-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathsum.json
More file actions
1 lines (1 loc) · 331 KB
/
sum.json
File metadata and controls
1 lines (1 loc) · 331 KB
1
{"keys": ["HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLEAUT", "DisableUserModeCallbackFilter", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\CustomLocale", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\ExtendedLocale", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Windows Error Reporting\\WMR", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\WMR\\Disable", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\GRE_Initialize\\DisableMetaFiles", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\Locale", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\Locale\\Alternate Sorts", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\Language Groups", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontLink\\SystemLink", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\DataStore_V1.0\\Disable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\DataStore_V1.0\\DataFilePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane2", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane3", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane4", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane6", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane7", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane8", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane9", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane10", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane11", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane12", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane13", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane14", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane15", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane16", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Segoe UI", "HKEY_CURRENT_USER\\Software\\Classes", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SQMClient\\Windows", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SQMClient\\Windows\\CEIPEnable", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SQMClient\\Windows", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Versions\\00060101.00060101", "HKEY_CURRENT_USER", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\SafeProcessSearchMode", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer", "HKEY_CLASSES_ROOT\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ee82dad3-29d6-11ec-88e3-806e6f6e6963}\\", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ee82dad3-29d6-11ec-88e3-806e6f6e6963}\\Data", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ee82dad3-29d6-11ec-88e3-806e6f6e6963}\\Generation", "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions", "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ee82dad6-29d6-11ec-88e3-806e6f6e6963}\\", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ee82dad6-29d6-11ec-88e3-806e6f6e6963}\\Data", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ee82dad6-29d6-11ec-88e3-806e6f6e6963}\\Generation", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ee82dad2-29d6-11ec-88e3-806e6f6e6963}\\", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ee82dad2-29d6-11ec-88e3-806e6f6e6963}\\Data", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ee82dad2-29d6-11ec-88e3-806e6f6e6963}\\Generation", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\LSA\\AccessProviders", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay", "HKEY_CLASSES_ROOT\\Folder", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0\\Disable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0\\DataFilePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane2", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane3", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane4", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane6", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane7", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane8", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane9", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane10", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane11", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane12", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane13", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane14", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane15", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane16", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System", "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\System", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\DisableUNCCheck", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