windows\\System32\\drivers\\RDPENCDD.sys",
        "C:\\Windows\\System32\\wininit.exe",
        "C:\\Windows\\System32\\drivers\\nwifi.sys",
        "C:\\Windows\\System32\\drivers\\ws2ifsl.sys",
        "C:\\Windows\\System32\\drivers\\PEAuth.sys",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
        "C:\\Windows\\System32\\drivers\\NV_AGP.SYS",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
        "C:\\Windows\\System32\\drivers\\rdpdr.sys",
        "C:\\Users\\cuck\\Pictures\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\elxstor.sys",
        "C:\\Windows\\System32\\drivers\\hidusb.sys",
        "C:\\Windows\\System32\\drivers\\ql40xx.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
        "C:\\Windows\\System32\\drivers\\amdxata.sys",
        "C:\\Windows\\System32\\drivers\\usbhub.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
        "C:\\Windows\\System32\\drivers\\vms3cap.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
        "C:\\Windows\\System32\\drivers\\nsiproxy.sys",
        "C:\\Windows\\System32\\drivers\\mup.sys",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
        "C:\\Windows\\System32\\BFE.DLL",
        "C:\\Windows\\explorer.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
        "C:\\Windows\\System32\\drivers\\netbt.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
        "C:\\Windows\\System32\\drivers\\atapi.sys",
        "C:\\Windows\\System32\\drivers\\storvsc.sys",
        "C:\\Windows\\System32\\drivers\\fileinfo.sys",
        "C:\\Windows\\System32\\drivers\\wd.sys",
        "C:\\Windows\\System32\\drivers\\RDPREFMP.sys",
        "C:\\Windows\\System32\\drivers\\pacer.sys",
        "C:\\Windows\\System32\\drivers\\dfsc.sys",
        "C:\\Windows\\System32\\drivers\\mrxsmb10.sys",
        "C:\\Users\\cuck\\Documents\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\mrxsmb20.sys",
        "C:\\Windows\\System32\\appidcertstorecheck.exe",
        "C:\\Windows\\System32\\drivers\\pci.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\b57nd60a.sys",
        "C:\\Windows\\System32\\drivers\\wimmount.sys",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
        "C:\\Windows\\System32\\drivers\\TsUsbFlt.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\acpi.sys",
        "C:\\Windows\\System32\\drivers\\udfs.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\AutoWake",
        "C:\\Windows\\System32\\drivers\\raspppoe.sys",
        "C:\\Users\\cuck\\Saved Games\\desktop.ini",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
        "C:\\Windows\\System32\\drivers\\hidbth.sys",
        "C:\\Windows\\System32\\drivers\\irenum.sys",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
        "C:\\Windows\\System32\\drivers\\srv2.sys",
        "C:\\Windows\\System32\\SearchIndexer.exe",
        "C:\\Windows\\System32\\drivers\\serenum.sys",
        "C:\\Windows\\System32\\drivers\\intelppm.sys",
        "C:\\Windows\\System32\\drivers\\mskssrv.sys",
        "C:\\Windows\\System32\\drivers\\mssmbios.sys",
        "C:\\Windows\\System32\\drivers\\BrSerId.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
        "C:\\Windows\\System32\\drivers\\agilevpn.sys",
        "C:\\Windows\\System32\\drivers\\usbohci.sys",
        "C:\\Windows\\System32\\drivers\\vsmraid.sys",
        "C:\\Windows\\System32\\drivers\\amdppm.sys",
        "C:\\Windows\\System32\\drivers\\pcmcia.sys",
        "C:\\Windows\\System32\\svchost.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SessionAgent",
        "C:\\Windows\\System32\\drivers\\mspqm.sys",
        "C:\\Windows\\System32\\drivers\\msisadrv.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
        "C:\\Windows\\System32\\drivers\\nvraid.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
        "C:\\Windows\\ehome\\ehPrivJob.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
        "C:\\Windows\\System32\\drivers\\mouclass.sys",
        "C:\\Windows\\System32\\drivers\\vgapnp.sys",
        "C:\\Windows\\System32\\drivers\\volmgrx.sys",
        "C:\\Windows\\System32\\drivers\\arcsas.sys",
        "C:\\Windows\\System32\\drivers\\amdide.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
        "C:\\Windows\\System32\\powercfg.exe",
        "C:\\Windows\\System32\\drivers\\termdd.sys",
        "C:\\Program Files\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\swenum.sys",
        "C:\\Windows\\System32\\taskhost.exe",
        "C:\\Windows\\System32\\drivers\\luafv.sys",
        "C:\\Windows\\System32\\drivers\\tdx.sys",
        "C:\\Windows\\System32\\drivers\\cmdide.sys",
        "C:\\Windows\\System32\\drivers\\sbp2port.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\PolicyConverter",
        "C:\\Windows\\System32\\drivers\\hidbatt.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
        "C:\\Windows\\System32\\drivers\\lsi_fc.sys",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
        "C:\\Windows\\System32\\drivers\\ksecpkg.sys",
        "C:\\Windows\\System32\\drivers\\USBSTOR.SYS",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURActivate",
        "C:\\Users\\cuck\\Music\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\tssecsrv.sys",
        "C:\\Windows\\System32\\drivers\\ndistapi.sys",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Diagnosis\\Scheduled",
        "C:\\Windows\\System32\\drivers\\Wdf01000.sys",
        "C:\\Windows\\System32\\drivers\\discache.sys",
        "C:\\Users\\cuck\\Desktop\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\usbprint.sys",
        "C:\\Windows\\System32\\drivers\\rdbss.sys",
        "C:\\Windows\\System32\\drivers\\errdev.sys",
        "C:\\Windows\\System32\\drivers\\processr.sys",
        "C:\\Windows\\System32\\drivers\\rdpbus.sys",
        "C:\\Windows\\System32\\sc.exe",
        "C:\\Windows\\System32\\drivers\\mspclock.sys",
        "C:\\Windows\\System32\\drivers\\aliide.sys",
        "C:\\Windows\\System32\\drivers\\mpio.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
        "C:\\Windows\\System32\\drivers\\evbda.sys",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\mcupdate",
        "C:\\Users\\cuck\\Downloads\\desktop.ini",
        "C:\\Windows\\System32\\wermgr.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
        "C:\\Windows\\System32\\drivers\\ql2300.sys",
        "C:\\Windows\\System32\\drivers\\umbus.sys",
        "C:\\Windows\\System32\\drivers\\tdtcp.sys",
        "C:\\Windows\\System32\\drivers\\acpipmi.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\UAGP35.SYS",
        "C:\\Windows\\System32\\drivers\\adpahci.sys",
        "C:\\Windows\\System32\\drivers\\sffdisk.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
        "C:\\Windows\\System32\\notepad.exe",
        "C:\\Windows\\System32\\drivers\\arc.sys",
        "C:\\Program Files (x86)\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\ohci1394.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RecordingRestart",
        "C:\\Windows\\System32\\drivers\\volmgr.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RAC\\RacTask",
        "C:\\Windows\\System32\\drivers\\cdfs.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
        "C:\\Windows\\System32\\drivers\\GAGP30KX.SYS",
        "C:\\Windows\\System32\\csrss.exe",
        "c:\\program files\\windows defender\\MpCmdRun.exe",
        "C:\\Windows\\System32\\drivers\\1394ohci.sys",
        "C:\\Windows\\System32\\drivers\\ksecdd.sys",
        "C:\\Windows\\System32\\drivers\\usbehci.sys",
        "C:\\Users\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\amdsata.sys",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\GadgetManager",
        "C:\\Windows\\System32\\drivers\\MTConfig.sys",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\crcdisk.sys",
        "C:\\Windows\\System32\\drivers\\mouhid.sys",
        "C:\\Windows\\System32\\drivers\\BrUsbMdm.sys",
        "C:\\Windows\\System32\\drivers\\lsi_scsi.sys",
        "C:\\Windows\\System32\\drivers\\sermouse.sys",
        "C:\\Windows\\System32\\spoolsv.exe",
        "C:\\Windows\\System32\\drivers\\scfilter.sys",
        "C:\\Windows\\System32\\sdclt.exe",
        "C:\\Users\\cuck\\Links\\desktop.ini",
        "C:\\Windows\\System32\\drivers\\http.sys",
        "C:\\Windows\\System32\\drivers\\raspptp.sys",
        "C:\\Windows\\System32\\drivers\\viaide.sys",
        "C:\\Windows\\System32\\drivers\\tcpipreg.sys",
        "C:\\Windows\\System32\\drivers\\qwavedrv.sys",
        "C:\\Windows\\System32\\drivers\\mrxsmb.sys",
        "C:\\Windows\\System32\\drivers\\AGP440.sys",
        "C:\\Windows\\System32\\wsqmcons.exe",
        "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
        "C:\\Windows\\System32\\drivers\\sffp_mmc.sys"
    ],
    "regkey_read": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Attributes",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{3307E641-F5EE-49E6-A1FE-BFB5D671441C}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Type",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Favorites",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{448186F9-75B9-4FB7-A6E0-B19A2BADC1BE}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D0250F3F-6480-484F-B719-42F659AC64D5}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\PreventItemCreationInUsersFilesFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\ProfileImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MpIdleTask\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\RpcId",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\CallForAttributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location\\Notifications\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\Content Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0003\\NetCfgInstanceId",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI\\ResolutionHost\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fs_Rec\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Roamable",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB02381F-D652-4B1C-894A-712498C62C51}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Capabilities",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2470470F-2634-478E-B181-571E98A789BB}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A656BBE1-4E3E-4C8A-BD79-A8CA56782753}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4DE0CAB9-ECFE-4AA9-B95A-FE815A2EAA4E}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\ProfileImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\StorageDelegate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoWebView",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D018DE2F-F02A-4BDB-BA74-56BCD427BE40}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Version",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A7C73732-9F11-4281-8D19-764D4EC9D94D}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.44.3.4!7\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Cryptography\\PrivKeyCachePurgeIntervalSeconds",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Type",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{374DE290-123F-4565-9164-39C4925E467B}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager\\Interactive\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP\\UPnPHostConfig\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5F5A18EB-DC73-4E45-A11C-B59043598412}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HideOnDesktopPerUser",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FB3C354D-297A-4EB2-9B58-090F6361906B}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB02381F-D652-4B1C-894A-712498C62C51}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HideFolderVerbs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B81A55E6-C03C-4EF0-B86F-A80A89DF468D}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06308A56-69E7-4844-A784-8509C25B6C62}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SessionAgent\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\WinHttpSettings",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\DocObject",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\DocObject",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DefaultIcon\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Logon Synchronization\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06308A56-69E7-4844-A784-8509C25B6C62}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{87F56B34-044E-4A48-8FDD-087BFABD5ECF}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MaxSockaddrLength",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB07F7B4-BB95-4B74-9D32-4533D566453C}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\VmApplet",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\PerceivedType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControls\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5BE46CE1-CA9B-4CAD-B2E9-8C3F7716AF90}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\PinToNameSpaceTree",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\RelativePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\Safety Warning Level",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7DC691A2-CB15-44DB-853C-19938051BB22}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{28011108-68DF-4C73-B91B-57427D501BBA}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F18ED8A5-C696-4951-B068-CA8E83634C04}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CC35D2E9-B9E1-4ADC-9DA5-71487D9E9EB5}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\CryptnetPreFetchTriggerPeriodSeconds",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BE669C13-8165-4536-96D0-6D6C39292AAE}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Comment",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\Mapping",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\Content Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E3163C33-301D-4730-A266-5518C5ED3967}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsAliasedNotifications",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Max Cached Icons",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Load",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ESENT\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\WinStations\\RDP-Tcp\\InitialProgram",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Data\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsFORDISPLAY",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Cryptography\\PrivKeyCacheMaxItems",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore\\SR\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\AppSetup",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{40DD7C5E-DA67-4A78-B96C-582A4CBAEDF3}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.47.1.1!7\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{551B3807-871F-4E48-A943-2330449F0615}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\DefaultIcon\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\LocalRedirectOnly",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B78DBF96-841E-4336-BFE9-1C4975F9DA60}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\MemUsageTask\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4D19A151-A712-4920-AC6D-6C6FD81C8CDB}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\LoadWithoutCOM",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\PolicyConverter\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip6\\WinSock 2.0 Provider ID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledProcesses\\78ED498",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-18\\Flags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{268014E7-A27E-4FD7-89A6-A481DA222EC8}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{8C5ED038-CFAD-48A0-BB2F-D128286E49B3}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4FDEA3B5-7CDE-48F7-940C-43CDBB18FB20}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\StorageDelegateSuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A8B18D02-60CD-4305-90CC-7DAAC028BDCD}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\AutorunsDisabled",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxUrlRetrievalByteCount",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RegisterSearch\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\WOW64",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Description",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\PerceivedType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableMandatoryBasicConstraints",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0004\\NetCfgInstanceId",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\Mapping",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHPORT\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1BB08CFD-C6AD-44C7-BD0B-8F23035A5731}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DiagMatchAnyMask",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NETFramework\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\MinSockaddrLength",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{17F5B0DE-8DA9-4280-8CB8-91422B9A8CE1}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\WOW64",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Stream",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\AltStartup",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C016366B-7126-46CA-B36B-592A3D95A60B}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\AitAgent\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C016366B-7126-46CA-B36B-592A3D95A60B}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag\\ScheduledDefrag\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HideInWebView",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ini\\PerceivedType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\FolderTypeID",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\system32\\p2pcollab.dll,-8042",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0001\\NetCfgInstanceId",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks\\Id",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC668097-4D6B-4093-AC14-014C09DBF820}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrScheduleTask\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{96137355-BC34-4BA7-81B7-47C87B556E7D}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\IconServiceLib",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0005\\NetCfgInstanceId",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SeparateProcess",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9979CB83-103A-4105-9E5D-C74B0AF6D198}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06CD2154-751E-469F-8E4A-C3F118356423}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B78DBF96-841E-4336-BFE9-1C4975F9DA60}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\97817950D81C9670CC34D809CF794431367EF474\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ehDRMInit\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{72DB7465-BC54-491B-A92A-4637A28C9BBF}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\ChainCacheResyncFiletime",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\InstallPlayReady\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Parameters\\Transports",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\MachineThrottling",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Description",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Video",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\Shell",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Sysinternals\\EulaAccepted",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{82676C49-21A7-4605-AA06-E04A067FB611}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\DefaultIcon\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\StreamResource",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Startup",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\ObjectName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Pictures",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia\\SystemSoundsService\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\Description",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip\\WinSock 2.0 Provider ID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask\\Id",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{40DD7C5E-DA67-4A78-B96C-582A4CBAEDF3}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{96137355-BC34-4BA7-81B7-47C87B556E7D}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\AlwaysShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsUniversalDelegate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ShareCredsWithWinHttp",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Defaults\\Provider\\Microsoft Enhanced RSA and AES Cryptographic Provider\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F6B1AFFE-48F0-4340-9F59-C73DDA17C17D}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCountPerChain",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\Enabled",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Local AppData",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\SafeProcessSearchMode",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk\\Proxy\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\HelperDllName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetCrawling",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\LsaExtensionConfig\\SspiCli\\CheckSignatureRoutine",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FB3C354D-297A-4EB2-9B58-090F6361906B}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\LsaExtensionConfig\\SspiCli\\CheckSignatureDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{8C5ED038-CFAD-48A0-BB2F-D128286E49B3}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SystemDataProviders\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\LoadWithoutCOM",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsParseDisplayName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\WOW64",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{72DB7465-BC54-491B-A92A-4637A28C9BBF}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\WOW64",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\UseDelayedAcceptance",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\UseDelayedAcceptance",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RacTask\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\LocalRedirectOnly",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Music",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\Wds\\rdpwd\\StartupPrograms",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClassicShell",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4DE0CAB9-ECFE-4AA9-B95A-FE815A2EAA4E}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0002\\NetCfgInstanceId",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{994C86AD-A929-4B2C-88A0-4E25A107A029}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\WOW64",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.67.1.1!7\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for SqlServer\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableCANameConstraints",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\UseDropHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp\\DisableBranchCache",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\GlobalSession",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableWeakSignatureFlags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\AlwaysShowExt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9435F817-FED2-454E-88CD-7F78FDA62C48}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{448186F9-75B9-4FB7-A6E0-B19A2BADC1BE}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0008\\NetCfgInstanceId",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7DC691A2-CB15-44DB-853C-19938051BB22}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CDA5F4EE-8293-4A5D-8564-04CD067D1A85}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CDA5F4EE-8293-4A5D-8564-04CD067D1A85}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Serial_Access_Num",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{268014E7-A27E-4FD7-89A6-A481DA222EC8}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\WOW64",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{613612BA-897D-44CE-8DC1-8FC283F9FD51}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCertCount",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection\\NAPStatus UI\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B43033E6-1453-4AD6-AFBA-C03CFC178286}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2E941CB2-1B33-47C4-905B-8B4278819513}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\Flags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\MachineGuid",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CC35D2E9-B9E1-4ADC-9DA5-71487D9E9EB5}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5F5A18EB-DC73-4E45-A11C-B59043598412}\\Actions",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{4E77131D-3629-431C-9818-C5679DC83E81} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\OptinNotification\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\QueryForInfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A7C73732-9F11-4281-8D19-764D4EC9D94D}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4D19A151-A712-4920-AC6D-6C6FD81C8CDB}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\\Blob",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Stream",
        "HKEY_CURRENT_USER\\Environment\\UserInitMprLogonScript",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DiagLevel",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DontShowSuperHidden",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\MaximumAllowedAllocationSize",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InitFolderHandler",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\MaxSockaddrLength",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance\\WinSAT\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\SecurityProviders",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0010\\NetCfgInstanceId",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Startup",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\mcupdate\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Networking\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugFlags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\GadgetManager\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Common Startup",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC668097-4D6B-4093-AC14-014C09DBF820}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Category",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\WOW64",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\DocObject",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{874CFED9-D01D-4D16-9775-B8A7A05004BF}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\WOW64",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlCountInCert",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0000\\NetCfgInstanceId",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{17F5B0DE-8DA9-4280-8CB8-91422B9A8CE1}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsFORPARSING",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{87F56B34-044E-4A48-8FDD-087BFABD5ECF}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC\\HotStart\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\CrawlStartPages\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\RelativePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\RestrictedAttributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{551B3807-871F-4E48-A943-2330449F0615}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI\\LPRemove\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{3307E641-F5EE-49E6-A1FE-BFB5D671441C}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\ObjectName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Taskman",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A48CABBF-24C8-4B87-B00F-9261807C3B43}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxySettingsPerUser",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\MapNetDriveVerbs",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableUnsupportedCriticalExtensions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\\InProcServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates\\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Defaults\\Provider\\Microsoft Enhanced RSA and AES Cryptographic Provider\\Image Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4FDEA3B5-7CDE-48F7-940C-43CDBB18FB20}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0009\\NetCfgInstanceId",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.67.1.2!7\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for Oracle\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DCLocator\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A48CABBF-24C8-4B87-B00F-9261807C3B43}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F6B1AFFE-48F0-4340-9F59-C73DDA17C17D}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A656BBE1-4E3E-4C8A-BD79-A8CA56782753}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2E941CB2-1B33-47C4-905B-8B4278819513}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\Type",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\System32\\fveui.dll,-844",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\System32\\fveui.dll,-843",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D0250F3F-6480-484F-B719-42F659AC64D5}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5A40E926-9E86-4B89-9CFD-B12311724371}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0007\\NetCfgInstanceId",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\WOW64",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location\\Id",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Run",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Security",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\WOW64",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras\\MobilityManager\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\LoadWithoutCOM",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\Flags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A8B18D02-60CD-4305-90CC-7DAAC028BDCD}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0006\\NetCfgInstanceId",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{28011108-68DF-4C73-B91B-57427D501BBA}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MinSockaddrLength",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\BrowseInPlace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\AlwaysShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5A40E926-9E86-4B89-9CFD-B12311724371}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RecordingRestart\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Parameters\\ServiceDll",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\system32\\dnsapi.dll,-103",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\NoFileFolderJunction",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D018DE2F-F02A-4BDB-BA74-56BCD427BE40}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Background Synchronization\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp\\Tracing\\Enabled",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F} {ADD8BA80-002B-11D0-8F0F-00C04FD7D062} 0xFFFF",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BE669C13-8165-4536-96D0-6D6C39292AAE}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\ObjectName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\AlwaysShowExt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RACAgent\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Stream",
        "HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns\\EulaAccepted",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB07F7B4-BB95-4B74-9D32-4533D566453C}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F18ED8A5-C696-4951-B068-CA8E83634C04}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{994C86AD-A929-4B2C-88A0-4E25A107A029}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\TokenSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates\\7D7F4414CCEF168ADF6BF40753B5BECD78375931\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\LocalRedirectOnly",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SafeBoot\\AlternateShell",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkCards\\12\\ServiceName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Description",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURActivate\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\QueryForOverlay",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\AlwaysShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\AutorunsDisabled",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis\\Scheduled\\Id",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ini\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\InitFolderHandler",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Description",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Personal",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{82676C49-21A7-4605-AA06-E04A067FB611}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Start",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadOverride",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Common AltStartup",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B81A55E6-C03C-4EF0-B86F-A80A89DF468D}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURDiscovery\\Id",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Desktop",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CD962721-73F1-4649-85D7-6884C1EF28D9}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing\\State",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\StubPath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{56784854-C6CB-462B-8169-88E350ACB882}",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ini\\Content Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\HelperDllName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParsingName",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System\\ConvertLogEntries\\Id",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\system32\\qagentrt.dll,-10",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\\Blob",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\Flags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\UpdateRecordPath\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\WOW64",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2470470F-2634-478E-B181-571E98A789BB}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1BB08CFD-C6AD-44C7-BD0B-8F23035A5731}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BattC\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0011\\NetCfgInstanceId",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\IsShortcut",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0011\\MatchingDeviceId",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Attributes",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9979CB83-103A-4105-9E5D-C74B0AF6D198}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\AutoWake\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscovery\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\inetaccs\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adsi\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{874CFED9-D01D-4D16-9775-B8A7A05004BF}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5BE46CE1-CA9B-4CAD-B2E9-8C3F7716AF90}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Category",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalByteCount",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B43033E6-1453-4AD6-AFBA-C03CFC178286}\\Path",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Cryptography\\PrivateKeyLifetimeSeconds",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06CD2154-751E-469F-8E4A-C3F118356423}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Stream",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CD962721-73F1-4649-85D7-6884C1EF28D9}\\Actions",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\ImagePath",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E3163C33-301D-4730-A266-5518C5ED3967}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableInetUnknownAuth",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\SuppressionPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)\\Id",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\ShellComponent",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry\\RegIdleBackup\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HasNavigationEnum",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}\\Actions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\Type",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9435F817-FED2-454E-88CD-7F78FDA62C48}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{613612BA-897D-44CE-8DC1-8FC283F9FD51}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Parameters\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\\InProcServer32\\LoadWithoutCOM",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Security",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6}\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSimpleStartMenu",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\ObjectName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Start",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\ImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector\\Id",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ServiceDll",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Start",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\StubPath",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\Description"
    ],
    "directory_created": [
        "C:\\Windows\\System32\\catroot2",
        "C:\\Windows\\System32\\catroot",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc",
        "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf"
    ]
}

Dropped

[
    {
        "yara": [],
        "sha1": "e685d8b955cff4d4e74c948df638202a14a07fbc",
        "name": "bea5da8b6487dac6_autorunsc64.exe",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
        "type": "PE32+ executable (console) x86-64, for MS Windows",
        "sha256": "700909607974e22e1de20018a28ad11d090f09f9f5d85404caa9048e73552d47",
        "urls": [
            "http:\/\/www.microsoft.com\/exporting"
        ],
        "crc32": "DA11C829",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/7635\/files\/bea5da8b6487dac6_autorunsc64.exe",
        "ssdeep": null,
        "size": 600060,
        "sha512": "17622d4e9fc6490228fcd80af2c25291a17094bcd46d6a58521b82bd3b0343e63b7d9459a60f7a04db393b152b7df9fce4db5cbc60e9559836d52f8f3cd184af",
        "pids": [
            1268
        ],
        "md5": "dc634bbd7d0eb8a6dce71d4123cad424"
    },
    {
        "yara": [],
        "sha1": "c64ad224b877cd5bbdcdb1799b71f3682602d231",
        "name": "b0a39e28d93f7822_TarD41D.tmp",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
        "type": "data",
        "sha256": "b0a39e28d93f7822fe6cac1e082c7adc581dcd2b61eb9f536e74bd14a75b27bc",
        "urls": [
            "http:\/\/www.microsoft.com\/pkiops\/certs\/Microsoft%20Certificate%20Trust%20List%20PCA(3).crt0",
            "http:\/\/www.microsoft.com\/pki\/certs\/MicRooCerAut_2010-06-23.crt07",
            "http:\/\/www.microsoft.com\/pki\/certs\/MicCerLisCA2011_2011-03-29.crt0",
            "http:\/\/www.microsoft.com\/pki\/certs\/MicrosoftRootCert.crt0",
            "http:\/\/www.microsoft.com\/pkiops\/crl\/Microsoft%20Certificate%20Trust%20List%20PCA(3).crl0u"
        ],
        "crc32": "B495BE07",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/7635\/files\/b0a39e28d93f7822_TarD41D.tmp",
        "ssdeep": null,
        "size": 138525,
        "sha512": "0663fb22bcefd0ac5f090104322a8c0dc1ceb77a168b589d7dbb9a74d109daf38beac97dab715220abab08c355496f5719159e17995248caa19eff45bc2a5d46",
        "pids": [
            2096
        ],
        "md5": "0e34ebf89b843b303f0fb5f194be9d28"
    },
    {
        "yara": [],
        "sha1": "cf925fc512b936fe7d44ceb6e999e4a020ed6ff0",
        "name": "4c9c4d831d61c8c3_CabD41C.tmp",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
        "type": "Microsoft Cabinet archive data, 56952 bytes, 1 file",
        "sha256": "4c9c4d831d61c8c38b2513f9b431ef4f4cf6af9fb18a2317cd2178d6e0997822",
        "urls": [],
        "crc32": "5168F337",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/7635\/files\/4c9c4d831d61c8c3_CabD41C.tmp",
        "ssdeep": null,
        "size": 56952,
        "sha512": "65dc435f6d3e1afd347ba1617a3eee59c6660f221faa36456a09e307d434d7276e8095e8aa34d59933e685a9f84564ec783e59ae9658791f7ebdbbc2eda32f7a",
        "pids": [
            2096
        ],
        "md5": "04d79a0dc77a8f449cbff6252862d398"
    },
    {
        "yara": [],
        "sha1": "556da65e88aadbfab90c518d9a52acbe4fd2b0e0",
        "name": "53e2e246655679e4_xggbwk",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
        "type": "Microsoft Cabinet archive data, 331565 bytes, 1 file",
        "sha256": "53e2e246655679e4629237a11b4a079cc30eca0f2843b160aa45330813430702",
        "urls": [],
        "crc32": "895CFD7E",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/7635\/files\/53e2e246655679e4_xggbwk",
        "ssdeep": null,
        "size": 331565,
        "sha512": "29c86685ca018ade365c7e47321b1b0cc873e666375c8ef9164c65424f5b1d2b3461330115f844582d12416a8ea55b81db3dfab3e64c063bd3fd78123c0f1f7c",
        "pids": [
            1268
        ],
        "md5": "115004a462a913f1033cdf317a519c93"
    }
]