\EnableExtensions", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\DelayedExpansion", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\DefaultColor", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\CompletionChar", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\PathCompletionChar", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\AutoRun", "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor", "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DisableUNCCheck", "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\EnableExtensions", "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DelayedExpansion", "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DefaultColor", "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\CompletionChar", "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\PathCompletionChar", "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\AutoRun", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles", "HKEY_LOCAL_MACHINE\\system\\CurrentControlSet", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\control\\NetworkProvider\\HwOrder", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\NetworkProvider\\HwOrder\\ProviderOrder", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPNP\\NetworkProvider", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPNP\\NetworkProvider\\name", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPNP\\NetworkProvider\\Class", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPNP\\NetworkProvider\\ProviderPath", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\NetworkProvider", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\NetworkProvider\\name", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\NetworkProvider\\Class", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\NetworkProvider\\ProviderPath", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\webclient\\NetworkProvider", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\NetworkProvider\\name", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\NetworkProvider\\Class", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\NetworkProvider\\ProviderPath", "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\Rpc", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LanmanWorkstation\\NetworkProvider", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\NetworkProvider\\Name", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\SafeBoot\\Option", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\.NETFramework\\Policy\\", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\Policy\\v4.0", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\.NETFramework", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\InstallRoot", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\CLRLoadLogDir", "HKEY_CURRENT_USER\\Software\\Microsoft\\.NETFramework", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\UseLegacyV2RuntimeActivationPolicyDefaultValue", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\OnlyUseLatestCLR", "Policy\\Standards", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\Policy\\Standards", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\Policy\\standards\\v4.0.30319", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\NoClientChecks", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\.NETFramework\\v4.0.30319\\SKUs\\", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\v4.0.30319\\SKUs\\default", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\NET Framework Setup\\NDP\\v4\\Full", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\NET Framework Setup\\NDP\\v4\\Full\\Release", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\DisableConfigCache", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Fusion", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\CacheLocation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\DownloadCacheQuotaInKB", "HKEY_CURRENT_USER\\Software\\Microsoft\\Fusion", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\EnableLog", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\LoggingLevel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\ForceLog", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\LogFailures", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\LogResourceBinds", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\FileInUseRetryAttempts", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\FileInUseMillisecondsBetweenRetries", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\UseLegacyIdentityFormat", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\DisableMSIPeek", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\Image File Execution