Generic

[
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
        "process_name": "autorunsc64.exe",
        "pid": 144,
        "summary": {
            "regkey_written": [
                "HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns\\EulaAccepted"
            ],
            "dll_loaded": [
                "kernel32",
                "API-MS-Win-Security-LSALookup-L1-1-0.dll",
                "apphelp.dll",
                "api-ms-win-core-localization-l1-2-1",
                "kernel32.dll",
                "api-ms-win-core-synch-l1-2-0",
                "ntmarta.dll",
                "API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
                "ole32.dll",
                "API-MS-Win-Security-SDDL-L1-1-0.dll",
                "C:\\Windows\\system32\\Wintrust.dll",
                "WindowsCodecs.dll",
                "OLEAUT32.dll",
                "profapi.dll",
                "SHELL32.dll",
                "comctl32.dll",
                "C:\\Windows\\system32\\advapi32.dll",
                "api-ms-win-core-fibers-l1-1-1",
                "C:\\Windows\\system32\\crypt32.dll",
                "C:\\Windows\\system32\\Kernel32.dll",
                "ADVAPI32.dll",
                "SETUPAPI.dll"
            ],
            "file_opened": [
                "C:\\Windows\\System32\\imageres.dll",
                "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727",
                "C:\\",
                "C:\\Windows\\System32\\",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db",
                "C:\\Windows\\System32\\dllhost.exe",
                "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe",
                "C:\\Windows\\System32\\EhStorShell.dll",
                "C:\\Windows\\System32\\lsass.exe",
                "C:\\Windows\\System32\\cscui.dll",
                "C:\\Windows\\ehome\\ehrecvr.exe",
                "C:\\Windows\\System32",
                "c:\\Windows\\System32\\imageres.dll",
                "C:\\Windows\\",
                "C:\\Windows\\Microsoft.NET\\Framework64\\",
                "C:\\Windows\\ehome\\ehsched.exe",
                "C:\\Windows\\Microsoft.Net\\Framework64\\",
                "C:\\Windows\\Microsoft.NET",
                "C:\\Windows\\ehome\\",
                "C:\\Windows\\Microsoft.Net\\Framework64\\v3.0\\",
                "C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\WPF\\PresentationFontCache.exe",
                "C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation",
                "C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\infocard.exe",
                "C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\WPF",
                "C:\\Users\\cuck\\Desktop\\desktop.ini",
                "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727",
                "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\",
                "C:\\Windows\\System32\\svchost.exe",
                "C:\\Windows\\System32\\ntshrui.dll",
                "C:\\Windows\\ehome",
                "C:\\Windows\\System32\\FXSSVC.exe",
                "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
                "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\",
                "C:\\Windows\\Microsoft.NET\\Framework64\\v3.0",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db",
                "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe",
                "C:\\Windows\\Microsoft.NET\\Framework",
                "C:\\Windows\\System32\\alg.exe",
                "C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\",
                "C:\\Windows",
                "C:\\Windows\\Microsoft.NET\\Framework64"
            ],
            "regkey_opened": [
                "HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance\\Disabled",
                "HKEY_LOCAL_MACHINE\\Software\\Sysinternals",
                "HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns",
                "HKEY_CURRENT_USER\\Software\\Sysinternals",
                "HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance"
            ],
            "file_exists": [
                "C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted",
                "C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted.dll",
                "C:\\Windows\\System32\\bdesvc.dll",
                "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe",
                "C:\\Windows\\ehome\\ehrecvr.exe",
                "C:\\Windows\\System32\\svchost.exe -k netsvcs.dll",
                "C:\\Windows\\System32\\aelupsvc.dll",
                "C:\\Windows\\System32\\svchost.exe -k bthsvcs.dll",
                "C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation.exe",
                "C:\\Windows\\System32\\BFE.DLL",
                "C:\\Windows\\System32\\svchost.exe -k netsvcs",
                "C:\\Windows\\System32\\FntCache.dll",
                "C:\\Windows\\System32\\svchost.exe -k LocalService",
                "C:\\Windows\\System32\\audiosrv.dll",
                "C:\\Windows\\System32\\svchost.exe -k.dll",
                "C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted.exe",
                "C:\\Windows\\System32\\svchost.exe -k bthsvcs",
                "C:\\Windows\\System32\\KMSVC.DLL",
                "C:\\Windows\\System32\\svchost.exe -k bthsvcs.exe",
                "C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation.dll",
                "C:\\Windows\\System32\\svchost.exe -k NetworkService.exe",
                "C:\\Windows\\System32\\qmgr.dll",
                "C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup.dll",
                "C:\\Windows\\System32\\defragsvc.dll",
                "C:\\Windows\\System32\\svchost.exe -k NetworkService",
                "C:\\Windows\\System32\\cscsvc.dll",
                "C:\\Windows\\System32\\svchost.exe -k LocalService.dll",
                "C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation.dll",
                "C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation.exe",
                "C:\\Windows\\System32\\appidsvc.dll",
                "C:\\Windows\\System32\\appmgmts.dll",
                "C:\\Windows\\Microsoft.Net\\Framework64\\v3.0\\WPF\\PresentationFontCache.exe",
                "C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork.com",
                "C:\\Windows\\System32\\svchost.exe -k NetSvcs.dll",
                "C:\\Windows\\System32\\es.dll",
                "C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation",
                "C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup.exe",
                "C:\\Windows\\System32\\svchost.exe -k NetSvcs",
                "C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation.com",
                "C:\\Windows\\System32\\certprop.dll",
                "C:\\Windows\\System32\\lsass.exe",
                "C:\\Windows\\System32\\wevtsvc.dll",
                "C:\\Windows\\System32\\svchost.exe -k NetworkService.dll",
                "C:\\Windows\\System32\\svchost.exe -k.exe",
                "C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup",
                "C:\\Windows\\System32\\fdPHost.dll",
                "C:\\Windows\\System32\\svchost.exe -k DcomLaunch.com",
                "C:\\Windows\\System32\\cryptsvc.dll",
                "C:\\Windows\\System32\\svchost.exe -k netsvcs.exe",
                "C:\\Windows\\System32\\svchost.exe -k defragsvc",
                "C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted",
                "C:\\Windows\\System32\\dllhost.exe",
                "C:\\Windows\\System32\\dot3svc.dll",
                "C:\\Windows\\System32\\svchost.exe -k NetworkService.com",
                "C:\\Windows\\System32\\dhcpcore.dll",
                "C:\\Windows\\System32\\gpsvc.dll",
                "C:\\Windows\\System32\\svchost.exe -k DcomLaunch.dll",
                "C:\\Windows\\System32\\svchost.exe -k bthsvcs.com",
                "C:\\Windows\\System32\\provsvc.dll",
                "C:\\Windows\\ehome\\ehsched.exe",
                "C:\\Windows\\System32\\FDResPub.dll",
                "C:\\Windows\\System32\\svchost.exe -k defragsvc.com",
                "C:\\Windows\\System32\\svchost.exe -k.com",
                "C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted.com",
                "C:\\Windows\\System32\\rpcss.dll",
                "C:\\Windows\\System32\\hidserv.dll",
                "C:\\Windows\\System32\\svchost.exe -k defragsvc.exe",
                "C:\\Windows\\System32\\svchost.exe",
                "C:\\Windows\\System32\\svchost.exe -k LocalServiceNetworkRestricted.dll",
                "C:\\Windows\\System32\\svchost.exe -k netsvcs.com",
                "C:\\Windows\\System32\\svchost.exe -k AxInstSVGroup.com",
                "C:\\Windows\\System32\\svchost.exe -k NetworkServiceAndNoImpersonation.com",
                "C:\\Windows\\System32\\FXSSVC.exe",
                "C:\\Windows\\System32\\bthserv.dll",
                "C:\\Windows\\System32\\iphlpsvc.dll",
                "C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted.exe",
                "C:\\Windows\\System32\\IKEEXT.DLL",
                "C:\\Windows\\System32\\dnsrslvr.dll",
                "C:\\Windows\\System32\\svchost.exe -k NetSvcs.exe",
                "C:\\Windows\\System32\\ListSvc.dll",
                "C:\\Windows\\System32\\eapsvc.dll",
                "C:\\Windows\\System32\\ipbusenum.dll",
                "C:\\Windows\\System32\\svchost.exe -k LocalService.exe",
                "C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted.com",
                "C:\\Windows\\System32\\appinfo.dll",
                "C:\\Windows\\System32\\alg.exe",
                "C:\\Windows\\System32\\svchost.exe -k LocalService.com",
                "C:\\Windows\\System32\\svchost.exe -k LocalServiceAndNoImpersonation",
                "C:\\Windows\\System32\\svchost.exe -k defragsvc.dll",
                "C:\\Windows\\System32\\svchost.exe -k DcomLaunch.exe",
                "C:\\Windows\\System32\\browser.dll",
                "C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork.dll",
                "C:\\Windows\\System32\\AxInstSv.dll",
                "C:\\Windows\\System32\\svchost.exe -k NetSvcs.com",
                "C:\\Windows\\System32\\msdtckrm.dll",
                "C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork",
                "C:\\Windows\\System32\\svchost.exe -k DcomLaunch",
                "C:\\Windows\\System32\\svchost.exe -k LocalServiceNoNetwork.exe",
                "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe",
                "C:\\Windows\\Microsoft.NET\\Framework64\\v3.0\\Windows Communication Foundation\\infocard.exe",
                "C:\\Windows\\System32\\dps.dll",
                "C:\\Windows\\System32\\svchost.exe -k"
            ],
            "guid": [
                "{08244ee6-92f0-47f2-9fc9-929baa2e7235}",
                "{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
                "{4e77131d-3629-431c-9818-c5679dc83e81}",
                "{d9144dcd-e998-4eca-ab6a-dcd83ccba16d}",
                "{0c6c4200-c589-11d0-999a-00c04fd655e1}",
                "{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}"
            ],
            "file_read": [
                "C:\\Users\\cuck\\Desktop\\desktop.ini"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NETFramework\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NeverShowExt",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Start",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\WOW64",
                "HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns\\EulaAccepted",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\LoadWithoutCOM",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\Content Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\Flags",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ServiceDll",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Start",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Start",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Type",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{4E77131D-3629-431C-9818-C5679DC83E81} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\NeverShowExt",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SeparateProcess",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoWebView",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\FolderTypeID",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Start",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for Oracle\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Networking\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Parameters\\ServiceDll",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Desktop",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\AutorunsDisabled",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Start",
                "HKEY_CURRENT_USER\\Software\\Sysinternals\\EulaAccepted",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Category",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\DocObject",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Parameters\\ServiceDll",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DefaultIcon\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalRedirectOnly",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\WOW64",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ServiceDll",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Name",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Type",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ServiceDll",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalRedirectOnly",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\Flags",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DontShowSuperHidden",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\PerceivedType",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\WOW64",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\SafeProcessSearchMode",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\WOW64",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetCrawling",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Icon",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Icon",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Max Cached Icons",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BattC\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\WOW64",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ESENT\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DCLocator\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET CLR Data\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fs_Rec\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\LoadWithoutCOM",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Type",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\WOW64",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Security",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\WOW64",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\WOW64",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\inetaccs\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\DefaultIcon\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Stream",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\LoadWithoutCOM",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\Flags",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClassicShell",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\Content Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\WOW64",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Start",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Start",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-18\\Flags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\.NET Data Provider for SqlServer\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Security",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Icon",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\AutorunsDisabled",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\WOW64",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adsi\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Parameters\\ServiceDll",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\PerceivedType",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\WOW64",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSimpleStartMenu",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Stream",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHPORT\\Start"
            ],
            "directory_created": [
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches"
            ]
        },
        "first_seen": 1589777684.999374,
        "ppid": 1268
    },
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe",
        "process_name": "autorunsc64.exe",
        "pid": 2716,
        "summary": {
            "regkey_written": [
                "HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns\\EulaAccepted"
            ],
            "dll_loaded": [
                "kernel32",
                "API-MS-Win-Security-LSALookup-L1-1-0.dll",
                "apphelp.dll",
                "api-ms-win-core-localization-l1-2-1",
                "kernel32.dll",
                "api-ms-win-core-synch-l1-2-0",
                "ntmarta.dll",
                "API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
                "ole32.dll",
                "API-MS-Win-Security-SDDL-L1-1-0.dll",
                "C:\\Windows\\system32\\Wintrust.dll",
                "WindowsCodecs.dll",
                "OLEAUT32.dll",
                "profapi.dll",
                "SHELL32.dll",
                "comctl32.dll",
                "C:\\Windows\\system32\\advapi32.dll",
                "api-ms-win-core-fibers-l1-1-1",
                "C:\\Windows\\system32\\crypt32.dll",
                "C:\\Windows\\system32\\Kernel32.dll",
                "ADVAPI32.dll",
                "SETUPAPI.dll"
            ],
            "file_opened": [
                "C:\\Windows\\System32\\ntshrui.dll",
                "c:\\Windows\\System32\\imageres.dll",
                "C:\\Users\\cuck\\Desktop\\desktop.ini",
                "C:\\Windows\\",
                "C:\\",
                "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db",
                "c:\\Windows\\System32\\userinit.exe",
                "C:\\Windows\\System32\\",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db",
                "C:\\Windows\\System32\\cscui.dll",
                "C:\\Windows",
                "c:\\Windows\\System32\\rdpclip.exe",
                "C:\\Windows\\System32\\EhStorShell.dll",
                "C:\\Windows\\System32\\rdpclip.exe",
                "C:\\Windows\\System32\\userinit.exe",
                "C:\\Windows\\System32"
            ],
            "regkey_opened": [
                "HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance\\Disabled",
                "HKEY_LOCAL_MACHINE\\Software\\Sysinternals",
                "HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns",
                "HKEY_CURRENT_USER\\Software\\Sysinternals",
                "HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance"
            ],
            "file_exists": [
                "C:\\Windows\\System32\\rdpclip.com",
                "C:\\Windows\\rdpclip.com",
                "C:\\Python27\\Scripts\\rdpclip.exe",
                "C:\\Python27\\Scripts\\rdpclip",
                "C:\\Python27\\rdpclip.exe",
                "C:\\Python27\\rdpclip.com",
                "C:\\Python27\\rdpclip",
                "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\rdpclip",
                "C:\\Windows\\System32\\wbem\\rdpclip.com",
                "C:\\Windows\\System32\\wbem\\rdpclip",
                "C:\\Windows\\rdpclip",
                "C:\\Windows\\System32\\userinit.exe",
                "C:\\Python27\\Scripts\\rdpclip.com",
                "C:\\Windows\\System32\\rdpclip.exe",
                "C:\\Windows\\System32\\rdpclip",
                "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\rdpclip.com"
            ],
            "guid": [
                "{08244ee6-92f0-47f2-9fc9-929baa2e7235}",
                "{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
                "{4e77131d-3629-431c-9818-c5679dc83e81}",
                "{d9144dcd-e998-4eca-ab6a-dcd83ccba16d}",
                "{0c6c4200-c589-11d0-999a-00c04fd655e1}",
                "{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}"
            ],
            "file_read": [
                "C:\\Users\\cuck\\Desktop\\desktop.ini"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InfoTip",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\Flags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalizedName",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\LoadWithoutCOM",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\LoadWithoutCOM",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DontShowSuperHidden",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\Flags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns\\EulaAccepted",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\Wds\\rdpwd\\StartupPrograms",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClassicShell",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\Content Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\Flags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Roamable",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\FolderTypeID",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResourceType",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-18\\Flags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResourceType",
                "HKEY_CURRENT_USER\\Software\\Sysinternals\\EulaAccepted",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DefaultIcon\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetCrawling",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Attributes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Description",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Desktop",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\SuppressionPolicy",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\LoadWithoutCOM",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Icon",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\SafeProcessSearchMode",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Max Cached Icons",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{4E77131D-3629-431C-9818-C5679DC83E81} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Description",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Description",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\AlwaysShowExt",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SeparateProcess",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\AlwaysShowExt",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\AppSetup",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSimpleStartMenu",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoWebView",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\FolderTypeID"
            ],
            "directory_created": [
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches"
            ]
        },
        "first_seen": 1589777702.733751,
        "ppid": 1268
    },
    {
        "process_path": "C:\\Windows\\System32\\lsass.exe",
        "process_name": "lsass.exe",
        "pid": 476,
        "summary": {},
        "first_seen": 1589777586.359375,
        "ppid": 376
    },
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
        "process_name": "6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
        "pid": 1268,
        "summary": {
            "file_created": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe"
            ],
            "directory_created": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf"
            ],
            "dll_loaded": [
                "kernel32",
                "api-ms-win-core-fibers-l1-1-1",
                "api-ms-win-core-localization-l1-2-1",
                "kernel32.dll",
                "DEVRTL.dll",
                "advapi32",
                "Cabinet.dll",
                "api-ms-win-core-synch-l1-2-0"
            ],
            "file_opened": [
                "",
                "C:\\Windows\\System32\\drivers\\amdk8.sys",
                "C:\\Program Files\\Windows Media Player\\wmpnetwk.exe",
                "C:\\Python27\\python.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RegisterSearch",
                "C:\\Windows\\System32\\drivers\\ndisuio.sys",
                "C:\\Windows\\System32\\drivers\\monitor.sys",
                "C:\\Windows\\System32\\drivers\\WUDFPf.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
                "C:\\Windows\\System32\\aepdu.dll",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
                "C:\\Windows\\System32\\drivers\\blbdrive.sys",
                "C:\\Windows\\System32\\clfs.sys",
                "C:\\Windows\\System32\\drivers\\netbios.sys",
                "C:\\Windows\\System32\\drivers\\mstee.sys",
                "C:\\Windows\\System32\\drivers\\hidir.sys",
                "C:\\Windows\\System32\\drivers\\rasl2tp.sys",
                "C:\\Windows\\System32\\drivers\\srvnet.sys",
                "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
                "C:\\Windows\\System32\\drivers\\asyncmac.sys",
                "C:\\Windows\\System32\\drivers\\flpydisk.sys",
                "C:\\Windows\\System32\\drivers\\lsi_sas2.sys",
                "C:\\Windows\\System32\\drivers\\mrxdav.sys",
                "C:\\Windows\\System32\\drivers\\mountmgr.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
                "C:\\Windows\\System32\\drivers\\rdyboost.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MobilePC\\HotStart",
                "C:\\Windows\\System32\\drivers\\wacompen.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MUI\\LPRemove",
                "C:\\Windows\\System32\\drivers\\circlass.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
                "C:\\Windows\\System32\\drivers\\CompositeBus.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
                "C:\\Windows\\System32\\drivers\\fdc.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SystemRestore\\SR",
                "C:\\Windows\\System32\\drivers\\bthmodem.sys",
                "C:\\Windows\\System32\\drivers\\compbatt.sys",
                "C:\\Windows\\System32\\drivers\\RDPCDD.sys",
                "C:\\Windows\\System32\\drivers\\filetrace.sys",
                "C:\\Windows\\System32\\mctadmin.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Location\\Notifications",
                "C:\\Windows\\System32\\drivers\\BrUsbSer.sys",
                "C:\\Windows\\System32\\drivers\\vdrvroot.sys",
                "C:\\Windows\\System32\\drivers\\stexstor.sys",
                "C:\\Windows\\System32\\drivers\\BrFiltUp.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
                "C:\\Windows\\System32\\drivers\\mshidkmdf.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\AitAgent",
                "C:\\Windows\\System32\\drivers\\TsUsbGD.sys",
                "C:\\Windows\\System32\\drivers\\HpSAMD.sys",
                "C:\\Windows\\System32\\drivers\\E1G6032E.sys",
                "C:\\Windows\\System32\\drivers\\msdsm.sys",
                "C:\\Windows\\System32\\drivers\\lltdio.sys",
                "C:\\Windows\\System32\\drivers\\vhdmp.sys",
                "C:\\Windows\\System32\\drivers\\usbuhci.sys",
                "C:\\Windows\\System32\\drivers\\pciide.sys",
                "C:\\Windows\\System32\\dwm.exe",
                "C:\\Windows\\System32\\drivers\\rassstp.sys",
                "C:\\Windows\\System32\\drivers\\IPMIDrv.sys",
                "C:\\Windows\\System32\\raserver.exe",
                "C:\\Windows\\System32\\drivers\\ndis.sys",
                "C:\\tmpyzbctd\\",
                "C:\\Windows\\System32\\drivers\\tunnel.sys",
                "C:\\Windows\\System32\\drivers\\hwpolicy.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
                "C:\\Windows\\System32\\drivers\\sisraid4.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Ras\\MobilityManager",
                "C:\\Windows\\System32\\drivers\\ndiscap.sys",
                "C:\\Program Files\\Windows Media Player\\",
                "C:\\Windows\\System32\\drivers\\umpass.sys",
                "C:\\Windows\\System32\\drivers\\bowser.sys",
                "C:\\Windows\\System32\\drivers\\partmgr.sys",
                "C:\\Windows\\System32\\drivers\\iaStorV.sys",
                "C:\\Windows\\System32\\drivers\\usbccgp.sys",
                "C:\\Windows\\System32\\cmd.exe",
                "C:\\Windows\\System32\\drivers\\sffp_sd.sys",
                "C:\\Windows\\System32\\drivers\\volsnap.sys",
                "C:\\Windows\\ehome\\mcupdate.exe",
                "C:\\Windows\\System32\\drivers\\mpsdrv.sys",
                "C:\\Windows\\System32\\drivers\\wmiacpi.sys",
                "C:\\Windows\\System32\\drivers\\MegaSR.sys",
                "C:\\Windows\\System32\\drivers\\adpu320.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Task Manager\\Interactive",
                "C:\\Windows\\System32\\drivers\\cdrom.sys",
                "C:\\Windows\\System32\\drivers\\BrFiltLo.sys",
                "C:\\Users\\cuck\\AppData\\Local\\",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
                "C:\\Windows\\System32\\drivers\\pcw.sys",
                "C:\\Windows\\System32\\Defrag.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Registry\\RegIdleBackup",
                "C:\\Windows\\System32\\drivers\\megasas.sys",
                "C:\\Windows\\System32\\drivers\\modem.sys",
                "C:\\Windows\\System32\\drivers\\adp94xx.sys",
                "C:\\Windows\\System32\\drivers\\iirsp.sys",
                "C:\\Windows\\System32\\drivers\\rspndr.sys",
                "C:\\Windows\\System32\\drivers\\hdaudbus.sys",
                "C:\\Windows\\System32\\drivers\\vga.sys",
                "C:\\",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
                "C:\\Windows\\System32\\drivers\\wanarp.sys",
                "C:\\Windows\\System32\\drivers\\dmvsc.sys",
                "C:\\Windows\\System32\\drivers\\FsDepends.sys",
                "C:\\Windows\\System32\\conhost.exe",
                "C:\\Windows\\System32\\drivers\\sisraid2.sys",
                "C:\\Windows\\System32\\appidpolicyconverter.exe",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
                "C:\\Windows\\System32\\drivers\\ULIAGPKX.SYS",
                "C:\\Windows\\System32\\drivers\\rasacd.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Maintenance\\WinSAT",
                "C:\\Windows\\System32\\drivers\\hcw85cir.sys",
                "C:\\Windows\\System32\\drivers\\VMBusHID.sys",
                "C:\\Windows\\System32\\drivers\\intelide.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RAC\\RacTask",
                "C:\\Windows\\System32\\drivers\\vmstorfl.sys",
                "C:\\Windows\\System32\\drivers\\ipfltdrv.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
                "C:\\Windows\\System32\\drivers\\HdAudio.sys",
                "C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe",
                "C:\\Windows\\System32\\drivers\\srv.sys",
                "C:\\Windows\\System32\\drivers\\msiscsi.sys",
                "C:\\Windows\\System32\\drivers\\CmBatt.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
                "C:\\Windows\\System32\\drivers\\bxvbda.sys",
                "C:\\Windows\\System32\\drivers\\vwifibus.sys",
                "C:\\Windows\\System32\\drivers\\drmkaud.sys",
                "C:\\Windows\\System32\\drivers\\fvevol.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
                "C:\\Windows\\System32\\ndfapi.dll",
                "C:\\Windows\\System32\\drivers\\ksthunk.sys",
                "C:\\Windows\\System32\\drivers\\ipnat.sys",
                "C:\\Windows\\System32\\drivers\\kbdhid.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
                "C:\\Windows\\System32\\drivers\\disk.sys",
                "C:\\Windows\\System32\\lpremove.exe",
                "C:\\Windows\\System32\\lsass.exe",
                "C:\\Windows\\System32\\drivers\\kbdclass.sys",
                "C:\\Windows\\System32\\drivers\\fltMgr.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
                "C:\\Windows\\System32\\drivers\\smb.sys",
                "C:\\Windows\\System32\\drivers\\isapnp.sys",
                "C:\\Windows\\System32\\drivers\\amdsbs.sys",
                "C:\\Windows\\System32\\lsm.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Autochk\\Proxy",
                "C:\\Windows\\System32\\drivers\\usbcir.sys",
                "C:\\Windows\\System32\\drivers\\vmbus.sys",
                "C:\\Windows\\System32\\drivers\\tdpipe.sys",
                "C:\\Windows\\System32\\drivers\\appid.sys",
                "C:\\Windows\\System32\\drivers\\cng.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
                "C:\\Windows\\System32\\drivers\\afd.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
                "C:\\Windows\\System32\\drivers\\tcpip.sys",
                "C:\\Windows\\System32\\services.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
                "C:\\Windows\\System32\\drivers\\BrSerWdm.sys",
                "C:\\Windows\\System32\\drivers\\ndiswan.sys",
                "C:\\Windows\\System32\\drivers\\serial.sys",
                "C:\\Windows\\System32\\drivers\\lsi_sas.sys",
                "C:\\Windows\\System32\\DFDWiz.exe",
                "C:\\Windows\\System32\\drivers\\dxgkrnl.sys",
                "C:\\Windows\\System32\\dfdts.dll",
                "C:\\Windows\\System32\\drivers\\nvstor.sys",
                "C:\\Windows\\System32\\LocationNotifications.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WDI\\ResolutionHost",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ehDRMInit",
                "C:\\Windows\\System32\\drivers\\csc.sys",
                "C:\\Windows\\System32\\drivers\\i8042prt.sys",
                "C:\\Windows\\System32\\gatherNetworkInfo.vbs",
                "C:\\Windows\\System32\\drivers\\parport.sys",
                "C:\\Windows\\System32\\drivers\\nfrd960.sys",
                "C:\\Windows\\System32\\drivers\\msahci.sys",
                "C:\\Program Files\\Windows Media Player\\wmpnscfg.exe",
                "C:\\Windows\\System32\\winlogon.exe",
                "C:\\Windows\\System32\\drivers\\sfloppy.sys",
                "C:\\Windows\\System32\\drivers\\RDPENCDD.sys",
                "C:\\Windows\\System32\\drivers\\nwifi.sys",
                "C:\\Windows\\System32\\drivers\\ws2ifsl.sys",
                "C:\\Windows\\System32\\drivers\\PEAuth.sys",
                "C:\\Windows\\System32\\drivers\\NV_AGP.SYS",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
                "C:\\Windows\\System32\\drivers\\rdpdr.sys",
                "C:\\Windows\\System32\\drivers\\elxstor.sys",
                "C:\\Windows\\System32\\drivers\\hidusb.sys",
                "C:\\Windows\\System32\\drivers\\ql40xx.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
                "C:\\Windows\\System32\\",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
                "C:\\Windows\\System32\\drivers\\amdxata.sys",
                "C:\\Windows\\System32\\drivers\\usbhub.sys",
                "C:\\Windows\\System32\\wininit.exe",
                "C:\\Windows\\System32\\drivers\\vms3cap.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
                "C:\\Windows\\System32\\drivers\\nsiproxy.sys",
                "C:\\Windows\\System32\\drivers\\mup.sys",
                "C:\\Windows\\System32\\BFE.DLL",
                "C:\\Windows\\explorer.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
                "C:\\Windows\\System32\\drivers\\netbt.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
                "C:\\Windows\\System32\\drivers\\atapi.sys",
                "C:\\Windows\\System32\\drivers\\storvsc.sys",
                "C:\\Windows\\System32\\drivers\\fileinfo.sys",
                "C:\\Windows\\System32\\drivers\\wd.sys",
                "C:\\Windows\\System32\\drivers\\RDPREFMP.sys",
                "C:\\Windows\\System32\\drivers\\pacer.sys",
                "C:\\Windows\\System32\\drivers\\dfsc.sys",
                "C:\\Windows\\System32\\drivers\\mrxsmb10.sys",
                "C:\\Windows\\System32\\drivers\\mrxsmb20.sys",
                "C:\\Windows\\System32\\appidcertstorecheck.exe",
                "C:\\Windows\\System32\\drivers\\pci.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
                "C:\\Windows\\System32\\drivers\\b57nd60a.sys",
                "C:\\Windows\\System32\\drivers\\wimmount.sys",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
                "C:\\Windows\\System32\\drivers\\TsUsbFlt.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
                "C:\\Windows\\System32\\drivers\\acpi.sys",
                "C:\\Windows\\System32\\drivers\\udfs.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\AutoWake",
                "C:\\Windows\\System32\\drivers\\raspppoe.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
                "C:\\Windows\\System32\\drivers\\hidbth.sys",
                "C:\\Windows\\System32\\drivers\\irenum.sys",
                "C:\\Windows\\System32\\drivers\\srv2.sys",
                "C:\\Windows\\System32\\SearchIndexer.exe",
                "C:\\Windows\\System32\\drivers\\serenum.sys",
                "C:\\Windows\\System32\\drivers\\intelppm.sys",
                "C:\\Windows\\System32\\drivers\\mskssrv.sys",
                "C:\\Windows\\System32\\drivers\\mssmbios.sys",
                "C:\\Windows\\System32\\drivers\\BrSerId.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
                "C:\\Users\\",
                "C:\\Windows\\System32\\drivers\\agilevpn.sys",
                "C:\\Windows\\System32\\drivers\\usbohci.sys",
                "C:\\Windows\\System32\\drivers\\vsmraid.sys",
                "C:\\Windows\\System32\\drivers\\amdppm.sys",
                "C:\\Windows\\System32\\drivers\\pcmcia.sys",
                "C:\\Windows\\System32\\svchost.exe",
                "C:\\Windows\\System32\\spoolsv.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SessionAgent",
                "C:\\Windows\\System32\\drivers\\mspqm.sys",
                "C:\\Windows\\System32\\drivers\\msisadrv.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
                "C:\\Users\\cuck\\AppData\\",
                "C:\\Windows\\System32\\drivers\\nvraid.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
                "C:\\Windows\\ehome\\ehPrivJob.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
                "C:\\Windows\\System32\\drivers\\mouclass.sys",
                "C:\\Windows\\System32\\drivers\\vgapnp.sys",
                "C:\\Windows\\System32\\drivers\\volmgrx.sys",
                "C:\\Windows\\System32\\drivers\\arcsas.sys",
                "C:\\Windows\\System32\\drivers\\amdide.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
                "C:\\Windows\\System32\\powercfg.exe",
                "C:\\Windows\\System32\\drivers\\termdd.sys",
                "C:\\Windows\\System32\\drivers\\swenum.sys",
                "C:\\Windows\\System32\\taskhost.exe",
                "C:\\Windows\\System32\\drivers\\luafv.sys",
                "C:\\Windows\\System32\\drivers\\tdx.sys",
                "C:\\Windows\\System32\\drivers\\cmdide.sys",
                "C:\\Windows\\System32\\drivers\\sbp2port.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\PolicyConverter",
                "C:\\Windows\\System32\\drivers\\hidbatt.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
                "C:\\Windows\\System32\\drivers\\lsi_fc.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
                "C:\\Windows\\System32\\drivers\\ksecpkg.sys",
                "C:\\Windows\\System32\\drivers\\USBSTOR.SYS",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURActivate",
                "C:\\Windows\\System32\\drivers\\tssecsrv.sys",
                "C:\\Windows\\System32\\drivers\\ndistapi.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Diagnosis\\Scheduled",
                "C:\\Windows\\System32\\drivers\\Wdf01000.sys",
                "C:\\Windows\\System32\\drivers\\discache.sys",
                "C:\\Windows\\System32\\drivers\\usbprint.sys",
                "C:\\Windows\\System32\\drivers\\rdbss.sys",
                "C:\\Windows\\System32\\drivers\\errdev.sys",
                "C:\\Windows\\System32\\drivers\\processr.sys",
                "C:\\Windows\\System32\\drivers\\rdpbus.sys",
                "C:\\Windows\\System32\\sc.exe",
                "C:\\Windows\\System32\\drivers\\mspclock.sys",
                "C:\\Windows\\System32\\drivers\\aliide.sys",
                "C:\\Windows\\System32\\drivers\\mpio.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
                "C:\\Windows\\System32\\drivers\\evbda.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\mcupdate",
                "C:\\Windows\\System32\\wermgr.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
                "C:\\Windows\\System32\\drivers\\ql2300.sys",
                "C:\\Windows\\System32\\drivers\\umbus.sys",
                "C:\\Windows\\System32\\drivers\\tdtcp.sys",
                "C:\\Windows\\System32\\drivers\\acpipmi.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
                "C:\\Windows\\System32\\drivers\\UAGP35.SYS",
                "C:\\Windows\\System32\\drivers\\adpahci.sys",
                "C:\\Windows\\System32\\drivers\\sffdisk.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
                "C:\\Windows\\System32\\notepad.exe",
                "C:\\Windows\\System32\\drivers\\arc.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
                "C:\\Windows\\System32\\drivers\\ohci1394.sys",
                "C:\\Windows\\System32\\drivers\\wfplwf.sys",
                "C:\\Python27\\",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RecordingRestart",
                "C:\\Windows\\System32\\drivers\\volmgr.sys",
                "\\Device\\NamedPipe\\",
                "C:\\Windows\\System32\\drivers\\cdfs.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
                "C:\\Windows\\System32\\drivers\\GAGP30KX.SYS",
                "C:\\Windows\\System32\\csrss.exe",
                "c:\\program files\\windows defender\\MpCmdRun.exe",
                "C:\\Windows\\System32\\drivers\\1394ohci.sys",
                "C:\\Windows\\System32\\drivers\\ksecdd.sys",
                "C:\\Windows\\System32\\drivers\\usbehci.sys",
                "C:\\Windows\\System32\\drivers\\amdsata.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\GadgetManager",
                "C:\\Windows\\System32\\drivers\\MTConfig.sys",
                "C:\\Windows\\System32\\drivers\\crcdisk.sys",
                "C:\\Windows\\System32\\drivers\\mouhid.sys",
                "C:\\Windows\\System32\\drivers\\BrUsbMdm.sys",
                "C:\\Windows\\System32\\drivers\\lsi_scsi.sys",
                "C:\\Windows\\System32\\drivers\\sermouse.sys",
                "C:\\Users\\cuck\\",
                "C:\\Windows\\System32\\drivers\\scfilter.sys",
                "C:\\Windows\\System32\\sdclt.exe",
                "C:\\Windows\\",
                "C:\\Windows\\System32\\drivers\\http.sys",
                "C:\\Windows\\System32\\drivers\\raspptp.sys",
                "C:\\Windows\\System32\\drivers\\viaide.sys",
                "C:\\Windows\\System32\\drivers\\tcpipreg.sys",
                "C:\\Windows\\System32\\drivers\\qwavedrv.sys",
                "C:\\Windows\\System32\\drivers\\mrxsmb.sys",
                "C:\\Windows\\System32\\drivers\\AGP440.sys",
                "C:\\Windows\\System32\\wsqmcons.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
                "C:\\Windows\\System32\\drivers\\sffp_mmc.sys"
            ],
            "regkey_opened": [
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\isapnp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Modem",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srvnet\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06308A56-69E7-4844-A784-8509C25B6C62}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Filetrace\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CC35D2E9-B9E1-4ADC-9DA5-71487D9E9EB5}",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VaultSvc",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lmhosts",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4DE0CAB9-ECFE-4AA9-B95A-FE815A2EAA4E}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FltMgr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_32\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBth",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcLocator",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wdf01000\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehSched\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDProxy\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iaStorV",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D0250F3F-6480-484F-B719-42F659AC64D5}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Schedule",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPDR",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vga\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MegaSR",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\discache",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2470470F-2634-478E-B181-571E98A789BB}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vds",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WbioSrvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbcir\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BDESVC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache3.0.0.0\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WMPNetworkSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDPIPE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rspndr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WIMMount\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mshidkmdf\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1BB08CFD-C6AD-44C7-BD0B-8F23035A5731}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BDESVC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProfSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouhid\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B81A55E6-C03C-4EF0-B86F-A80A89DF468D}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Npfs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbFlt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppuinotify\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\1394ohci",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EventSystem",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stexstor\\Parameters",
                "HKEY_CURRENT_USER\\Software\\Classes\\htmlfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAgileVpn",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EapHost\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NlaSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nv_agp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{3307E641-F5EE-49E6-A1FE-BFB5D671441C}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbMdm\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\monitor",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinDefend",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidUsb\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Processor\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgrx\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Schedule\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IKEEXT",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A656BBE1-4E3E-4C8A-BD79-A8CA56782753}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection\\NAPStatus UI",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdK8\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{87F56B34-044E-4A48-8FDD-087BFABD5ECF}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UxSms\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltUp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\drmkaud",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fvevol",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CscService\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MRxDAV\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\s3cap\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ACPI",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\viaide",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\i8042prt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{00BB5F5C-4A20-4FD6-8900-4699F989BF01}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\discache\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanServer",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid2\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\exfat",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbohci",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Power",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mountmgr",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\CrawlStartPages",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4D19A151-A712-4920-AC6D-6C6FD81C8CDB}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteRegistry",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wercplsupport\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BFE\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPNAT\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storflt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A132EB1D-A1EA-48EF-8B69-9358EADF5BD3}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql2300",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swenum",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\E1G60\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpahci\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcLocator\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DPS",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msahci\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SessionEnv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serial",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanWorkstation",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netman\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NativeWifiP\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdxata",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelppm\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tunnel\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SSDPSRV",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C4375D81-FA72-45AC-85F2-3B86A11CCC7D}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RacTask",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbSer\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4FDEA3B5-7CDE-48F7-940C-43CDBB18FB20}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wd\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nv_agp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmRdpService\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tdx\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Browser",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppID",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ohci1394",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPCDD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msisadrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS2\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBatt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\isapnp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermDD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KtmRm",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetTcpPortSharing\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FltMgr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fastfat",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\drmkaud\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\mcupdate",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hkmsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iphlpsvc",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_sd",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{82676C49-21A7-4605-AA06-E04A067FB611}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sfloppy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURActivate",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\megasas",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Appinfo",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TapiSrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\defragsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrSerWdm\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdpbus\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDIS",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{600F3312-A477-448A-936D-EB2DF977300B}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVEdrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAcd",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbehci",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sermouse\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dmvsc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPCSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Brserid\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_FC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wcncsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SessionEnv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sfloppy\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BITS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsata",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSDTC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PolicyAgent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RACAgent",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CompositeBus\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TBS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wbengine\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupProvider\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5F5A18EB-DC73-4E45-A11C-B59043598412}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiSystemHost\\Parameters",
                "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinRM\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HpSAMD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbSer",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbFlt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cmdide",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BTHMODEM\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\udfs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\THREADORDER\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ohci1394\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\MemUsageTask",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinHttpAutoProxySvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPAutoReg\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance\\WinSAT",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AFD",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCardSvr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupProvider",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WbioSrvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupListener",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CertPropSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidIr",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrkWks",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volsnap\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SysMain",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\secdrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\scfilter\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arcsas\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\viaide\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecDD",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hidserv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DcomLaunch\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Beep",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSTEE",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CLFS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\atapi\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pciide",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WANARP\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lmhosts\\Parameters",
                "HKEY_USERS\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdio",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vsmraid",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSTEE\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpu320",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdclass\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdpbus",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcSs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adp94xx",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CmBatt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppIDSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PeerDistSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Fax\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tssecsrv",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2E941CB2-1B33-47C4-905B-8B4278819513}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpu320\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AsyncMac\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NlaSvc",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9979CB83-103A-4105-9E5D-C74B0AF6D198}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPCLOCK\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdbss",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RegisterSearch",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdPHost",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioSrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wcncsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Tcpip\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Rasl2tp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wbengine",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB07F7B4-BB95-4B74-9D32-4533D566453C}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rspndr",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hidserv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\napagent\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CmBatt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PptpMiniport",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2pimsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAuto\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dhcp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsbs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcEptMapper",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouclass",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SCSI\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPWD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CD962721-73F1-4649-85D7-6884C1EF28D9}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gagp30kx\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PcaSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\napagent",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BTHMODEM",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ndisuio",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBth\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ehDRMInit",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDTCP\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinDefend\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Brserid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis\\Scheduled",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wanarpv6",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdyboost\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netlogon",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UI0Detect",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FDResPub",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KeyIso",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Themes\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HpSAMD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcEptMapper\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bowser\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E3163C33-301D-4730-A266-5518C5ED3967}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nfrd960",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Psched",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVEdrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WcsPlugInService",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UxSms",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBT",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tdx",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cmdide\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBIOS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermService\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CryptSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PcaSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdhid",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcw\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CertPropSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wudfsvc",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{96137355-BC34-4BA7-81B7-47C87B556E7D}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WcsPlugInService\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\blbdrive\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pciide\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wuauserv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasPppoe\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swprv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SensrSvc",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}",
                "HKEY_CURRENT_USER\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
                "HKEY_CURRENT_USER\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbhub\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wercplsupport",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\flpydisk\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkCards\\12",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stisvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netlogon\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SNMPTRAP\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouhid",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\upnphost\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nfrd960\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MMCSS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HTTP\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hwpolicy\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VgaSave",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IRENUM\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sbp2port\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tcpipreg",
                "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ws2ifsl",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioSrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiServiceHost\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2psvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RpcSs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HTTP",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ebdrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisCap",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\W32Time",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{8C5ED038-CFAD-48A0-BB2F-D128286E49B3}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\atapi",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Power\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\E1G60",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPREFMP",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_sd\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvraid",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_64",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ntfs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vwifibus",
                "HKEY_CURRENT_USER\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pla\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPENCDD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AxInstSV\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAgileVpn\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ALG\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b06bdrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VaultSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql2300\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Msfs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sermouse",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanServer\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\i8042prt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NativeWifiP",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdK8",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\PolicyConverter",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storflt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SstpSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wlansvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrustedInstaller\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC668097-4D6B-4093-AC14-014C09DBF820}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpsdrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPDBusEnum",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PerfHost\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\udfs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BE669C13-8165-4536-96D0-6D6C39292AAE}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{613612BA-897D-44CE-8DC1-8FC283F9FD51}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WebClient",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{448186F9-75B9-4FB7-A6E0-B19A2BADC1BE}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MRxDAV",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hkmsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Null\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AsyncMac",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpio\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbGD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CNG",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mcx2Svc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdide\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tssecsrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CompositeBus",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\agp440\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermService",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9435F817-FED2-454E-88CD-7F78FDA62C48}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vmbus",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{268014E7-A27E-4FD7-89A6-A481DA222EC8}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BFE",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Tcpip",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WudfPf\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdbss\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mouclass\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iScsiPrt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmRdpService",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SDRSVC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinRM",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DXGKrnl\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stisvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPBusEnum\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tunnel",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbuhci\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPDR\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06CD2154-751E-469F-8E4A-C3F118356423}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WSearch\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DcomLaunch",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hcw85cir",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehSched",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EventSystem\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\THREADORDER",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AxInstSV",
                "HKEY_USERS\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vdrvroot\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Psched\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FileInfo",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WMPNetworkSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAcd\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PptpMiniport\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Parport",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbohci\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisWan\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TermDD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DXGKrnl",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uagp35",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WerSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Disk",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSiSCSI",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PEAUTH\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serenum\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storvsc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteAccess\\Parameters",
                "HKEY_USERS\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDIS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VSS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdide",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\AitAgent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5A40E926-9E86-4B89-9CFD-B12311724371}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{72DB7465-BC54-491B-A92A-4637A28C9BBF}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TsUsbGD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SstpSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvstor\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache3.0.0.0",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\USBSTOR",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MsRPC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_mmc",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\umbus",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecDD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppID\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\flpydisk",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wecsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PolicyAgent\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\stexstor",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2psvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\netprofm\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AcpiPmi\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\umbus\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WmiAcpi\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\elxstor\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffp_mmc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swenum\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ErrDev",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F18ED8A5-C696-4951-B068-CA8E83634C04}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{17F5B0DE-8DA9-4280-8CB8-91422B9A8CE1}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSDTC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\partmgr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MozillaMaintenance\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPREFMP\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv2",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\elxstor",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore\\SR",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iScsiPrt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MozillaMaintenance",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vdrvroot",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dnscache\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MMCSS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TCPIP6\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager\\Interactive",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adp94xx\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gpsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wmiApSrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProtectedStorage",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VgaSave\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b57nd60a",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CLFS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ndisuio\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wscsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB02381F-D652-4B1C-894A-712498C62C51}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dmvsc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsata\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b57nd60a\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FDResPub\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CSC\\Parameters",
                "HKEY_CURRENT_USER\\SOFTWARE\\Classes\\exefile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Rasl2tp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hcw85cir\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A48CABBF-24C8-4B87-B00F-9261807C3B43}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\scfilter",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mountmgr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\OptinNotification",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ws2ifsl\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WIMMount",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\storvsc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPQM\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Filetrace",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SENS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\partmgr",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serenum",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TBS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteAccess",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisWan",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fastfat\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WSearch",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql40xx",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EFS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ebdrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\secdrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vsmraid\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb20\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ksthunk\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D018DE2F-F02A-4BDB-BA74-56BCD427BE40}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MsRPC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SysMain\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffdisk",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Smb\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Smb",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecPkg",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\lltdio\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Winmgmt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CDA5F4EE-8293-4A5D-8564-04CD067D1A85}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\arcsas",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0004",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0007",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0006",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0001",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0000",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0003",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0002",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid4",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SamSs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0009",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0008",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VMBusHID",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb20",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0005",
                "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\idsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI\\ResolutionHost",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpsdrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SENS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dnscache",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wudfsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\eventlog",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SamSs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb10",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DfsC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS2",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Compbatt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FB3C354D-297A-4EB2-9B58-090F6361906B}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wuauserv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\COMSysApp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wdf01000",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iirsp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TCPIP6",
                "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gpsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbccgp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\adpahci",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDTCP",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\crcdisk\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mup\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\aliide",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\1394ohci\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetTcpPortSharing",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{551B3807-871F-4E48-A943-2330449F0615}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPNAT",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCPolicySvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCPolicySvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdrom\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\USBSTOR\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5BE46CE1-CA9B-4CAD-B2E9-8C3F7716AF90}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WANARP",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisCap\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SessionAgent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\spldr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry\\RegIdleBackup",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmPass",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Beep\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pci\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ErrDev\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppIDSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\aliide\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HomeGroupListener\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltLo",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msdsm",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SharedAccess\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RecordingRestart",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AeLookupSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Browser\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\netprofm",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdPHost\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcmcia\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SNMPTRAP",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\megasas\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CryptSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\luafv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\luafv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DfsC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbprint\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Modem\\Parameters",
                "HKEY_USERS\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msahci",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Netman",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Winmgmt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EFS",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A8B18D02-60CD-4305-90CC-7DAAC028BDCD}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdhid\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uliagpkx\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_FC\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsi",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UI0Detect\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KtmRm\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPCLOCK",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv2\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\COMSysApp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdrom",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ALG",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisTapi\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MpsSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\blbdrive",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltUp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HDAudBus",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\GadgetManager",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid4\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelide",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ACPI\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IKEEXT\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\seclogon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pla",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bthserv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProtectedStorage\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WinHttpAutoProxySvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppMgmt\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehRecvr",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AeLookupSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bthserv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pci",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBT\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System\\ConvertLogEntries",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPAutoReg",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DPS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasSstp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcw",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\UmPass\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PEAUTH",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TabletInputService",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ehRecvr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Spooler",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\pcmcia",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbehci\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