Options\\DevOverrideEnable", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\.NETFramework\\NGen\\Policy\\v4.0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\NGen\\Policy\\v4.0\\OptimizeUsedBinaries", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\Policy\\Servicing", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\StrongName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\UseRyuJIT", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\FeatureSIMD", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Fusion\\PublisherPolicy\\Default", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\Latest", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\index4", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\LegacyPolicyTimeStamp", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\v4.0_policy.4.0.System__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\policy.4.0.System__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\v4.0_policy.4.0.System.Configuration__b03f5f7f11d50a3a", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\policy.4.0.System.Configuration__b03f5f7f11d50a3a", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\v4.0_policy.4.0.System.Xml__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\policy.4.0.System.Xml__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\Policy\\APTCA", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\v4.0_policy.4.0.System.Core__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\policy.4.0.System.Core__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\v4.0_policy.4.0.System.Numerics__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\policy.4.0.System.Numerics__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\v4.0_policy.4.0.System.Security__b03f5f7f11d50a3a", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\policy.4.0.System.Security__b03f5f7f11d50a3a", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\AppContext", "HKEY_CURRENT_USER\\software\\microsoft\\windows\\currentversion\\run", "HKEY_LOCAL_MACHINE\\software\\microsoft\\windows\\currentversion\\run", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\Winlogon\\Userinit", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Script Host\\Settings", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows Script Host\\Settings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows Script Host\\Settings\\IgnoreUserSettings", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Script Host\\Settings\\Enabled", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows Script Host\\Settings\\Enabled", "HKEY_CURRENT_USER\\Software\\Classes\\AppID\\cscript.exe", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Script Host\\Settings\\LogSecuritySuccesses", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows Script Host\\Settings\\LogSecuritySuccesses", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Script Host\\Settings\\TrustPolicy", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Script Host\\Settings\\UseWINSAFER", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows Script Host\\Settings\\TrustPolicy", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows Script Host\\Settings\\UseWINSAFER", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows Script Host\\Settings\\Timeout", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows Script Host\\Settings\\DisplayLogo", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Script Host\\Settings\\Timeout", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Script Host\\Settings\\DisplayLogo", "HKEY_CLASSES_ROOT\\.vbs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.vbs\\(Default)", "HKEY_CLASSES_ROOT\\VBSFile\\ScriptEngine", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VBSFile\\ScriptEngine\\(Default)", "HKEY_CURRENT_USER\\Software\\Classes\\VBScript", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VBScript\\CLSID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VBScript\\CLSID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\Policy\\v4.0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\InstallRoot", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\CLRLoadLogDir", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\UseLegacyV2RuntimeActivationPolicyDefaultValue", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\OnlyUseLatestCLR", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\Policy\\Standards", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NoClientChecks", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\DisableConfigCache", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\CacheLocation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\DownloadCacheQuotaInKB", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\EnableLog", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\LoggingLevel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\ForceLog", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\LogFailures", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\LogResourceBinds", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\UseLegacyIdentityFormat", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\DisableMSIPeek", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\DevOverrideEnable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\Latest", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\index4", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\LegacyPolicyTimeStamp", "HKEY_CURRENT_USER\\Control