                "HKEY_USERS\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidUsb",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk\\Proxy",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSiSCSI\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdsbs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MpsSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BITS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrustedInstaller",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VSS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B43033E6-1453-4AD6-AFBA-C03CFC178286}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RemoteRegistry\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B78DBF96-841E-4336-BFE9-1C4975F9DA60}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelppm",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SiSRaid2",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Spooler\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\gagp30kx",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasMan",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\intelide\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\bowser",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPDBusEnum\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srv",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MpIdleTask",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WacomPen",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_64\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dot3svc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wd",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\agp440",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WmiAcpi",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{874CFED9-D01D-4D16-9775-B8A7A05004BF}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msiserver\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Serial\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\defragsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KSecPkg\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FsDepends",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\monitor\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPWD",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgrx",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IpFilterDriver",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mrxsmb10\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location\\Notifications",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MTConfig",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WPCSvc",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MegaSR\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PerfHost",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\srvnet",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7F9C951C-D364-4B70-8D07-D2C9B7F76E35}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Null",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\s3cap",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPCDD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC\\HotStart",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vga",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPMIDRV",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\hwpolicy",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\EapHost",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\AutoWake",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsiproxy\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Npfs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Dhcp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\StorSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\upnphost",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volsnap",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\StorSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vmbus\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wlansvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CSC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0010",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}\\0011",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A7C73732-9F11-4281-8D19-764D4EC9D94D}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7DC691A2-CB15-44DB-853C-19938051BB22}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SAS",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Ntfs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wanarpv6\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SSDPSRV\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{994C86AD-A929-4B2C-88A0-4E25A107A029}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\VMBusHID\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSKSSRV",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrSerWdm",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidBatt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WebClient\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-32-544",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SCardSvr",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbuhci",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mshidkmdf",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SDRSVC",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\KeyIso\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasPppoe",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\clr_optimization_v2.0.50727_32",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSPQM",
                "HKEY_LOCAL_MACHINE\\Software\\Classes\\htmlfile\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdPPM",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\idsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\spldr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras\\MobilityManager",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbprint",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FsDepends\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioEndpointBuilder",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LanmanWorkstation\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msisadrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TDPIPE\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ShellHWDetection",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbhub",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbcir",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uliagpkx",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsi\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vwifibus\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iphlpsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vds\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\usbccgp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fdc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WfpLwf\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MTConfig\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\tcpipreg\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AFD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{28011108-68DF-4C73-B91B-57427D501BBA}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sbp2port",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdfs\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\exfat\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mpio",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiServiceHost",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WfpLwf",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WwanSvc",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasMan\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Appinfo\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iaStorV\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\fvevol\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WudfPf",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\dot3svc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WerSvc",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI\\LPRemove",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WdiSystemHost",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\p2pimsvc\\Parameters",
                "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AcpiPmi",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PlugPlay\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HdAudAddService\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkCards",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PeerDistSvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nsiproxy",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AppMgmt",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HDAudBus\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\b06bdrv\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FileInfo\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPMIDRV\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Fax",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WwanSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wmiApSrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IPBusEnum",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TapiSrv",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SharedAccess",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ql40xx\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CscService",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SensrSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NdisTapi",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrUsbMdm",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NDProxy",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mcx2Svc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PlugPlay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AmdPPM\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B936B1AF-0C7E-4C4D-84F1-CF67453259A1}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\circlass\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\QWAVE\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vhdmp\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\seclogon\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\LSI_SCSI",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Processor",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\uagp35\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RDPENCDD\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Themes",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\FontCache\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msiserver",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ksthunk",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ShellHWDetection\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\iirsp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\W32Time\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\CNG\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\crcdisk",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Parport\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Msfs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TrkWks\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\WacomPen\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HidIr\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IRENUM",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sppuinotify",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HdAudAddService",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Compbatt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F6B1AFFE-48F0-4340-9F59-C73DDA17C17D}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mssmbios\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\swprv",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{40DD7C5E-DA67-4A78-B96C-582A4CBAEDF3}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\amdxata\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\eventlog\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\ProfSvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\msdsm\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\NetBIOS\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\mssmbios",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\BrFiltLo\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvstor",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\nvraid\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasSstp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\PNRPsvc\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\MSKSSRV\\Parameters",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C016366B-7126-46CA-B36B-592A3D95A60B}",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\IpFilterDriver\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Mup",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\volmgr",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\vhdmp",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\TabletInputService\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\rdyboost",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\cdfs",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\wscsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\AudioEndpointBuilder\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Wecsvc",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\sffdisk\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\RasAuto",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\Disk\\Parameters",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\kbdclass",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\circlass"
            ],
            "file_written": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe"
            ],
            "regkey_deleted": [
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Sidebar",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\mctadmin"
            ],
            "connects_ip": [
                "103.114.163.252"
            ],
            "file_exists": [
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
                "C:\\Windows\\System32\\drivers\\hdaudbus.sys",
                "C:\\Windows\\System32\\drivers\\hwpolicy.sys",
                "C:\\Windows\\System32\\drivers\\vga.sys",
                "C:\\Windows\\System32\\drivers\\filetrace.sys",
                "C:\\Windows\\System32\\drivers\\amdxata.sys",
                "C:\\Windows\\System32\\drivers\\pacer.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
                "C:\\Windows\\System32\\drivers\\lsi_fc.sys",
                "C:\\Windows\\System32\\drivers\\USBSTOR.SYS",
                "C:\\Windows\\System32\\drivers\\amdk8.sys",
                "C:\\Program Files\\Windows Media Player\\wmpnetwk.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURActivate",
                "C:\\Windows\\System32\\drivers\\dxgkrnl.sys",
                "C:\\Windows\\System32\\drivers\\usbhub.sys",
                "C:\\Windows\\System32\\drivers\\wmiacpi.sys",
                "C:\\Windows\\System32\\drivers\\Wdf01000.sys",
                "C:\\Windows\\System32\\conhost.exe",
                "C:\\Windows\\System32\\drivers\\fvevol.sys",
                "C:\\Windows\\System32\\NOTEPAD.EXE %1",
                "C:\\Windows\\System32\\drivers\\BrUsbSer.sys",
                "C:\\Windows\\System32\\drivers\\MegaSR.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RegisterSearch",
                "C:\\Windows\\System32\\wininit.exe",
                "C:\\Windows\\System32\\drivers\\ksecpkg.sys",
                "C:\\Windows\\System32\\drivers\\ndisuio.sys",
                "C:\\Windows\\System32\\drivers\\rasacd.sys",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\",
                "C:\\Windows\\System32\\drivers\\monitor.sys",
                "C:\\Windows\\System32\\drivers\\ndistapi.sys",
                "C:\\Windows\\System32\\drivers\\nsiproxy.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Diagnosis\\Scheduled",
                "C:\\Windows\\System32\\drivers\\hcw85cir.sys",
                "C:\\Windows\\System32\\drivers\\scfilter.sys",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf",
                "C:\\Windows\\System32\\drivers\\discache.sys",
                "C:\\Windows\\System32\\drivers\\tssecsrv.sys",
                "C:\\Windows\\System32\\drivers\\volmgr.sys",
                "C:\\Windows\\System32\\drivers\\wfplwf.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
                "C:\\Windows\\System32\\drivers\\blbdrive.sys",
                "C:\\Windows\\System32\\clfs.sys",
                "C:\\Windows\\System32\\drivers\\mskssrv.sys",
                "C:\\Windows\\System32\\drivers\\netbios.sys",
                "C:\\Windows\\explorer.exe",
                "C:\\Windows\\System32\\drivers\\tunnel.sys",
                "C:\\Windows\\System32\\drivers\\wanarp.sys",
                "C:\\Windows\\System32\\drivers\\adpu320.sys",
                "C:\\Windows\\System32\\drivers\\intelide.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
                "C:\\Windows\\System32\\drivers\\errdev.sys",
                "C:\\Windows\\System32\\drivers\\ksthunk.sys",
                "C:\\Windows\\System32\\drivers\\mspclock.sys",
                "C:\\Windows\\System32\\drivers\\netbt.sys",
                "C:\\Windows\\System32\\drivers\\hidir.sys",
                "C:\\Windows\\System32\\drivers\\rdpbus.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
                "C:\\Windows\\System32\\drivers\\WUDFPf.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
                "C:\\Windows\\System32\\drivers\\mouclass.sys",
                "C:\\Windows\\System32\\drivers\\rasl2tp.sys",
                "C:\\Windows\\System32\\drivers\\atapi.sys",
                "C:\\Windows\\System32\\drivers\\ipfltdrv.sys",
                "C:\\Windows\\System32\\drivers\\aliide.sys",
                "C:\\Windows\\System32\\drivers\\mpio.sys",
                "C:\\Windows\\System32\\drivers\\fileinfo.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SystemRestore\\SR",
                "C:\\Windows\\System32\\drivers\\RDPREFMP.sys",
                "C:\\Windows\\System32\\drivers\\evbda.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\mcupdate",
                "C:\\Windows\\System32\\drivers\\vmstorfl.sys",
                "C:\\Windows\\System32\\smss.exe",
                "C:\\Windows\\System32\\drivers\\flpydisk.sys",
                "C:\\Windows\\System32\\drivers\\kbdhid.sys",
                "C:\\Windows\\System32\\drivers\\lsi_sas2.sys",
                "C:\\Windows\\System32\\drivers\\mrxdav.sys",
                "C:\\Windows\\System32\\drivers\\mountmgr.sys",
                "C:\\Windows\\System32\\drivers\\mrxsmb10.sys",
                "C:\\Windows\\System32\\drivers\\srv.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
                "C:\\Windows\\System32\\drivers\\CmBatt.sys",
                "C:\\Windows\\System32\\drivers\\volmgrx.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
                "C:\\Windows\\System32\\drivers\\PEAuth.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MobilePC\\HotStart",
                "C:\\Windows\\System32\\drivers\\wacompen.sys",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MUI\\LPRemove",
                "C:\\Windows\\System32\\drivers\\ULIAGPKX.SYS",
                "C:\\Windows\\System32\\drivers\\pci.sys",
                "C:\\Windows\\System32\\drivers\\circlass.sys",
                "C:\\Windows\\System32\\drivers\\GAGP30KX.SYS",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
                "C:\\Windows\\System32\\drivers\\CompositeBus.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
                "C:\\Windows\\System32\\drivers\\drmkaud.sys",
                "C:\\Windows\\System32\\drivers\\fdc.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
                "C:\\Python27\\python.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe",
                "C:\\Users\\cuck\\AppData\\Roaming",
                "C:\\Windows\\System32\\drivers\\b57nd60a.sys",
                "C:\\Windows\\System32\\drivers\\nwifi.sys",
                "C:\\Windows\\System32\\drivers\\sffp_sd.sys",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
                "C:\\Windows\\System32\\drivers\\bthmodem.sys",
                "C:\\Windows\\System32\\drivers\\HdAudio.sys",
                "C:\\Windows\\System32\\drivers\\compbatt.sys",
                "C:\\Program Files\\Windows Sidebar\\Sidebar.exe \\autoRun",
                "C:\\Windows\\System32\\drivers\\dfsc.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
                "C:\\Windows\\System32\\drivers\\sisraid2.sys",
                "C:\\Windows\\System32\\drivers\\BrUsbMdm.sys",
                "C:\\Windows\\System32\\drivers\\usbuhci.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
                "C:\\Windows\\System32\\drivers\\storvsc.sys",
                "C:\\Windows\\System32\\drivers\\acpipmi.sys",
                "C:\\Windows\\System32\\drivers\\disk.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
                "C:\\Windows\\System32\\drivers\\BrFiltLo.sys",
                "C:\\Windows\\System32\\drivers\\acpi.sys",
                "C:\\Windows\\System32\\drivers\\udfs.sys",
                "C:\\Windows\\System32\\lsass.exe",
                "C:\\Windows\\System32\\drivers\\MTConfig.sys",
                "C:\\Windows\\System32\\drivers\\kbdclass.sys",
                "C:\\Windows\\System32\\drivers\\fltMgr.sys",
                "C:\\Windows\\System32\\drivers\\viaide.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\AutoWake",
                "C:\\Windows\\System32\\drivers\\raspppoe.sys",
                "C:\\Windows\\System32\\drivers\\adpahci.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
                "C:\\Windows\\System32\\drivers\\rdpdr.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
                "C:\\Windows\\System32\\drivers\\BrFiltUp.sys",
                "C:\\Windows\\System32\\drivers\\hidbth.sys",
                "C:\\Windows\\System32\\drivers\\isapnp.sys",
                "C:\\Windows\\System32\\drivers\\tdtcp.sys",
                "C:\\Windows\\System32\\drivers\\sffdisk.sys",
                "C:\\Windows\\System32\\drivers\\amdsbs.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
                "C:\\Windows\\System32\\drivers\\arc.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
                "C:\\Windows\\System32\\drivers\\irenum.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Location\\Notifications",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Autochk\\Proxy",
                "C:\\Windows\\System32\\drivers\\ipnat.sys",
                "C:\\Windows\\System32\\drivers\\tcpip.sys",
                "C:\\Windows\\System32\\drivers\\usbcir.sys",
                "C:\\Windows\\System32\\drivers\\srv2.sys",
                "C:\\Windows\\System32\\SearchIndexer.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RecordingRestart",
                "C:\\Windows\\System32\\drivers\\tdpipe.sys",
                "C:\\Windows\\System32\\drivers\\vms3cap.sys",
                "C:\\Windows\\System32\\drivers\\stexstor.sys",
                "C:\\Windows\\System32\\drivers\\appid.sys",
                "C:\\Windows\\System32\\drivers\\cng.sys",
                "C:\\Windows\\System32\\drivers\\serenum.sys",
                "C:\\Windows\\System32\\drivers\\intelppm.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RAC\\RacTask",
                "C:\\Windows\\System32\\drivers\\bowser.sys",
                "C:\\Windows\\System32\\drivers\\mssmbios.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
                "C:\\Windows\\System32\\drivers\\agilevpn.sys",
                "C:\\Windows\\System32\\drivers\\BrSerId.sys",
                "C:\\Windows\\System32\\drivers\\mshidkmdf.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
                "C:\\Windows\\System32\\drivers\\afd.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\AitAgent",
                "C:\\Windows\\System32\\drivers\\usbprint.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Maintenance\\WinSAT",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
                "C:\\Windows\\System32\\drivers\\TsUsbGD.sys",
                "C:\\Windows\\System32\\drivers\\HpSAMD.sys",
                "C:\\Windows\\System32\\drivers\\E1G6032E.sys",
                "C:\\Windows\\System32\\drivers\\cdfs.sys",
                "C:\\Windows\\System32\\drivers\\msdsm.sys",
                "C:\\Windows\\System32\\drivers\\lltdio.sys",
                "C:\\Windows\\System32\\csrss.exe",
                "C:\\Windows\\System32\\services.exe",
                "C:\\Windows\\System32\\drivers\\vhdmp.sys",
                "C:\\Windows\\System32\\drivers\\mpsdrv.sys",
                "C:\\Windows\\System32\\drivers\\usbohci.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
                "C:\\Windows\\System32\\drivers\\rspndr.sys",
                "C:\\Windows\\System32\\drivers\\pciide.sys",
                "C:\\Windows\\System32\\dwm.exe",
                "C:\\Windows\\System32\\drivers\\asyncmac.sys",
                "C:\\Windows\\System32\\drivers\\raspptp.sys",
                "C:\\Windows\\System32\\drivers\\mrxsmb20.sys",
                "C:\\Windows\\System32\\drivers\\1394ohci.sys",
                "C:\\Windows\\System32\\drivers\\BrSerWdm.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
                "C:\\Windows\\System32\\drivers\\FsDepends.sys",
                "C:\\Windows\\System32\\drivers\\usbehci.sys",
                "C:\\Windows\\System32\\drivers\\vwifibus.sys",
                "C:\\Windows\\System32\\drivers\\amdsata.sys",
                "C:\\Windows\\System32\\drivers\\vdrvroot.sys",
                "C:\\Windows\\System32\\drivers\\serial.sys",
                "C:\\Windows\\System32\\drivers\\pcmcia.sys",
                "C:\\Windows\\System32\\taskhost.exe",
                "C:\\Windows\\System32\\drivers\\ndis.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
                "C:\\Windows\\System32\\drivers\\lsi_sas.sys",
                "C:\\Windows\\System32\\drivers\\mup.sys",
                "C:\\Windows\\System32\\svchost.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
                "C:\\Windows\\System32\\drivers\\nvstor.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SessionAgent",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\GadgetManager",
                "C:\\Windows\\System32\\drivers\\bxvbda.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
                "C:\\Windows\\System32\\drivers\\sisraid4.sys",
                "C:\\Windows\\System32\\drivers\\rdyboost.sys",
                "C:\\Windows\\System32\\drivers\\crcdisk.sys",
                "C:\\Windows\\System32\\drivers\\msisadrv.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Ras\\MobilityManager",
                "C:\\Windows\\System32\\drivers\\wd.sys",
                "C:\\Windows\\System32\\drivers\\rdbss.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WDI\\ResolutionHost",
                "C:\\Windows\\System32\\drivers\\mouhid.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
                "C:\\Windows\\System32\\mctadmin.exe",
                "C:\\Windows\\System32\\drivers\\RDPCDD.sys",
                "C:\\Windows\\System32\\drivers\\ndiscap.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ehDRMInit",
                "C:\\Windows\\System32\\drivers\\UAGP35.SYS",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
                "C:\\Windows\\System32\\drivers\\lsi_scsi.sys",
                "C:\\Windows\\System32\\drivers\\nvraid.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
                "C:\\Windows\\System32\\drivers\\TsUsbFlt.sys",
                "C:\\Windows\\System32\\drivers\\umpass.sys",
                "C:\\Windows\\System32\\drivers\\ql2300.sys",
                "C:\\Windows\\System32\\drivers\\sermouse.sys",
                "C:\\Windows\\System32\\drivers\\partmgr.sys",
                "C:\\Windows\\System32\\spoolsv.exe",
                "C:\\Windows\\System32\\drivers\\csc.sys",
                "C:\\Windows\\System32\\drivers\\rassstp.sys",
                "C:\\Windows\\System32\\drivers\\i8042prt.sys",
                "C:\\Windows\\System32\\drivers\\tdx.sys",
                "C:\\Windows\\System32\\drivers\\iaStorV.sys",
                "C:\\Windows\\System32\\drivers\\parport.sys",
                "C:\\Windows\\System32\\drivers\\ndiswan.sys",
                "C:\\Windows\\System32\\drivers\\nfrd960.sys",
                "C:\\Windows\\System32\\drivers\\msahci.sys",
                "C:\\Windows\\System32\\cmd.exe",
                "C:\\Windows\\System32\\drivers\\processr.sys",
                "C:\\Windows\\System32\\drivers\\mspqm.sys",
                "C:\\Windows\\System32\\drivers\\ksecdd.sys",
                "C:\\Windows\\System32\\drivers\\http.sys",
                "C:\\Windows\\System32\\lsm.exe",
                "C:\\Windows\\System32\\drivers\\volsnap.sys",
                "C:\\Windows\\System32\\winlogon.exe",
                "C:\\Windows\\System32\\drivers\\sfloppy.sys",
                "C:\\Windows\\System32\\drivers\\amdppm.sys",
                "C:\\Windows\\System32\\drivers\\umbus.sys",
                "C:\\Windows\\System32\\drivers\\dmvsc.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
                "C:\\Windows\\System32\\drivers\\IPMIDrv.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
                "C:\\Windows\\System32\\drivers\\RDPENCDD.sys",
                "C:\\Windows\\System32\\drivers\\usbccgp.sys",
                "C:\\Windows\\System32\\drivers\\wimmount.sys",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
                "C:\\Windows\\System32\\drivers\\megasas.sys",
                "C:\\Windows\\System32\\drivers\\ws2ifsl.sys",
                "C:\\Windows\\System32\\drivers\\vgapnp.sys",
                "C:\\Windows\\inf\\",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Task Manager\\Interactive",
                "C:\\Windows\\System32\\drivers\\VMBusHID.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
                "C:\\Windows\\System32\\drivers\\NV_AGP.SYS",
                "C:\\Windows\\System32\\drivers\\arcsas.sys",
                "C:\\Windows\\System32\\drivers\\cdrom.sys",
                "C:\\Windows\\System32\\drivers\\amdide.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
                "C:\\Windows\\System32\\drivers\\srvnet.sys",
                "C:\\Windows\\System32\\drivers\\msiscsi.sys",
                "C:\\Windows\\System32\\drivers\\vmbus.sys",
                "C:\\Windows\\System32\\drivers\\vsmraid.sys",
                "C:\\Windows\\System32\\drivers\\elxstor.sys",
                "C:\\Windows\\System32\\drivers\\tcpipreg.sys",
                "C:\\Windows\\System32\\drivers\\hidusb.sys",
                "C:\\Windows\\System32\\drivers\\termdd.sys",
                "C:\\Windows\\System32\\drivers\\ql40xx.sys",
                "C:\\Windows\\System32\\drivers\\qwavedrv.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
                "C:\\Windows\\System32\\drivers\\pcw.sys",
                "C:\\Windows\\System32\\drivers\\swenum.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Registry\\RegIdleBackup",
                "C:\\Windows\\System32\\drivers\\mrxsmb.sys",
                "C:\\Windows\\System32\\drivers\\AGP440.sys",
                "C:\\Windows\\System32\\drivers\\ohci1394.sys",
                "C:\\Windows\\System32\\drivers\\luafv.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
                "C:\\tmpyzbctd\\bin\\inject-x64.exe",
                "C:\\Windows\\System32\\drivers\\modem.sys",
                "C:\\Windows\\System32\\drivers\\cmdide.sys",
                "C:\\Windows\\System32\\drivers\\mstee.sys",
                "C:\\Windows\\System32\\drivers\\adp94xx.sys",
                "C:\\Windows\\System32\\drivers\\sbp2port.sys",
                "C:\\Windows\\System32\\drivers\\smb.sys",
                "C:\\Windows\\System32\\drivers\\iirsp.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
                "C:\\Windows\\System32\\drivers\\sffp_mmc.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\PolicyConverter",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
                "C:\\Windows\\System32\\drivers\\hidbatt.sys"
            ],
            "file_failed": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\aitagent",
                "C:\\Windows\\ehome\\ehrec",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\BthUdTask.exe",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\%1",
                "C:\\Program",
                "C:\\Windows\\ehome\\mcupdate",
                "C:\\Windows\\System32\\d",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\sc.exe"
            ],
            "command_line": [
                "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe\" -accepteula",
                "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe\"  -a s -ct -m -h *",
                "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe\" -accepteula"
            ],
            "file_read": [
                "C:\\Windows\\System32\\drivers\\amdk8.sys",
                "C:\\Program Files\\Windows Media Player\\wmpnetwk.exe",
                "C:\\Python27\\python.exe",
                "C:\\Windows\\System32\\drivers\\filetrace.sys",
                "C:\\Windows\\System32\\drivers\\ndisuio.sys",
                "C:\\Windows\\System32\\drivers\\monitor.sys",
                "C:\\Windows\\System32\\drivers\\WUDFPf.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask",
                "C:\\Windows\\System32\\aepdu.dll",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver",
                "C:\\Windows\\System32\\drivers\\blbdrive.sys",
                "C:\\Windows\\System32\\clfs.sys",
                "C:\\Windows\\System32\\drivers\\netbios.sys",
                "C:\\Windows\\System32\\drivers\\mstee.sys",
                "C:\\Windows\\System32\\drivers\\hidir.sys",
                "C:\\Windows\\System32\\drivers\\rasl2tp.sys",
                "C:\\Windows\\System32\\drivers\\srvnet.sys",
                "C:\\Windows\\System32\\drivers\\ipfltdrv.sys",
                "C:\\Windows\\System32\\drivers\\asyncmac.sys",
                "C:\\Windows\\System32\\drivers\\flpydisk.sys",
                "C:\\Windows\\System32\\drivers\\lsi_sas2.sys",
                "C:\\Windows\\System32\\drivers\\mrxdav.sys",
                "C:\\Windows\\System32\\drivers\\mountmgr.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)",
                "C:\\Windows\\System32\\drivers\\rdyboost.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MobilePC\\HotStart",
                "C:\\Windows\\System32\\drivers\\wacompen.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MUI\\LPRemove",
                "C:\\Windows\\System32\\drivers\\circlass.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService",
                "C:\\Windows\\System32\\drivers\\CompositeBus.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck",
                "C:\\Windows\\System32\\drivers\\fdc.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SystemRestore\\SR",
                "C:\\Windows\\System32\\drivers\\bthmodem.sys",
                "C:\\Windows\\System32\\drivers\\compbatt.sys",
                "C:\\Windows\\System32\\drivers\\RDPCDD.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RegisterSearch",
                "C:\\Windows\\System32\\mctadmin.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Location\\Notifications",
                "C:\\Windows\\System32\\drivers\\BrUsbSer.sys",
                "C:\\Windows\\System32\\drivers\\vdrvroot.sys",
                "C:\\Windows\\System32\\drivers\\stexstor.sys",
                "C:\\Windows\\System32\\drivers\\BrFiltUp.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo",
                "C:\\Windows\\System32\\drivers\\mshidkmdf.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\AitAgent",
                "C:\\Windows\\System32\\drivers\\TsUsbGD.sys",
                "C:\\Windows\\System32\\drivers\\HpSAMD.sys",
                "C:\\Windows\\System32\\drivers\\E1G6032E.sys",
                "C:\\Windows\\System32\\drivers\\msdsm.sys",
                "C:\\Windows\\System32\\drivers\\lltdio.sys",
                "C:\\Windows\\System32\\drivers\\vhdmp.sys",
                "C:\\Windows\\System32\\drivers\\usbuhci.sys",
                "C:\\Windows\\System32\\drivers\\pciide.sys",
                "C:\\Windows\\System32\\dwm.exe",
                "C:\\Windows\\System32\\drivers\\rassstp.sys",
                "C:\\Windows\\System32\\drivers\\IPMIDrv.sys",
                "C:\\Windows\\System32\\raserver.exe",
                "C:\\Windows\\System32\\drivers\\ndis.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
                "C:\\Windows\\System32\\drivers\\tunnel.sys",
                "C:\\Windows\\System32\\drivers\\hwpolicy.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Multimedia\\SystemSoundsService",
                "C:\\Windows\\System32\\drivers\\sisraid4.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Ras\\MobilityManager",
                "C:\\Windows\\System32\\drivers\\ndiscap.sys",
                "C:\\Windows\\System32\\drivers\\umpass.sys",
                "C:\\Windows\\System32\\drivers\\bowser.sys",
                "C:\\Windows\\System32\\drivers\\partmgr.sys",
                "C:\\Windows\\System32\\drivers\\iaStorV.sys",
                "C:\\Windows\\System32\\drivers\\wfplwf.sys",
                "C:\\Windows\\System32\\drivers\\usbccgp.sys",
                "C:\\Windows\\System32\\cmd.exe",
                "C:\\Windows\\System32\\drivers\\sffp_sd.sys",
                "C:\\Windows\\System32\\drivers\\volsnap.sys",
                "C:\\Windows\\ehome\\mcupdate.exe",
                "C:\\Windows\\System32\\drivers\\mpsdrv.sys",
                "C:\\Windows\\System32\\drivers\\wmiacpi.sys",
                "C:\\Windows\\System32\\drivers\\MegaSR.sys",
                "C:\\Windows\\System32\\drivers\\adpu320.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Task Manager\\Interactive",
                "C:\\Windows\\System32\\drivers\\cdrom.sys",
                "C:\\Windows\\System32\\drivers\\BrFiltLo.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SystemDataProviders",
                "C:\\Windows\\System32\\drivers\\pcw.sys",
                "C:\\Windows\\System32\\Defrag.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Registry\\RegIdleBackup",
                "C:\\Windows\\System32\\drivers\\megasas.sys",
                "C:\\Windows\\System32\\drivers\\modem.sys",
                "C:\\Windows\\System32\\drivers\\adp94xx.sys",
                "C:\\Windows\\System32\\drivers\\iirsp.sys",
                "C:\\Windows\\System32\\drivers\\rspndr.sys",
                "C:\\Windows\\System32\\drivers\\hdaudbus.sys",
                "C:\\Windows\\System32\\drivers\\vga.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\UPnP\\UPnPHostConfig",
                "C:\\Windows\\System32\\drivers\\wanarp.sys",
                "C:\\Windows\\System32\\drivers\\dmvsc.sys",
                "C:\\Windows\\System32\\drivers\\FsDepends.sys",
                "C:\\Windows\\System32\\conhost.exe",
                "C:\\Windows\\System32\\drivers\\sisraid2.sys",
                "C:\\Windows\\System32\\appidpolicyconverter.exe",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\dXfIrC",
                "C:\\Windows\\System32\\drivers\\ULIAGPKX.SYS",
                "C:\\Windows\\System32\\drivers\\rasacd.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Maintenance\\WinSAT",
                "C:\\Windows\\System32\\drivers\\hcw85cir.sys",
                "C:\\Windows\\System32\\drivers\\VMBusHID.sys",
                "C:\\Windows\\System32\\drivers\\intelide.sys",
                "C:\\Windows\\System32\\drivers\\vmstorfl.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch",
                "C:\\Windows\\System32\\drivers\\HdAudio.sys",
                "C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe",
                "C:\\Windows\\System32\\drivers\\srv.sys",
                "C:\\Windows\\System32\\drivers\\msiscsi.sys",
                "C:\\Windows\\System32\\drivers\\CmBatt.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification",
                "C:\\Windows\\System32\\drivers\\bxvbda.sys",
                "C:\\Windows\\System32\\drivers\\vwifibus.sys",
                "C:\\Windows\\System32\\drivers\\drmkaud.sys",
                "C:\\Windows\\System32\\drivers\\fvevol.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask",
                "C:\\Windows\\System32\\ndfapi.dll",
                "C:\\Windows\\System32\\drivers\\ksthunk.sys",
                "C:\\Windows\\System32\\drivers\\ipnat.sys",
                "C:\\Windows\\System32\\drivers\\kbdhid.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrScheduleTask",
                "C:\\Windows\\System32\\drivers\\disk.sys",
                "C:\\Windows\\System32\\lpremove.exe",
                "C:\\Windows\\System32\\lsass.exe",
                "C:\\Windows\\System32\\drivers\\kbdclass.sys",
                "C:\\Windows\\System32\\drivers\\fltMgr.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam",
                "C:\\Windows\\System32\\drivers\\smb.sys",
                "C:\\Windows\\System32\\drivers\\isapnp.sys",
                "C:\\Windows\\System32\\drivers\\amdsbs.sys",
                "C:\\Windows\\System32\\lsm.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\UpdateRecordPath",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Autochk\\Proxy",
                "C:\\Windows\\System32\\drivers\\usbcir.sys",
                "C:\\Windows\\System32\\drivers\\vmbus.sys",
                "C:\\Windows\\System32\\drivers\\tdpipe.sys",
                "C:\\Windows\\System32\\drivers\\appid.sys",
                "C:\\Windows\\System32\\drivers\\cng.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Background Synchronization",
                "C:\\Windows\\System32\\drivers\\afd.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector",
                "C:\\Windows\\System32\\drivers\\tcpip.sys",
                "C:\\Windows\\System32\\services.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask",
                "C:\\Windows\\System32\\drivers\\BrSerWdm.sys",
                "C:\\Windows\\System32\\drivers\\ndiswan.sys",
                "C:\\Windows\\System32\\drivers\\serial.sys",
                "C:\\Windows\\System32\\drivers\\lsi_sas.sys",
                "C:\\Windows\\System32\\DFDWiz.exe",
                "C:\\Windows\\System32\\drivers\\dxgkrnl.sys",
                "C:\\Windows\\System32\\dfdts.dll",
                "C:\\Windows\\System32\\drivers\\nvstor.sys",
                "C:\\Windows\\System32\\LocationNotifications.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WDI\\ResolutionHost",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ehDRMInit",
                "C:\\Windows\\System32\\drivers\\csc.sys",
                "C:\\Windows\\System32\\drivers\\i8042prt.sys",
                "C:\\Windows\\System32\\gatherNetworkInfo.vbs",
                "C:\\Windows\\System32\\drivers\\parport.sys",
                "C:\\Windows\\System32\\drivers\\nfrd960.sys",
                "C:\\Windows\\System32\\drivers\\msahci.sys",
                "C:\\Program Files\\Windows Media Player\\wmpnscfg.exe",
                "C:\\Windows\\System32\\winlogon.exe",
                "C:\\Windows\\System32\\drivers\\sfloppy.sys",
                "C:\\Windows\\System32\\drivers\\RDPENCDD.sys",
                "C:\\Windows\\System32\\wininit.exe",
                "C:\\Windows\\System32\\drivers\\nwifi.sys",
                "C:\\Windows\\System32\\drivers\\ws2ifsl.sys",
                "C:\\Windows\\System32\\drivers\\PEAuth.sys",
                "C:\\Windows\\System32\\drivers\\NV_AGP.SYS",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator",
                "C:\\Windows\\System32\\drivers\\rdpdr.sys",
                "C:\\Windows\\System32\\drivers\\elxstor.sys",
                "C:\\Windows\\System32\\drivers\\hidusb.sys",
                "C:\\Windows\\System32\\drivers\\ql40xx.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\xGgBwK",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor",
                "C:\\Windows\\System32\\drivers\\amdxata.sys",
                "C:\\Windows\\System32\\drivers\\usbhub.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscovery",
                "C:\\Windows\\System32\\drivers\\vms3cap.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry",
                "C:\\Windows\\System32\\drivers\\nsiproxy.sys",
                "C:\\Windows\\System32\\drivers\\mup.sys",
                "C:\\Windows\\System32\\BFE.DLL",
                "C:\\Windows\\explorer.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector",
                "C:\\Windows\\System32\\drivers\\netbt.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
                "C:\\Windows\\System32\\drivers\\atapi.sys",
                "C:\\Windows\\System32\\drivers\\storvsc.sys",
                "C:\\Windows\\System32\\drivers\\fileinfo.sys",
                "C:\\Windows\\System32\\drivers\\wd.sys",
                "C:\\Windows\\System32\\drivers\\RDPREFMP.sys",
                "C:\\Windows\\System32\\drivers\\pacer.sys",
                "C:\\Windows\\System32\\drivers\\dfsc.sys",
                "C:\\Windows\\System32\\drivers\\mrxsmb10.sys",
                "C:\\Windows\\System32\\drivers\\mrxsmb20.sys",
                "C:\\Windows\\System32\\appidcertstorecheck.exe",
                "C:\\Windows\\System32\\drivers\\pci.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader",
                "C:\\Windows\\System32\\drivers\\b57nd60a.sys",
                "C:\\Windows\\System32\\drivers\\wimmount.sys",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
                "C:\\Windows\\System32\\drivers\\TsUsbFlt.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange",
                "C:\\Windows\\System32\\drivers\\acpi.sys",
                "C:\\Windows\\System32\\drivers\\udfs.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\AutoWake",
                "C:\\Windows\\System32\\drivers\\raspppoe.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary",
                "C:\\Windows\\System32\\drivers\\hidbth.sys",
                "C:\\Windows\\System32\\drivers\\irenum.sys",
                "C:\\Windows\\System32\\drivers\\srv2.sys",
                "C:\\Windows\\System32\\SearchIndexer.exe",
                "C:\\Windows\\System32\\drivers\\serenum.sys",
                "C:\\Windows\\System32\\drivers\\intelppm.sys",
                "C:\\Windows\\System32\\drivers\\mskssrv.sys",
                "C:\\Windows\\System32\\drivers\\mssmbios.sys",
                "C:\\Windows\\System32\\drivers\\BrSerId.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask",
                "C:\\Windows\\System32\\drivers\\agilevpn.sys",
                "C:\\Windows\\System32\\drivers\\usbohci.sys",
                "C:\\Windows\\System32\\drivers\\vsmraid.sys",
                "C:\\Windows\\System32\\drivers\\amdppm.sys",
                "C:\\Windows\\System32\\drivers\\pcmcia.sys",
                "C:\\Windows\\System32\\svchost.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControls",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\SessionAgent",
                "C:\\Windows\\System32\\drivers\\mspqm.sys",
                "C:\\Windows\\System32\\drivers\\msisadrv.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Defrag\\ScheduledDefrag",
                "C:\\Windows\\System32\\drivers\\nvraid.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks",
                "C:\\Windows\\ehome\\ehPrivJob.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Offline Files\\Logon Synchronization",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\6acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a.bin",
                "C:\\Windows\\System32\\drivers\\mouclass.sys",
                "C:\\Windows\\System32\\drivers\\vgapnp.sys",
                "C:\\Windows\\System32\\drivers\\volmgrx.sys",
                "C:\\Windows\\System32\\drivers\\arcsas.sys",
                "C:\\Windows\\System32\\drivers\\amdide.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1",
                "C:\\Windows\\System32\\powercfg.exe",
                "C:\\Windows\\System32\\drivers\\termdd.sys",
                "C:\\Windows\\System32\\drivers\\swenum.sys",
                "C:\\Windows\\System32\\taskhost.exe",
                "C:\\Windows\\System32\\drivers\\luafv.sys",
                "C:\\Windows\\System32\\drivers\\tdx.sys",
                "C:\\Windows\\System32\\drivers\\cmdide.sys",
                "C:\\Windows\\System32\\drivers\\sbp2port.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\AppID\\PolicyConverter",
                "C:\\Windows\\System32\\drivers\\hidbatt.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor",
                "C:\\Windows\\System32\\drivers\\lsi_fc.sys",
                "C:\\Windows\\System32\\drivers\\ksecpkg.sys",
                "C:\\Windows\\System32\\drivers\\USBSTOR.SYS",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURActivate",
                "C:\\Windows\\System32\\drivers\\tssecsrv.sys",
                "C:\\Windows\\System32\\drivers\\ndistapi.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Diagnosis\\Scheduled",
                "C:\\Windows\\System32\\drivers\\Wdf01000.sys",
                "C:\\Windows\\System32\\drivers\\discache.sys",
                "C:\\Windows\\System32\\drivers\\usbprint.sys",
                "C:\\Windows\\System32\\drivers\\rdbss.sys",
                "C:\\Windows\\System32\\drivers\\errdev.sys",
                "C:\\Windows\\System32\\drivers\\processr.sys",
                "C:\\Windows\\System32\\drivers\\rdpbus.sys",
                "C:\\Windows\\System32\\sc.exe",
                "C:\\Windows\\System32\\drivers\\mspclock.sys",
                "C:\\Windows\\System32\\drivers\\aliide.sys",
                "C:\\Windows\\System32\\drivers\\mpio.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2",
                "C:\\Windows\\System32\\drivers\\evbda.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\mcupdate",
                "C:\\Windows\\System32\\wermgr.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\OCURDiscovery",
                "C:\\Windows\\System32\\drivers\\ql2300.sys",
                "C:\\Windows\\System32\\drivers\\umbus.sys",
                "C:\\Windows\\System32\\drivers\\tdtcp.sys",
                "C:\\Windows\\System32\\drivers\\acpipmi.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
                "C:\\Windows\\System32\\drivers\\UAGP35.SYS",
                "C:\\Windows\\System32\\drivers\\adpahci.sys",
                "C:\\Windows\\System32\\drivers\\sffdisk.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\InstallPlayReady",
                "C:\\Windows\\System32\\notepad.exe",
                "C:\\Windows\\System32\\drivers\\arc.sys",
                "C:\\Windows\\System32\\drivers\\ohci1394.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Media Center\\RecordingRestart",
                "C:\\Windows\\System32\\drivers\\volmgr.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\RAC\\RacTask",
                "C:\\Windows\\System32\\drivers\\cdfs.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration",
                "C:\\Windows\\System32\\drivers\\GAGP30KX.SYS",
                "C:\\Windows\\System32\\csrss.exe",
                "c:\\program files\\windows defender\\MpCmdRun.exe",
                "C:\\Windows\\System32\\drivers\\1394ohci.sys",
                "C:\\Windows\\System32\\drivers\\ksecdd.sys",
                "C:\\Windows\\System32\\drivers\\usbehci.sys",
                "C:\\Windows\\System32\\drivers\\amdsata.sys",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SideShow\\GadgetManager",
                "C:\\Windows\\System32\\drivers\\MTConfig.sys",
                "C:\\Windows\\System32\\drivers\\crcdisk.sys",
                "C:\\Windows\\System32\\drivers\\mouhid.sys",
                "C:\\Windows\\System32\\drivers\\BrUsbMdm.sys",
                "C:\\Windows\\System32\\drivers\\lsi_scsi.sys",
                "C:\\Windows\\System32\\drivers\\sermouse.sys",
                "C:\\Windows\\System32\\spoolsv.exe",
                "C:\\Windows\\System32\\drivers\\scfilter.sys",
                "C:\\Windows\\System32\\sdclt.exe",
                "C:\\Windows\\System32\\drivers\\http.sys",
                "C:\\Windows\\System32\\drivers\\raspptp.sys",
                "C:\\Windows\\System32\\drivers\\viaide.sys",
                "C:\\Windows\\System32\\drivers\\tcpipreg.sys",
                "C:\\Windows\\System32\\drivers\\qwavedrv.sys",
                "C:\\Windows\\System32\\drivers\\mrxsmb.sys",
                "C:\\Windows\\System32\\drivers\\AGP440.sys",
                "C:\\Windows\\System32\\wsqmcons.exe",
                "C:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
                "C:\\Windows\\System32\\drivers\\sffp_mmc.sys"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{3307E641-F5EE-49E6-A1FE-BFB5D671441C}\\Actions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\MediaCenterRecoveryTask\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{448186F9-75B9-4FB7-A6E0-B19A2BADC1BE}\\Actions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D0250F3F-6480-484F-B719-42F659AC64D5}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW1\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MpIdleTask\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location\\Notifications\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0003\\NetCfgInstanceId",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI\\ResolutionHost\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB02381F-D652-4B1C-894A-712498C62C51}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2470470F-2634-478E-B181-571E98A789BB}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A656BBE1-4E3E-4C8A-BD79-A8CA56782753}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D018DE2F-F02A-4BDB-BA74-56BCD427BE40}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A7C73732-9F11-4281-8D19-764D4EC9D94D}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager\\Interactive\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP\\UPnPHostConfig\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore\\SR\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FB3C354D-297A-4EB2-9B58-090F6361906B}\\Path",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB02381F-D652-4B1C-894A-712498C62C51}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B81A55E6-C03C-4EF0-B86F-A80A89DF468D}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06308A56-69E7-4844-A784-8509C25B6C62}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SessionAgent\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Logon Synchronization\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\SqlLiteRecoveryTask\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06308A56-69E7-4844-A784-8509C25B6C62}\\Actions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{87F56B34-044E-4A48-8FDD-087BFABD5ECF}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB07F7B4-BB95-4B74-9D32-4533D566453C}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\WindowsParentalControls\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5BE46CE1-CA9B-4CAD-B2E9-8C3F7716AF90}\\Path",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7DC691A2-CB15-44DB-853C-19938051BB22}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F18ED8A5-C696-4951-B068-CA8E83634C04}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CC35D2E9-B9E1-4ADC-9DA5-71487D9E9EB5}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BE669C13-8165-4536-96D0-6D6C39292AAE}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E3163C33-301D-4730-A266-5518C5ED3967}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4DE0CAB9-ECFE-4AA9-B95A-FE815A2EAA4E}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\DispatchRecoveryTasks\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{40DD7C5E-DA67-4A78-B96C-582A4CBAEDF3}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{551B3807-871F-4E48-A943-2330449F0615}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B78DBF96-841E-4336-BFE9-1C4975F9DA60}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\MemUsageTask\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4D19A151-A712-4920-AC6D-6C6FD81C8CDB}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\PolicyConverter\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{268014E7-A27E-4FD7-89A6-A481DA222EC8}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4FDEA3B5-7CDE-48F7-940C-43CDBB18FB20}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A8B18D02-60CD-4305-90CC-7DAAC028BDCD}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Smb\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RegisterSearch\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI\\LPRemove\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0004\\NetCfgInstanceId",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1BB08CFD-C6AD-44C7-BD0B-8F23035A5731}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{17F5B0DE-8DA9-4280-8CB8-91422B9A8CE1}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C016366B-7126-46CA-B36B-592A3D95A60B}\\Path",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\AitAgent\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{C016366B-7126-46CA-B36B-592A3D95A60B}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Defrag\\ScheduledDefrag\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Filtering Platform\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0001\\NetCfgInstanceId",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC668097-4D6B-4093-AC14-014C09DBF820}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrScheduleTask\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticResolver\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{96137355-BC34-4BA7-81B7-47C87B556E7D}\\Path",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PeriodicScanRetry\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0005\\NetCfgInstanceId",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9979CB83-103A-4105-9E5D-C74B0AF6D198}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06CD2154-751E-469F-8E4A-C3F118356423}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B78DBF96-841E-4336-BFE9-1C4975F9DA60}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6}\\Actions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{8C5ED038-CFAD-48A0-BB2F-D128286E49B3}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ehDRMInit\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{72DB7465-BC54-491B-A92A-4637A28C9BBF}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stexstor\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\InstallPlayReady\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{82676C49-21A7-4605-AA06-E04A067FB611}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpahci\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia\\SystemSoundsService\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}\\Path",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql40xx\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\exfat\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{40DD7C5E-DA67-4A78-B96C-582A4CBAEDF3}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{96137355-BC34-4BA7-81B7-47C87B556E7D}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F6B1AFFE-48F0-4340-9F59-C73DDA17C17D}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ShellHWDetection\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Autochk\\Proxy\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ObjectStoreRecoveryTask\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}\\Path",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FB3C354D-297A-4EB2-9B58-090F6361906B}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{8C5ED038-CFAD-48A0-BB2F-D128286E49B3}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\SystemDataProviders\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{72DB7465-BC54-491B-A92A-4637A28C9BBF}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RacTask\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\StorSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4DE0CAB9-ECFE-4AA9-B95A-FE815A2EAA4E}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0002\\NetCfgInstanceId",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{994C86AD-A929-4B2C-88A0-4E25A107A029}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\secdrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbFlt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vga\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9435F817-FED2-454E-88CD-7F78FDA62C48}\\Actions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{448186F9-75B9-4FB7-A6E0-B19A2BADC1BE}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0008\\NetCfgInstanceId",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7DC691A2-CB15-44DB-853C-19938051BB22}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CDA5F4EE-8293-4A5D-8564-04CD067D1A85}\\Path",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}\\Path",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ActivateWindowsSearch\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CDA5F4EE-8293-4A5D-8564-04CD067D1A85}\\Actions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{268014E7-A27E-4FD7-89A6-A481DA222EC8}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gagp30kx\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{613612BA-897D-44CE-8DC1-8FC283F9FD51}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdpbus\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection\\NAPStatus UI\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IpFilterDriver\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Power Efficiency Diagnostics\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B43033E6-1453-4AD6-AFBA-C03CFC178286}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RemoteAssistance\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2E941CB2-1B33-47C4-905B-8B4278819513}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CC35D2E9-B9E1-4ADC-9DA5-71487D9E9EB5}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\s3cap\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fastfat\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAcd\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5F5A18EB-DC73-4E45-A11C-B59043598412}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\OptinNotification\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A7C73732-9F11-4281-8D19-764D4EC9D94D}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4D19A151-A712-4920-AC6D-6C6FD81C8CDB}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adp94xx\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidIr\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wcncsvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Maintenance\\WinSAT\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TBS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0010\\NetCfgInstanceId",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\mcupdate\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cmdide\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\idsvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\GadgetManager\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPDR\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tcpipreg\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC668097-4D6B-4093-AC14-014C09DBF820}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pci\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcmcia\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{874CFED9-D01D-4D16-9775-B8A7A05004BF}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mshidkmdf\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MegaSR\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vdrvroot\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ohci1394\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vwifibus\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0000\\NetCfgInstanceId",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{17F5B0DE-8DA9-4280-8CB8-91422B9A8CE1}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msahci\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{87F56B34-044E-4A48-8FDD-087BFABD5ECF}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KeyIso\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC\\HotStart\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Shell\\CrawlStartPages\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{551B3807-871F-4E48-A943-2330449F0615}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{3307E641-F5EE-49E6-A1FE-BFB5D671441C}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DXGKrnl\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbuhci\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Appinfo\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A48CABBF-24C8-4B87-B00F-9261807C3B43}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WmiAcpi\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioSrv\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcSs\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SysMain\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PptpMiniport\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBIOS\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TsUsbGD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pcw\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4FDEA3B5-7CDE-48F7-940C-43CDBB18FB20}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0009\\NetCfgInstanceId",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProfSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Themes\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Tcpip\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A48CABBF-24C8-4B87-B00F-9261807C3B43}\\Actions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F6B1AFFE-48F0-4340-9F59-C73DDA17C17D}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdide\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpio\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A656BBE1-4E3E-4C8A-BD79-A8CA56782753}\\Path",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2E941CB2-1B33-47C4-905B-8B4278819513}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D0250F3F-6480-484F-B719-42F659AC64D5}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvstor\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5A40E926-9E86-4B89-9CFD-B12311724371}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPsvc\\parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0007\\NetCfgInstanceId",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\blbdrive\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSiSCSI\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Location\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wuauserv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Multimedia\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}\\Actions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ReindexSearchRoot\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srvnet\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NativeWifiP\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltUp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras\\MobilityManager\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PeerDistSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SensrSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WMPNetworkSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A8B18D02-60CD-4305-90CC-7DAAC028BDCD}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDPIPE\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SamSs\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPCDD\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0006\\NetCfgInstanceId",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{28011108-68DF-4C73-B91B-57427D501BBA}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSDTC\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcEptMapper\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wdf01000\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IRENUM\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AcpiPmi\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wanarpv6\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PNRPAutoReg\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hcw85cir\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVE\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PerfTrack\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSS\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\flpydisk\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WANARP\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WwanSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5A40E926-9E86-4B89-9CFD-B12311724371}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wscsvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbehci\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tssecsrv\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WDI\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDProxy\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\RecordingRestart\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netlogon\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b57nd60a\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Fax\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscoveryW2\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupProvider\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbohci\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uagp35\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{D018DE2F-F02A-4BDB-BA74-56BCD427BE40}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Offline Files\\Background Synchronization\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MpsSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid2\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wecsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\NetworkAccessProtection\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelide\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CscService\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCPolicySvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BE669C13-8165-4536-96D0-6D6C39292AAE}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasPppoe\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SCSI\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiServiceHost\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\defragsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swprv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wercplsupport\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrSerWdm\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CNG\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidUsb\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\RAC\\RACAgent\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppuinotify\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HomeGroupListener\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{EB07F7B4-BB95-4B74-9D32-4533D566453C}\\Actions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv2\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\spldr\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{28011108-68DF-4C73-B91B-57427D501BBA}\\Actions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F18ED8A5-C696-4951-B068-CA8E83634C04}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DfsC\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wbengine\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crcdisk\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hidserv\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WIMMount\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdPPM\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bthserv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sbp2port\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rspndr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tunnel\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{994C86AD-A929-4B2C-88A0-4E25A107A029}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NDIS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\partmgr\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KtmRm\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffdisk\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\monitor\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ql2300\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSAMD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\elxstor\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MsRPC\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\seclogon\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbcir\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkCards\\12\\ServiceName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VgaSave\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdxata\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURActivate\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iirsp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsi\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAgileVpn\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Media Sharing\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Diagnosis\\Scheduled\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HdAudAddService\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PlugPlay\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MemoryDiagnostic\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsbs\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dot3svc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPENCDD\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\aliide\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_sd\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\b06bdrv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UxSms\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPWD\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MobilePC\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehRecvr\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{82676C49-21A7-4605-AA06-E04A067FB611}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\upnphost\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\umbus\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WSearch\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\MUI\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPHLPSVC\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Time Synchronization\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ehSched\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\discache\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CSC\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B81A55E6-C03C-4EF0-B86F-A80A89DF468D}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wlansvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\adpu320\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CLFS\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Application Experience\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WbioSrvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\OCURDiscovery\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FltMgr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrkWks\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdfs\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecDD\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdclass\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPNAT\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MozillaMaintenance\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CD962721-73F1-4649-85D7-6884C1EF28D9}\\Path",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WacomPen\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storflt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\viaide\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mup\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ALG\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mountmgr\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinRM\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vsmraid\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pla\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BFE\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\USBSTOR\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SNMPTRAP\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hkmsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iaStorV\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RpcLocator\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Rasl2tp\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\COMSysApp\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\THREADORDER\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vhdmp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBth\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\ConfigureInternetTimeService\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AudioEndpointBuilder\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WdiSystemHost\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdyboost\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CertPropSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ebdrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPDBusEnum\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_FC\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinHttpAutoProxySvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermDD\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Wd\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Msfs\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\agp440\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppMgmt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LSI_SAS2\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\PLA\\System\\ConvertLogEntries\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WfpLwf\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PcaSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PvrRecoveryTask\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetTcpPortSharing\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PEAUTH\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AeLookupSvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SstpSvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmPass\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\swenum\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vmbus\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MTConfig\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSTEE\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nfrd960\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\UpdateRecordPath\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sffp_mmc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dhcp\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\WindowsBackup\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Npfs\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Filetrace\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2470470F-2634-478E-B181-571E98A789BB}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinDefend\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serenum\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\AppID\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Modem\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dmvsc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\vds\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nsiproxy\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HTTP\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{1BB08CFD-C6AD-44C7-BD0B-8F23035A5731}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\megasas\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSKSSRV\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbMdm\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\tdx\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteRegistry\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2psvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SCardSvr\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouclass\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FsDepends\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrFiltLo\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Mcx2Svc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisWan\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0011\\NetCfgInstanceId",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NlaSvc\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AsyncMac\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RemoteAccess\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Task Manager\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\isapnp\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\netprofm\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TDTCP\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Windows Error Reporting\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nv_agp\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WudfPf\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Processor\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\0011\\MatchingDeviceId",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\i8042prt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mouhid\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisTapi\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\pciide\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AmdK8\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sfloppy\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9979CB83-103A-4105-9E5D-C74B0AF6D198}\\Path",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SideShow\\AutoWake\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Media