Panel\\International\\Geo", "HKEY_CURRENT_USER\\Control Panel\\International\\Geo\\Nation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\Policy\\standards\\v4.0.30319", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v4.0.30319\\SKUs\\default", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\NET Framework Setup\\NDP\\v4\\Full\\Release", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\FileInUseRetryAttempts", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\FileInUseMillisecondsBetweenRetries", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\NGen\\Policy\\v4.0\\OptimizeUsedBinaries", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\UseRyuJIT", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\FeatureSIMD", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\v4.0_policy.4.0.System__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\policy.4.0.System__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\v4.0_policy.4.0.System.Configuration__b03f5f7f11d50a3a", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\policy.4.0.System.Configuration__b03f5f7f11d50a3a", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\v4.0_policy.4.0.System.Xml__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\policy.4.0.System.Xml__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\v4.0_policy.4.0.System.Core__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\policy.4.0.System.Core__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\v4.0_policy.4.0.System.Numerics__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\policy.4.0.System.Numerics__b77a5c561934e089", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\v4.0_policy.4.0.System.Security__b03f5f7f11d50a3a", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\policy.4.0.System.Security__b03f5f7f11d50a3a", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\cmd.exe", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\PoEQoAEI.exe", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\QgQAYoYM.exe", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\choco.exe", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\QgQAYoYM.exe", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Times", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\PoEQoAEI.exe"], "resolved_apis": ["kernel32.dll.GetModuleHandleA", "kernel32.dll.CreateFileA", "kernel32.dll.GetModuleHandleW", "kernel32.dll.VirtualAlloc", "kernel32.dll.ReadFile", "kernel32.dll.GetTickCount", "kernel32.dll.Sleep", "kernel32.dll.DeleteFileW", "kernel32.dll.GetSystemTimeAsFileTime", "kernel32.dll.GetCurrentProcessId", "kernel32.dll.GetCurrentThreadId", "kernel32.dll.CreateDirectoryW", "kernel32.dll.GetCommandLineW", "kernel32.dll.GetFileSize", "kernel32.dll.GetModuleFileNameW", "kernel32.dll.CloseHandle", "kernel32.dll.WriteFile", "kernel32.dll.CreateFileW", "kernel32.dll.GetLastError", "kernel32.dll.TerminateProcess", "kernel32.dll.IsDebuggerPresent", "kernel32.dll.ExitProcess", "kernel32.dll.GetStdHandle", "kernel32.dll.GetFileType", "user32.dll.LoadStringW", "user32.dll.PostQuitMessage", "user32.dll.EndPaint", "user32.dll.BeginPaint", "user32.dll.DestroyWindow", "user32.dll.SetTimer", "user32.dll.UpdateWindow", "user32.dll.TranslateMessage", "advapi32.dll.GetUserNameW", "advapi32.dll.RegCloseKey", "advapi32.dll.RegSetValueExW", "advapi32.dll.RegOpenKeyExW", "advapi32.dll.RegQueryValueExW", "shell32.dll.ShellExecuteExW", "ole32.dll.CoUninitialize", "ole32.dll.CoInitializeEx", "kernel32.dll.UnmapViewOfFile", "kernel32.dll.FlsAlloc", "kernel32.dll.FlsGetValue", "kernel32.dll.FlsSetValue", "kernel32.dll.FlsFree", "uxtheme.dll.ThemeInitApiHook", "user32.dll.IsProcessDPIAware", "dwmapi.dll.DwmIsCompositionEnabled", "advapi32.dll.RegQueryInfoKeyW", "advapi32.dll.RegEnumValueW", "advapi32.dll.RegQueryValueExA", "advapi32.dll.RegEnumKeyExW", "cryptbase.dll.SystemFunction036", "sechost.dll.LookupAccountNameLocalW", "advapi32.dll.LookupAccountSidW", "sechost.dll.LookupAccountSidLocalW", "oleaut32.dll.