Center\\PBDADiscovery\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdio\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lmhosts\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ndisuio\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Serial\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\luafv\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\storvsc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mpsdrv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Beep\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Compbatt\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\stisvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TapiSrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\uliagpkx\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\scfilter\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EFS\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Psched\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\circlass\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FontCache3.0.0.0\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FDResPub\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\nvraid\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdPHost\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NdisCap\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{874CFED9-D01D-4D16-9775-B8A7A05004BF}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msisadrv\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Dnscache\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msdsm\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasSstp\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CmBatt\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sermouse\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UI0Detect\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SessionEnv\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SSDPSRV\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5BE46CE1-CA9B-4CAD-B2E9-8C3F7716AF90}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\amdsata\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgr\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\UPnP\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HDAudBus\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\lltdsvc\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\intelppm\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\FileInfo\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volmgrx\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPMIDRV\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wudfsvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AFD\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WcsPlugInService\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B43033E6-1453-4AD6-AFBA-C03CFC178286}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SDRSVC\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{5F5A18EB-DC73-4E45-A11C-B59043598412}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppID\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbhub\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{06CD2154-751E-469F-8E4A-C3F118356423}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DcomLaunch\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\QWAVEdrv\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CD962721-73F1-4649-85D7-6884C1EF28D9}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbccgp\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Netman\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\rdbss\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ErrDev\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\NetBT\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Ras\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ACPI\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mssmbios\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AppIDSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{E3163C33-301D-4730-A266-5518C5ED3967}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\p2pimsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\SystemRestore\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WPCSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MMCSS\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\cdrom\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ksthunk\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SiSRaid4\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb20\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TabletInputService\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EventSystem\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VMBusHID\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\E1G60\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\arcsas\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BrUsbSer\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)\\Id",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\udfs\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\AxInstSV\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CompositeBus\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ProtectedStorage\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Null\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TrustedInstaller\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BDESVC\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SENS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fdc\\Start",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\Registry\\RegIdleBackup\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\volsnap\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Power\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\drmkaud\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HidBatt\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\fvevol\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\KSecPkg\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\CryptSvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MRxDAV\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasMan\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\bowser\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Disk\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\atapi\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}\\Actions",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb10\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\sppsvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Parport\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\EapHost\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\1394ohci\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Spooler\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gpsvc\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{9435F817-FED2-454E-88CD-7F78FDA62C48}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\usbprint\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{613612BA-897D-44CE-8DC1-8FC283F9FD51}\\Path",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\kbdhid\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PerfHost\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RasAuto\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPREFMP\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\napagent\\Parameters\\ServiceDll",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ntfs\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Brserid\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPBusEnum\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\srv\\ObjectName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPQM\\Type",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\DPS\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\iScsiPrt\\ImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows\\DiskDiagnostic\\Microsoft-Windows-DiskDiagnosticDataCollector\\Id",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MSPCLOCK\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\hwpolicy\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BTHMODEM\\Start",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\mrxsmb\\Description"
            ],
            "regkey_written": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)"
            ]
        },
        "first_seen": 1589777586.59375,
        "ppid": 2724
    },
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe",
        "process_name": "autorunsc64.exe",
        "pid": 2096,
        "summary": {
            "file_created": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp"
            ],
            "file_recreated": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
                "\\Device\\KsecDD"
            ],
            "regkey_written": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
                "HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns\\EulaAccepted",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\LanguageList"
            ],
            "dll_loaded": [
                "PROPSYS.dll",
                "imagehlp.dll",
                "kernel32",
                "API-MS-Win-Security-LSALookup-L1-1-0.dll",
                "apphelp.dll",
                "api-ms-win-core-localization-l1-2-1",
                "CFGMGR32.dll",
                "kernel32.dll",
                "credssp.dll",
                "CRYPTBASE.dll",
                "C:\\Windows\\system32\\rsaenh.dll",
                "SensApi.dll",
                "ntdll.dll",
                "cryptsp.dll",
                "api-ms-win-core-synch-l1-2-0",
                "winhttp.dll",
                "ntmarta.dll",
                "bcrypt.dll",
                "API-MS-WIN-Service-Management-L1-1-0.dll",
                "cryptnet.dll",
                "setupapi.dll",
                "api-ms-win-appmodel-runtime-l1-1-1",
                "API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
                "API-MS-WIN-Service-winsvc-L1-1-0.dll",
                "ole32.dll",
                "USERENV.dll",
                "CRYPTSP.dll",
                "USER32.dll",
                "DEVRTL.dll",
                "C:\\Windows\\system32\\mswsock.dll",
                "API-MS-Win-Security-SDDL-L1-1-0.dll",
                "SspiCli.dll",
                "IPHLPAPI.DLL",
                "C:\\Windows\\system32\\Wintrust.dll",
                "ncrypt.dll",
                "WindowsCodecs.dll",
                "C:\\Windows\\system32\\CRYPT32.dll",
                "NSI.dll",
                "OLEAUT32.dll",
                "profapi.dll",
                "SHELL32.dll",
                "RPCRT4.dll",
                "DNSAPI.dll",
                "C:\\Windows\\System32\\wship6.dll",
                "comctl32.dll",
                "ext-ms-win-kernel32-package-current-l1-1-0",
                "SHLWAPI.dll",
                "API-MS-WIN-Service-Management-L2-1-0.dll",
                "C:\\Windows\\system32\\advapi32.dll",
                "api-ms-win-core-fibers-l1-1-1",
                "WINTRUST.DLL",
                "C:\\Windows\\system32\\cryptnet.dll",
                "C:\\Windows\\system32\\crypt32.dll",
                "C:\\Windows\\system32\\bcryptprimitives.dll",
                "C:\\Windows\\system32\\Kernel32.dll",
                "ADVAPI32.dll",
                "C:\\Windows\\System32\\wshtcpip.dll",
                "SETUPAPI.dll",
                "WS2_32.dll",
                "Cabinet.dll",
                "WINHTTP.dll"
            ],
            "file_opened": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
                "C:\\Windows\\SysWOW64",
                "C:\\",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\",
                "C:\\Windows\\System32\\EhStorShell.dll",
                "C:\\Windows\\System32\\SystemPropertiesPerformance.exe",
                "C:\\ProgramData",
                "c:\\Windows\\System32\\rundll32.exe",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
                "c:\\program files (x86)\\windows mail\\WinMail.exe",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
                "c:\\Windows\\SysWOW64\\ie4uinit.exe",
                "C:\\Windows\\System32\\en-US\\WINHTTP.dll.mui",
                "C:\\Windows\\SysWOW64\\en-US\\unregmp2.exe.mui",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
                "c:\\Windows\\SysWOW64\\mscories.dll",
                "c:\\Windows\\System32\\iconcodecservice.dll",
                "C:\\Users\\cuck\\Desktop\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\Certificates\\",
                "C:\\Windows\\explorer.exe",
                "C:\\Windows\\System32\\en-US\\KERNELBASE.dll.mui",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
                "C:\\Users\\cuck\\Music\\desktop.ini",
                "C:\\Windows\\SysWOW64\\regsvr32.exe",
                "c:\\Windows\\SysWOW64\\regsvr32.exe",
                "C:\\Users\\cuck\\Favorites\\desktop.ini",
                "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
                "C:\\Program Files\\Windows Mail\\WinMail.exe",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
                "C:\\Users\\cuck\\Downloads\\desktop.ini",
                "C:\\Windows\\System32\\imageres.dll",
                "C:\\ProgramData\\Microsoft\\",
                "C:\\Program Files\\Windows Mail\\",
                "c:\\program files\\windows mail\\WinMail.exe",
                "c:\\Windows\\SysWOW64\\iedkcs32.dll",
                "C:\\Users\\cuck\\Searches\\desktop.ini",
                "C:\\Users\\cuck\\Links\\desktop.ini",
                "c:\\Windows\\SysWOW64\\unregmp2.exe",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\",
                "C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\ntexe.cat",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\",
                "C:\\Program Files (x86)\\Windows Mail\\",
                "C:\\Program Files (x86)\\Windows Mail\\WinMail.exe",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\",
                "C:\\Program Files",
                "C:\\Program Files (x86)",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows",
                "C:\\Windows\\System32\\ntshrui.dll",
                "C:\\Users\\cuck\\Saved Games\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu",
                "C:\\Program Files\\Windows Mail",
                "c:\\Windows\\SysWOW64\\rundll32.exe",
                "C:\\Windows\\System32\\rsaenh.dll",
                "C:\\Windows",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
                "C:\\Program Files (x86)\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CRLs\\",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db",
                "c:\\Windows\\System32\\userinit.exe",
                "c:\\Windows\\System32\\systempropertiesperformance.exe",
                "c:\\Windows\\System32\\imageres.dll",
                "C:\\Users\\",
                "c:\\Windows\\explorer.exe",
                "C:\\Users\\cuck\\Videos\\desktop.ini",
                "C:\\Users",
                "C:\\Users\\cuck\\Documents\\desktop.ini",
                "C:\\Windows\\System32\\shdocvw.dll",
                "C:\\Users\\cuck\\Contacts\\desktop.ini",
                "C:\\Users\\desktop.ini",
                "C:\\Windows\\SysWOW64\\ie4uinit.exe",
                "C:\\Users\\cuck",
                "c:\\Windows\\System32\\rdpclip.exe",
                "C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db",
                "C:\\Windows\\System32\\catroot",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs",
                "C:\\Windows\\System32\\catroot2",
                "C:\\Users\\cuck\\AppData\\",
                "c:\\Windows\\System32\\cmd.exe",
                "c:\\Windows\\System32\\iedkcs32.dll",
                "C:\\Users\\cuck\\AppData\\LocalLow",
                "C:\\Users\\cuck\\AppData",
                "C:\\Windows\\SysWOW64\\",
                "C:\\Windows\\System32\\catroot2\\",
                "C:\\Users\\cuck\\",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CTLs\\",
                "c:\\Windows\\System32\\unregmp2.exe",
                "C:\\Windows\\System32\\en-US\\unregmp2.exe.mui",
                "C:\\Windows\\System32\\cscui.dll",
                "C:\\Windows\\System32",
                "C:\\Windows\\System32\\cmd.exe",
                "C:\\Windows\\",
                "C:\\Windows\\System32\\regsvr32.exe",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\",
                "C:\\ProgramData\\Microsoft",
                "C:\\Windows\\SysWOW64\\unregmp2.exe",
                "C:\\Windows\\System32\\ie4uinit.exe",
                "C:\\Program Files (x86)\\Windows Mail",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\",
                "c:\\Windows\\System32\\regsvr32.exe",
                "C:\\Users\\cuck\\Pictures\\desktop.ini",
                "C:\\Windows\\System32\\rdpclip.exe",
                "C:\\Program Files\\desktop.ini",
                "c:\\Windows\\System32\\ie4uinit.exe",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft",
                "C:\\Windows\\System32\\",
                "C:\\Windows\\System32\\unregmp2.exe",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs",
                "c:\\Windows\\System32\\mscories.dll",
                "C:\\Windows\\System32\\userinit.exe"
            ],
            "regkey_opened": [
                "HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance\\Disabled",
                "HKEY_CURRENT_USER\\Software\\Sysinternals",
                "HKEY_CLASSES_ROOT\\CLSID\\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\\Instance",
                "HKEY_CURRENT_USER\\Software\\Sysinternals\\AutoRuns",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Class\\{4d36e972-e325-11ce-bfc1-08002be10318}",
                "HKEY_LOCAL_MACHINE\\Software\\Sysinternals"
            ],
            "resolves_host": [
                "crl.microsoft.com",
                "www.microsoft.com"
            ],
            "file_written": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp"
            ],
            "regkey_deleted": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE"
            ],
            "file_deleted": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp"
            ],
            "file_exists": [
                "C:\\Windows\\System32\\rundll32.exe",
                "C:\\Windows\\System32\\rdpclip.com",
                "C:\\Windows\\System32\\explorer.exe",
                "C:\\Users\\cuck\\AppData\\LocalLow",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled",
                "C:\\Windows\\System32\\regsvr32.exe",
                "C:\\Python27\\cmd.exe",
                "C:\\Windows\\SysWOW64\\regsvr32.exe",
                "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\rdpclip",
                "C:\\Windows\\SysWOW64\\rundll32.exe",
                "C:\\Python27\\explorer.exe",
                "C:\\Windows\\System32\\SystemPropertiesPerformance.exe",
                "C:\\Python27\\Scripts\\explorer.exe",
                "C:\\Windows\\System32\\cmd.exe",
                "C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\ntexe.cat",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
                "C:\\Python27\\IconCodecService.dll",
                "C:\\Python27\\Scripts\\SystemPropertiesPerformance.exe",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
                "C:\\Python27\\rdpclip.com",
                "C:\\Python27\\Scripts\\cmd.exe",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
                "C:\\Windows\\System32\\rdpclip",
                "C:\\Windows\\System32\\p2pcollab.dll",
                "C:\\Python27\\Scripts\\IconCodecService.dll",
                "C:\\Windows\\SysWOW64\\iedkcs32.dll",
                "C:\\Windows\\System32\\catroot\\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\\",
                "C:\\Windows\\SysWOW64\\unregmp2.exe",
                "C:\\Windows\\System32\\ie4uinit.exe",
                "C:\\Windows\\inf\\",
                "C:\\Windows\\System32\\fveui.dll",
                "C:\\Program Files (x86)\\Windows Mail\\WinMail.exe",
                "C:\\Windows\\System32\\QAGENTRT.DLL",
                "C:\\Windows\\System32\\mscories.dll",
                "C:\\Windows\\explorer.exe",
                "C:\\Python27\\SystemPropertiesPerformance.exe",
                "C:\\Windows\\System32\\catroot2\\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\\",
                "C:\\Windows\\SysWOW64\\ie4uinit.exe",
                "C:\\Windows\\System32\\wbem\\rdpclip",
                "C:\\Windows\\System32\\dnsapi.dll",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
                "C:\\Windows\\rdpclip",
                "C:\\Windows\\System32\\rdpclip.exe",
                "C:\\Python27\\Scripts\\rdpclip.com",
                "C:\\Windows\\rdpclip.com",
                "C:\\Windows\\SysWOW64\\mscories.dll",
                "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\rdpclip.com",
                "C:\\Windows\\System32\\iedkcs32.dll",
                "C:\\Python27\\Scripts\\rdpclip.exe",
                "C:\\Python27\\Scripts\\rdpclip",
                "C:\\Program Files\\Windows Mail\\WinMail.exe",
                "C:\\Python27\\rdpclip.exe",
                "C:\\Python27\\rdpclip",
                "C:\\Windows\\System32\\wbem\\rdpclip.com",
                "C:\\Windows\\System32\\unregmp2.exe",
                "C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat",
                "C:\\Windows\\System32\\IconCodecService.dll",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled",
                "C:\\Users\\cuck\\AppData\\Local\\Temp",
                "C:\\Windows\\System32\\userinit.exe",
                "C:\\Python27\\regsvr32.exe",
                "C:\\Python27\\Scripts\\regsvr32.exe"
            ],
            "file_failed": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\%USERPROFILE%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled\\",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\%USERPROFILE%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\F90F18257CBB4D84216AC1E1F3BB2C76",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\%USERPROFILE%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\",
                "C:\\ProgramData\\Microsoft\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\C24EC5BDAF13613245B4CECC3DE91DC6",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled\\",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\B8CC409ACDBF2A2FE04C56F2875B1FD6",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\696F3DE637E6DE85B458996D49D759AD",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AutorunsDisabled\\"
            ],
            "guid": [
                "{add8ba80-002b-11d0-8f0f-00c04fd7d062}",
                "{08244ee6-92f0-47f2-9fc9-929baa2e7235}",
                "{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
                "{4e77131d-3629-431c-9818-c5679dc83e81}",
                "{d9144dcd-e998-4eca-ab6a-dcd83ccba16d}",
                "{dffacdc5-679f-4156-8947-c5c76bc0b67f}",
                "{0c6c4200-c589-11d0-999a-00c04fd655e1}",
                "{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}"
            ],
            "file_read": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarD41D.tmp",
                "C:\\Users\\cuck\\Documents\\desktop.ini",
                "C:\\Users\\cuck\\Searches\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
                "C:\\Users\\cuck\\Links\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
                "C:\\Users\\cuck\\Videos\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
                "C:\\Users\\cuck\\Desktop\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabD41C.tmp",
                "C:\\Users\\cuck\\Contacts\\desktop.ini",
                "C:\\Users\\desktop.ini",
                "C:\\Users\\cuck\\Pictures\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini",
                "C:\\Users\\cuck\\Music\\desktop.ini",
                "C:\\Program Files\\desktop.ini",
                "C:\\Users\\cuck\\Favorites\\desktop.ini",
                "C:\\Users\\cuck\\Saved Games\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
                "C:\\Users\\cuck\\Downloads\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
                "C:\\Program Files (x86)\\desktop.ini"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\RelativePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Favorites",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\Content Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Comment",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\StubPath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Load",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Roamable",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Name",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\StorageDelegate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoWebView",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\StreamResourceType",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Pictures",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Category",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Version",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.44.3.4!7\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Stream",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HideOnDesktopPerUser",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HideFolderVerbs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DefaultIcon\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MaxSockaddrLength",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\RelativePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\Safety Warning Level",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\CryptnetPreFetchTriggerPeriodSeconds",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Stream",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\Content Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsAliasedNotifications",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Max Cached Icons",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\WinStations\\RDP-Tcp\\InitialProgram",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\WinHttpSettings",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsFORDISPLAY",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Cryptography\\PrivKeyCacheMaxItems",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\GlobalSession",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\AppSetup",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\DefaultIcon\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\LoadWithoutCOM",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\LoadWithoutCOM",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HideInWebView",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip6\\WinSock 2.0 Provider ID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledProcesses\\78ED498",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-18\\Flags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\StorageDelegateSuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxUrlRetrievalByteCount",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Stream",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\PerceivedType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Security",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\Mapping",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DiagMatchAnyMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Stream",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\AltStartup",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\MapNetDriveVerbs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableUnsupportedCriticalExtensions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ini\\PerceivedType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\PublishExpandedPath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Name",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\system32\\p2pcollab.dll,-8042",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Personal",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\MaxSockaddrLength",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Stream",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsFORPARSING",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\IconServiceLib",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\PreCreate",
                "HKEY_CURRENT_USER\\Environment\\UserInitMprLogonScript",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SeparateProcess",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\97817950D81C9670CC34D809CF794431367EF474\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCountPerChain",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PreCreate",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\ChainCacheResyncFiletime",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\DisabledSessions\\MachineThrottling",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\StreamResourceType",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Music",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\PublishExpandedPath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Video",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\Shell",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\DefaultIcon\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalRedirectOnly",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Startup",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\ParentFolder",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip\\WinSock 2.0 Provider ID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\ShellComponent",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\RpcId",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InfoTip",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-20\\Flags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsUniversalDelegate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ShareCredsWithWinHttp",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Parameters\\Transports",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\Enabled",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Icon",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Local AppData",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\SafeProcessSearchMode",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Icon",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\HelperDllName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableMandatoryBasicConstraints",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetCrawling",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\LsaExtensionConfig\\SspiCli\\CheckSignatureRoutine",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\MinSockaddrLength",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\LsaExtensionConfig\\SspiCli\\CheckSignatureDll",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\LoadWithoutCOM",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsParseDisplayName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\ShellComponent",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\UseDelayedAcceptance",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\Wds\\rdpwd\\StartupPrograms",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClassicShell",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\UseDropHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\ShellComponent",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{FEBEF00C-046D-438D-8A88-BF94A6C9E703}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.67.1.1!7\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableCANameConstraints",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\\InProcServer32\\LoadWithoutCOM",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp\\DisableBranchCache",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\PinToNameSpaceTree",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCertCount",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\Flags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\PreCreate",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{4E77131D-3629-431C-9818-C5679DC83E81} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\QueryForInfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\VmApplet",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Security",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Category",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DiagLevel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\MaximumAllowedAllocationSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InitFolderHandler",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\StreamResourceType",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Startup",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugFlags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Defaults\\Provider\\Microsoft Enhanced RSA and AES Cryptographic Provider\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Common Startup",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\StubPath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlCountInCert",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{3af36230-a269-11d1-b5bf-0000f8051515}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\RestrictedAttributes",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Attributes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Taskman",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.dll\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxySettingsPerUser",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Attributes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates\\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Defaults\\Provider\\Microsoft Enhanced RSA and AES Cryptographic Provider\\Image Path",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.67.1.2!7\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Capabilities",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\System32\\fveui.dll,-844",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\System32\\fveui.dll,-843",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\RelativePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Run",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\PreventItemCreationInUsersFilesFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}\\InProcServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.47.1.1!7\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-19\\Flags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\MachineGuid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\CallForAttributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\Icon",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MinSockaddrLength",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{4E77131D-3629-431C-9818-C5679DC83E81}\\InProcServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\InfoTip",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\system32\\dnsapi.dll,-103",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{10C07CD0-EF91-4567-B850-448B77CB37F9}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\NoFileFolderJunction",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp\\Tracing\\Enabled",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResource",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F} {ADD8BA80-002B-11D0-8F0F-00C04FD7D062} 0xFFFF",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableWeakSignatureFlags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Serial_Access_Num",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Icon",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\SecurityProviders",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Security",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C5ABBF53-E17F-4121-8900-86626FC2C973}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Stream",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4340}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\\InProcServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\UseDelayedAcceptance",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates\\7D7F4414CCEF168ADF6BF40753B5BECD78375931\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\LocalRedirectOnly",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Name",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SafeBoot\\AlternateShell",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{45ea75a0-a269-11d1-b5bf-0000f8051515}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\TokenSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\RelativePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\QueryForOverlay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.exe\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DF7266AC-9274-4867-8D55-3BD661DE872D}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Cryptography\\PrivKeyCachePurgeIntervalSeconds",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParentFolder",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\\ShellComponent",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ini\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Security",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inifile\\IsShortcut",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadOverride",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9381D8F2-0288-11D0-9501-00AA00B911A5}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Common AltStartup",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\InfoTip",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{374DE290-123F-4565-9164-39C4925E467B}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\RelativePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Desktop",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\InfoTip",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResource",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing\\State",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\SharingPrivate\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{E92B03AB-B707-11d2-9CBD-0000F87A369E}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{630b1da0-b465-11d1-9948-00c04f98bbc9}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\StubPath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{56784854-C6CB-462B-8169-88E350ACB882}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Stream",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ini\\Content Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\HelperDllName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DontShowSuperHidden",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{C9E9A340-D1F1-11D0-821E-444553540600}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\\FolderTypeID",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@%SystemRoot%\\system32\\qagentrt.dll,-10",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\\Blob",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{190337D1-B8CA-4121-A639-6D472D16972A}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A302545D-DEFF-464B-ABE8-61C8648D939B}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\>{26923b43-4d38-484f-9b9e-de460746276c}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\dllfile\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D9DC8A3B-B784-432E-A781-5A1130A75963}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalRedirectOnly",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\Mapping",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\\InprocServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.dll\\PerceivedType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{AE50C081-EBD2-438A-8655-8A092E34987A}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{7790769C-0471-11d2-AF11-00C04FA35D02}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4900540-2379-4C75-844B-64E6FAF8716B}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{4f645220-306d-11d2-995d-00c04f98bbc9}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6D809377-6AF0-444B-8957-A3773F02200E}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalByteCount",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{43668BF8-C14E-49B2-97C9-747784D784B7}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A63293E8-664E-48DB-A079-DF759E0509F7}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Cryptography\\PrivateKeyLifetimeSeconds",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{76FC4E2D-D6AD-4519-A663-37BD56068185}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\Name",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{7C028AF8-F614-47B3-82DA-BA94E41B1089}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableInetUnknownAuth",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{98EC0E18-2098-4D44-8644-66979315A281}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSimpleStartMenu",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\EnhancedStorageShell\\SuppressionPolicy",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components\\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\\ShellComponent",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{89820200-ECBD-11cf-8B85-00AA005B4383}\\StubPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HasNavigationEnum",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A74AEB-AEB4-465C-A014-D097EE346D63}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{8983036C-27C0-404B-8F08-102D10DCFD74}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A990AE9F-A03B-4E80-94BC-9912D7504104}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{054FAE61-4DD8-4787-80B6-090220C4B700}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Name"
            ],
            "directory_created": [
                "C:\\Windows\\System32\\catroot2",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches",
                "C:\\Windows\\System32\\catroot"
            ]
        },
        "first_seen": 1589777599.264999,
        "ppid": 1268
    }
]

Signatures

[
    {
        "markcount": 1,
        "families": [],
        "description": "Collects information to fingerprint the system (MachineGuid, DigitalProductId, SystemBiosDate)",
        "severity": 1,
        "marks": [
            {
                "category": "registry",
                "ioc": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\MachineGuid",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "recon_fingerprint"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "This executable has a PDB path",
        "severity": 1,
        "marks": [
            {
                "category": "pdb_path",
                "ioc": "E:\\MyProjects\\SVN_PROJECT\\trunk\\XMR\\GetuserInfoClient\\SuperKillX\\x64\\Release\\SuperKillX.pdb",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "has_pdb"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "The file contains an unknown PE resource name possibly indicative of a packer",
        "severity": 1,
        "marks": [
            {
                "category": "resource name",
                "ioc": "IMAGE_LIST",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "pe_unknown_resource_name"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Foreign language identified in PE resource",
        "severity": 2,
        "marks": [
            {
                "name": "IMAGE_LIST",
                "language": "LANG_CHINESE",
                "offset": "0x000490c0",
                "filetype": "Microsoft Cabinet archive data, 331565 bytes, 1 file",
                "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
                "type": "generic",
                "size": "0x00050f2d"
            }
        ],
        "references": [],
        "name": "origin_langid"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Searches running processes potentially to identify processes for sandbox evasion, code injection or memory dumping",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "conhost.exe",
                        "snapshot_handle": "0x0000000000000190",
                        "process_identifier": 300
                    },
                    "time": 1589777673.46875,
                    "tid": 2740,
                    "flags": {}
                },
                "pid": 1268,
                "type": "call",
                "cid": 5049
            }
        ],
        "references": [],
        "name": "injection_process_search"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Checks adapter addresses which can be used to detect virtual network interfaces",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "network",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741772,
                    "api": "GetAdaptersAddresses",
                    "return_value": 111,
                    "arguments": {
                        "flags": 15,
                        "family": 0
                    },
                    "time": 1589777604.295999,
                    "tid": 3020,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 5281
            }
        ],
        "references": [],
        "name": "antivm_network_adapters"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "The binary likely contains encrypted or compressed data indicative of a packer",
        "severity": 2,
        "marks": [
            {
                "entropy": 7.996078958553206,
                "section": {
                    "size_of_data": "0x00051200",
                    "virtual_address": "0x00049000",
                    "entropy": 7.996078958553206,
                    "name": ".rsrc",
                    "virtual_size": "0x00051170"
                },
                "type": "generic",
                "description": "A section with a high entropy has been found"
            },
            {
                "entropy": 0.5481418918918919,
                "type": "generic",
                "description": "Overall entropy of this PE file is high"
            }
        ],
        "references": [
            "http:\/\/www.forensickb.com\/2013\/03\/file-entropy-explained.html",
            "http:\/\/virii.es\/U\/Using%20Entropy%20Analysis%20to%20Find%20Encrypted%20and%20Packed%20Malware.pdf"
        ],
        "name": "packer_entropy"
    },
    {
        "markcount": 16,
        "families": [],
        "description": "Checks for the Locally Unique Identifier on the system for a suspicious privilege",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1589777586.76575,
                    "tid": 2740,
                    "flags": {}
                },
                "pid": 1268,
                "type": "call",
                "cid": 65
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1589777599.420999,
                    "tid": 2260,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 85
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeSecurityPrivilege"
                    },
                    "time": 1589777599.436999,
                    "tid": 2260,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 98
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1589777599.436999,
                    "tid": 2260,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 100
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeBackupPrivilege"
                    },
                    "time": 1589777599.436999,
                    "tid": 2260,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 102
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeRestorePrivilege"
                    },
                    "time": 1589777599.436999,
                    "tid": 2260,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 145
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1589777255.627645,
                    "tid": 2328,
                    "flags": {}
                },
                "pid": 144,
                "type": "call",
                "cid": 92
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeSecurityPrivilege"
                    },
                    "time": 1589777255.627645,
                    "tid": 2328,
                    "flags": {}
                },
                "pid": 144,
                "type": "call",
                "cid": 105
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1589777255.627645,
                    "tid": 2328,
                    "flags": {}
                },
                "pid": 144,
                "type": "call",
                "cid": 107
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeBackupPrivilege"
                    },
                    "time": 1589777255.627645,
                    "tid": 2328,
                    "flags": {}
                },
                "pid": 144,
                "type": "call",
                "cid": 109
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeRestorePrivilege"
                    },
                    "time": 1589777255.643645,
                    "tid": 2328,
                    "flags": {}
                },
                "pid": 144,
                "type": "call",
                "cid": 152
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1589777273.45502,
                    "tid": 1432,
                    "flags": {}
                },
                "pid": 2716,
                "type": "call",
                "cid": 85
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeSecurityPrivilege"
                    },
                    "time": 1589777273.45502,
                    "tid": 1432,
                    "flags": {}
                },
                "pid": 2716,
                "type": "call",
                "cid": 98
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1589777273.45502,
                    "tid": 1432,
                    "flags": {}
                },
                "pid": 2716,
                "type": "call",
                "cid": 100
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeBackupPrivilege"
                    },
                    "time": 1589777273.45502,
                    "tid": 1432,
                    "flags": {}
                },
                "pid": 2716,
                "type": "call",
                "cid": 102
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeRestorePrivilege"
                    },
                    "time": 1589777273.45502,
                    "tid": 1432,
                    "flags": {}
                },
                "pid": 2716,
                "type": "call",
                "cid": 145
            }
        ],
        "references": [],
        "name": "privilege_luid_check"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Terminates another process",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "process",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 109,
                    "nt_status": -1073741493,
                    "api": "NtTerminateProcess",
                    "return_value": 0,
                    "arguments": {
                        "status_code": "0x00000000",
                        "process_identifier": 2096,
                        "process_handle": "0x0000000000000184"
                    },
                    "time": 1589777684.54675,
                    "tid": 2204,
                    "flags": {}
                },
                "pid": 1268,
                "type": "call",
                "cid": 20241
            },
            {
                "call": {
                    "category": "process",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 109,
                    "nt_status": -1073741493,
                    "api": "NtTerminateProcess",
                    "return_value": -1073741558,
                    "arguments": {
                        "status_code": "0x00000000",
                        "process_identifier": 2096,
                        "process_handle": "0x0000000000000184"
                    },
                    "time": 1589777684.54675,
                    "tid": 2204,
                    "flags": {}
                },
                "pid": 1268,
                "type": "call",
                "cid": 20242
            }
        ],
        "references": [],
        "name": "terminates_remote_process"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Installs itself for autorun at Windows startup",
        "severity": 3,
        "marks": [
            {
                "type": "generic",
                "reg_key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
                "reg_value": "\"%1\" %*"
            },
            {
                "type": "generic",
                "reg_key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)",
                "reg_value": "\"%1\" %*"
            }
        ],
        "references": [],
        "name": "persistence_autorun"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Attempts to create or modify system certificates",
        "severity": 3,
        "marks": [
            {
                "category": "registry",
                "ioc": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "modifies_certificates"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Expresses interest in specific running processes",
        "severity": 3,
        "marks": [
            {
                "category": "process: potential process injection target",
                "ioc": "winlogon.exe",
                "type": "ioc",
                "description": null
            },
            {
                "category": "process: potential process injection target",
                "ioc": "explorer.exe",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "process_interest"
    },
    {
        "markcount": 3,
        "families": [],
        "description": "Uses Sysinternals tools in order to add additional command line functionality",
        "severity": 3,
        "marks": [
            {
                "category": "cmdline",
                "ioc": "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe\" -accepteula",
                "type": "ioc",
                "description": null
            },
            {
                "category": "cmdline",
                "ioc": "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhuMeAyLnLf\\autorunsc64.exe\"  -a s -ct -m -h *",
                "type": "ioc",
                "description": null
            },
            {
                "category": "cmdline",
                "ioc": "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\pHqGhdXfIrCvSc\\autorunsc64.exe\" -accepteula",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [
            "docs.microsoft.com\/en-us\/sysinternals\/downloads\/"
        ],
        "name": "sysinternals_tools_usage"
    }
]

Yara

The Yara rules did not detect anything in the file.

Network

{
    "tls": [],
    "udp": [
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 546,
            "time": 3.1348209381103516,
            "dport": 137,
            "sport": 137
        },
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 20778,
            "time": 9.134487867355347,
            "dport": 138,
            "sport": 138
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 22622,
            "time": 56.30344295501709,
            "dport": 5355,
            "sport": 49556
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 22942,
            "time": 21.353087902069092,
            "dport": 5355,
            "sport": 49840
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 23262,
            "time": 51.51863384246826,
            "dport": 5355,
            "sport": 50202
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 23582,
            "time": 75.48181700706482,
            "dport": 5355,
            "sport": 50952
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 23902,
            "time": 3.0604028701782227,
            "dport": 5355,
            "sport": 51001
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 24230,
            "time": 26.76778793334961,
            "dport": 5355,
            "sport": 52259
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 24550,
            "time": 1.0994529724121094,
            "dport": 5355,
            "sport": 53595
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 24878,
            "time": 3.0721728801727295,
            "dport": 5355,
            "sport": 53848
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 25206,
            "time": 67.58376288414001,
            "dport": 5355,
            "sport": 54025
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 25526,
            "time": 40.885679960250854,
            "dport": 5355,
            "sport": 54237
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 25846,
            "time": 1.621513843536377,
            "dport": 5355,
            "sport": 54255
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 26174,
            "time": 32.015684843063354,
            "dport": 5355,
            "sport": 54335
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 26494,
            "time": -0.04454994201660156,
            "dport": 5355,
            "sport": 55314
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 26822,
            "time": 18.686545848846436,
            "dport": 5355,
            "sport": 55880
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 27142,
            "time": 62.19700789451599,
            "dport": 5355,
            "sport": 56347
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 27462,
            "time": 54.1380410194397,
            "dport": 5355,
            "sport": 56353
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 27782,
            "time": 72.86210989952087,
            "dport": 5355,
            "sport": 56388
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 28102,
            "time": 80.28118896484375,
            "dport": 5355,
            "sport": 58056
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 28422,
            "time": 70.20402193069458,
            "dport": 5355,
            "sport": 58651
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 28742,
            "time": 36.9695508480072,
            "dport": 5355,
            "sport": 58989
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 29062,
            "time": 64.85789394378662,
            "dport": 5355,
            "sport": 59490
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 29382,
            "time": 34.310001850128174,
            "dport": 5355,
            "sport": 59548
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 29702,
            "time": 46.238972902297974,
            "dport": 5355,
            "sport": 60071
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 30022,
            "time": 58.924113035202026,
            "dport": 5355,
            "sport": 60575
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 30342,
            "time": 48.889102935791016,
            "dport": 5355,
            "sport": 62601
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 30662,
            "time": 77.65541005134583,
            "dport": 5355,
            "sport": 63089
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 30982,
            "time": 29.395230054855347,
            "dport": 5355,
            "sport": 63506
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 31302,
            "time": 43.52337884902954,
            "dport": 5355,
            "sport": 63646
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 31622,
            "time": 24.109850883483887,
            "dport": 5355,
            "sport": 64017
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 31942,
            "time": 1.837514877319336,
            "dport": 1900,
            "sport": 1900
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 51352,
            "time": 1.3428828716278076,
            "dport": 3702,
            "sport": 49152
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 59736,
            "time": 3.182492971420288,
            "dport": 1900,
            "sport": 53598
        }
    ],
    "dns_servers": [],
    "http": [],
    "icmp": [],
    "smtp": [],
    "tcp": [],
    "smtp_ex": [],
    "mitm": [],
    "hosts": [],
    "pcap_sha256": "71fd7cc32ce49b83814ae4736515de2543bfadfea16cdcdfdbfabb6e8fcbd218",
    "dns": [],
    "http_ex": [],
    "domains": [],
    "dead_hosts": [],
    "sorted_pcap_sha256": "57fc36e0f94245cb89e0c2efdb4b10bc77b5c3642de3f1afcb7f1b5d1fd7ee8c",
    "irc": [],
    "https_ex": []
}

Screenshots

Screenshot from the sandboxScreenshot from the sandboxScreenshot from the sandbox

vC36a100r.exe removal instructions

The instructions below shows how to remove vC36a100r.exe with help from the FreeFixer removal tool. Basically, you install FreeFixer, scan your computer, check the vC36a100r.exe file for removal, restart your computer and scan it again to verify that vC36a100r.exe has been successfully removed. Here are the removal instructions in more detail:

  1. Download and install FreeFixer: http://www.freefixer.com/download.html
  2. Start FreeFixer and press the Start Scan button. The scan will finish in approximately five minutes.
    Screenshot of Start Scan button
  3. When the scan is finished, locate vC36a100r.exe in the scan result and tick the checkbox next to the vC36a100r.exe file. Do not check any other file for removal unless you are 100% sure you want to delete it. Tip: Press CTRL-F to open up FreeFixer's search dialog to quickly locate vC36a100r.exe in the scan result.
    Red arrow point on the unwanted file
    c:\Windows\System32\vC36a100r.exe
  4. Scroll down to the bottom of the scan result and press the Fix button. FreeFixer will now delete the vC36a100r.exe file.
    Screenshot of Fix button
  5. Restart your computer.
  6. Start FreeFixer and scan your computer again. If vC36a100r.exe still remains in the scan result, proceed with the next step. If vC36a100r.exe is gone from the scan result you're done.
  7. If vC36a100r.exe still remains in the scan result, check its checkbox again in the scan result and click Fix.
  8. Restart your computer.
  9. Start FreeFixer and scan your computer again. Verify that vC36a100r.exe no longer appear in the scan result.
Please select the option that best describe your thoughts on the removal instructions given above








Free Questionnaires

Hashes [?]

PropertyValue
MD520b50e68c813b2da91cca0cc28f0b9a0
SHA2566acc9e76299202550a9aaa370306a63806454f1943cf21cffefe81ef9ac81e6a

Error Messages

These are some of the error messages that can appear related to vc36a100r.exe:

vc36a100r.exe has encountered a problem and needs to close. We are sorry for the inconvenience.

vc36a100r.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.

vc36a100r.exe has stopped working.

End Program - vc36a100r.exe. This program is not responding.

vc36a100r.exe is not a valid Win32 application.

vc36a100r.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.

What will you do with vC36a100r.exe?

To help other users, please let us know what you will do with vC36a100r.exe:



Comments

Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.

I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.

No comments posted yet.

Leave a reply