#500", "advapi32.dll.LookupAccountNameW", "kernel32.dll.SetFilePointer", "kernel32.dll.SuspendThread", "kernel32.dll.CreateThread", "kernel32.dll.WaitForSingleObject", "kernel32.dll.WinExec", "kernel32.dll.FindClose", "kernel32.dll.CopyFileA", "kernel32.dll.DeleteFileA", "kernel32.dll.SetFileAttributesA", "kernel32.dll.GetCommandLineA", "kernel32.dll.ResumeThread", "user32.dll.GetMessageA", "user32.dll.DefWindowProcA", "user32.dll.LoadIconA", "gdi32.dll.CreateCompatibleDC", "gdi32.dll.DeleteObject", "gdi32.dll.TextOutA", "gdi32.dll.SetBkColor", "gdi32.dll.SetTextColor", "gdi32.dll.CreateSolidBrush", "gdi32.dll.CreateFontIndirectA", "advapi32.dll.GetUserNameA", "kernel32.dll.FreeLibrary", "user32.dll.LoadCursorA", "user32.dll.CreateWindowExA", "kernel32.dll.SortGetHandle", "kernel32.dll.SortCloseHandle", "sechost.dll.OpenSCManagerW", "sechost.dll.OpenServiceW", "sechost.dll.QueryServiceStatus", "sechost.dll.CloseServiceHandle", "rpcrt4.dll.RpcStringBindingComposeW", "rpcrt4.dll.RpcBindingFromStringBindingW", "rpcrt4.dll.RpcStringFreeW", "rpcrt4.dll.NdrClientCall2", "ole32.dll.CoTaskMemAlloc", "ole32.dll.CoTaskMemFree", "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW", "setupapi.dll.CM_Get_Device_Interface_List_ExW", "comctl32.dll.#332", "advapi32.dll.InitializeSecurityDescriptor", "advapi32.dll.SetEntriesInAclW", "ntmarta.dll.GetMartaExtensionInterface", "comctl32.dll.#386", "advapi32.dll.SetSecurityDescriptorDacl", "kernel32.dll.AcquireSRWLockExclusive", "kernel32.dll.ReleaseSRWLockExclusive", "kernel32.dll.RaiseException", "kernel32.dll.OpenProcess", "kernel32.dll.CreateToolhelp32Snapshot", "kernel32.dll.GetFileAttributesW", "kernel32.dll.FindFirstFileW", "kernel32.dll.FindNextFileW", "kernel32.dll.CopyFileW", "kernel32.dll.TerminateThread", "kernel32.dll.VirtualFree", "kernel32.dll.SetFileAttributesW", "kernel32.dll.SetEvent", "kernel32.dll.GetEnvironmentVariableW", "kernel32.dll.GlobalLock", "kernel32.dll.GlobalUnlock", "kernel32.dll.GlobalAlloc", "kernel32.dll.GlobalFree", "kernel32.dll.CreateProcessW", "kernel32.dll.LoadLibraryA", "kernel32.dll.GetCurrentDirectoryW", "kernel32.dll.ExitThread", "advapi32.dll.CloseServiceHandle", "advapi32.dll.OpenProcessToken", "advapi32.dll.CreateProcessWithLogonW", "advapi32.dll.LogonUserW", "advapi32.dll.OpenSCManagerW", "gdi32.dll.CreateCompatibleBitmap", "gdi32.dll.SelectObject", "gdi32.dll.GetDIBits", "gdi32.dll.DeleteDC", "mpr.dll.WNetCancelConnection2W", "mpr.dll.WNetAddConnection2W", "ole32.dll.CreateStreamOnHGlobal", "kernel32.dll.CreateFileMappingA", "kernel32.dll.GetModuleFileNameA", "kernel32.dll.CreateProcessA", "advapi32.dll.RegOpenKeyExA", "kernel32.dll.GetEnvironmentVariableA", "ws2_32.dll.WSAStartup", "ws2_32.dll.recv", "ws2_32.dll.send", "ws2_32.dll.closesocket", "ws2_32.dll.connect", "ws2_32.dll.htons", "ws2_32.dll.gethostbyname", "ws2_32.dll.socket", "user32.dll.DispatchMessageA", "user32.dll.GetSystemMetrics", "user32.dll.GetForegroundWindow", "user32.dll.FindWindowA", "kernel32.dll.SetThreadUILanguage", "kernel32.dll.CopyFileExW", "kernel32.dll.SetConsoleInputExeNameW", "kernel32.dll.GetCurrentProcessorNumber", "kernel32.dll.ProcessIdToSessionId", "kernel32.dll.LocalFree", "kernel32.dll.LocalAlloc", "kernel32.dll.MapViewOfFile", "kernel32.dll.GetLogicalDriveStringsA", "kernel32.dll.CreateEventA", "gdi32.dll.GetObjectA", "gdi32.dll.CreateDIBSection", "gdi32.dll.BitBlt", "user32.dll.UnregisterClassA", "user32.dll.ShowWindow", "user32.dll.SetWindowPos", "user32.dll.SetClipboardData", "user32.dll.SetClassLongA", "user32.dll.SendMessageA", "kernel32.dll.CreateMutexA", "kernel32.dll.Process32First", "kernel32.dll.Process32Next", "advapi32.dll.LsaAddAccountRights", "advapi32.dll.LsaOpenPolicy", "kernel32.dll.ReleaseMutex", "drprov.dll.NPGetCaps", "drprov.dll.NPAddConnection", "drprov.dll.NPAddConnection3", "drprov.dll.NPCancelConnection", "drprov.dll.NPGetConnection", "drprov.dll.NPGetUniversalName", "drprov.dll.NPOpenEnum", "drprov.dll.NPEnumResource", "drprov.dll.NPCloseEnum", "drprov.dll.NPGetResourceParent", "drprov.dll.NPGetResourceInformation", "ntlanman.dll.NPGetCaps", "ntlanman.dll.NPGetUser", "ntlanman.dll.NPAddConnection", "ntlanman.dll.NPAddConnection3", "ntlanman.dll.NPGetReconnectFlags", "ntlanman.dll.NPCancelConnection", "ntlanman.dll.NPGetConnection", "ntlanman.dll.NPGetConnection3", "ntlanman.dll.NPGetUniversalName", "ntlanman.dll.NPGetConnectionPerformance", "ntlanman.dll.NPOpenEnum", "ntlanman.dll.NPEnumResource", "ntlanman.dll.NPCloseEnum", "ntlanman.dll.NPFormatNetworkName", "ntlanman.dll.NPGetResourceParent", "ntlanman.dll.NPGetResourceInformation", "davclnt.dll.NPGetCaps", "davclnt.dll.NPGetUser", "davclnt.dll.NPAddConnection", "davclnt.dll.NPAddConnection3", "davclnt.dll.NPCancelConnection", "davclnt.dll.NPGetConnection", "davclnt.dll.NPGetUniversalName", "davclnt.dll.NPOpenEnum", "davclnt.dll.NPEnumResource", "davclnt.dll.NPCloseEnum", "davclnt.dll.NPFormatNetworkName", "davclnt.dll.NPGetResourceParent", "davclnt.dll.NPGetResourceInformation", "advapi32.dll.CreateWellKnownSid", "rpcrt4.dll.RpcBindingSetAuthInfoExW", "rpcrt4.dll.RpcBindingFree", "wkscli.dll.NetWkstaGetInfo", "cscapi.dll.CscNetApiGetInterface", "netutils.dll.NetApiBufferFree", "browcli.dll.NetServerEnum", "netutils.dll.NetApiBufferAllocate", "kernel32.dll.CreateDirectoryA", "kernel32.dll.InitializeCriticalSectionEx", "kernel32.dll.LCMapStringEx", "user32.dll.GetDC", "kernel32.dll.UpdateResourceA", "kernel32.dll.EndUpdateResourceA", "kernel32.dll.BeginUpdateResourceA", "kernel32.dll.OpenThread", "advapi32.dll.AllocateAndInitializeSid", "kernel32.dll.GetLocaleInfoEx", "user32.dll.DrawTextW", "user32.dll.DrawTextA", "user32.dll.FillRect", "gdi32.dll.TextOutW", "advapi32.dll.FreeSid", "advapi32.dll.CheckTokenMembership", "kernel32.dll.GetLogicalDriveStringsW", "user32.dll.RegisterClassExA", "netapi32.dll.NetApiBufferFree", "user32.dll.GetKeyboardState", "user32.dll.OpenClipboard", "user32.dll.EmptyClipboard", "user32.dll.CloseClipboard", "user32.dll.InvalidateRect", "user32.dll.GetKeyState", "user32.dll.GetIconInfo", "user32.dll.DrawIcon", "user32.dll.DestroyIcon", "advapi32.dll.SetEntriesInAclA", "user32.dll.FindWindowExA", "ws2_32.dll.select", "ws2_32.dll.getsockname", "advapi32.dll.SetServiceStatus", "advapi32.dll.QueryServiceStatus", "advapi32.dll.CreateServiceW", "advapi32.dll.OpenServiceW", "advapi32.dll.StartServiceW", "shell32.dll.ExtractIconExW", "ws2_32.dll.ioctlsocket", "kernel32.dll.RtlZeroMemory", "oleaut32.dll.OleLoadPicture", "shell32.dll.ExtractAssociatedIconW", "ws2_32.dll.bind", "ws2_32.dll.shutdown", "ws2_32.dll.htonl", "ws2_32.dll.listen", "ws2_32.dll.accept", "ws2_32.dll.getpeername", "netapi32.dll.NetUserAdd", "advapi32.dll.SetNamedSecurityInfoW", "wtsapi32.dll.WTSLogoffSession", "wtsapi32.dll.WTSFreeMemory", "advapi32.dll.ConvertSidToStringSidA", "samlib.dll.SamConnect", "samlib.dll.SamEnumerateDomainsInSamServer", "samlib.dll.SamLookupDomainInSamServer", "samlib.dll.SamFreeMemory", "samlib.dll.SamOpenDomain", "samlib.dll.SamCloseHandle", "advapi32.dll.StartServiceCtrlDispatcherW", "advapi32.dll.RegisterServiceCtrlHandlerW", "shell32.dll.ExtractAssociatedIconA", "netapi32.dll.NetUserSetInfo", "netapi32.dll.NetLocalGroupAddMembers", "wtsapi32.dll.WTSEnumerateSessionsA", "kernel32.dll.BeginUpdateResourceW", "mpr.dll.WNetEnumResourceW", "kernel32.dll.GetUserGeoID", "mpr.dll.WNetOpenEnumW", "netapi32.dll.NetLocalGroupDelMembers", "advapi32.dll.ConvertStringSidToSidA", "netapi32.dll.NetLocalGroupGetMembers", "netapi32.dll.NetLocalGroupAdd", "user32.dll.InSendMessage", "netapi32.dll.NetLocalGroupDel"], "executed_commands": ["C:\\Windows\\USR_Shohdi_Photo_USR.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\00093972889ca75c5958faf ", "C:\\Windows\\svhost.exe", "REG DELETE HKLM\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot /f", "C:\\Users\\John\\AppData\\Local\\Temp\\avscan.exe", "c:\\windows\\W_X_C.bat", "cmd.exe", "C:\\123.bat", "cmd.exe /c assoc .txt = exefile", "cmd.exe /c ftype comfile=C:\\Users\\John\\AppData\\Local\\Temp\\001810244a8174f91ca2d268.exe", "cmd.exe /c ftype zipfile=C:\\Users\\John\\AppData\\Local\\Temp\\001810244a8174f91ca2d268.exe", "cmd.exe /c ftype jpgfile=C:\\Users\\John\\AppData\\Local\\Temp\\001810244a8174f91ca2d268.exe", "cmd.exe /c ftype txtfile=C:\\Users\\John\\AppData\\Local\\Temp\\001810244a8174f91ca2d268.exe", "\"C:\\Users\\John\\AppData\\Local\\Temp\\Ikavapit.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\Ikavapit.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\002c25c2faae53d4eba08d1d.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\002c25c2faae53d4eba08d1d.exe ", "c:\\windows\\resources\\themes\\explorer.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\004bbfd7a5d13bed5a521c5 ", "\"C:\\Users\\John\\AppData\\Roaming\\Microsoft\\Search\\SearchHelper.exe\"", "\"\\\\.\\C:\\Users\\John\\AppData\\Local\\Temp\\WER9mso.dir00\\com3.exe\"", "\"C:\\Users\\John\\AppData\\Local\\Temp\\005ed0da93e60b217027e09c.exe\" silent pause", "C:\\Users\\John\\AppData\\Local\\Temp\\005ed0da93e60b217027e09c.exe silent pause", "\"C:\\Windows\\System32\\reg.exe\" ADD HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run /f /t REG_SZ /v \"Intel GPU\" /d \"C:\\Program Files\\Intel GPU\\GfxUI.exe\"", "REG ADD HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run /f /t REG_SZ /v \"Intel GPU\" /d \"C:\\Program Files\\Intel GPU\\GfxUI.exe\"", "nslookup carder.bit ns1.wowservers.ru", "nslookup ransomware.bit ns2.wowservers.ru", "nslookup carder.bit ns2.wowservers.ru", "nslookup ransomware.bit ns1.wowservers.ru", "\"C:\\Users\\John\\AppData\\Local\\Temp\\CTS.exe\"", "nslookup politiaromana.bit ns1.virmach.ru", "nslookup malwarehunterteam.bit ns1.virmach.ru", "nslookup gdcb.bit ns2.virmach.ru", "nslookup politiaromana.bit ns2.virmach.ru", "nslookup malwarehunterteam.bit ns2.virmach.ru", "C:\\Users\\John\\AppData\\Local\\Temp\\00a3e344d657b3c621dc0ec ", "C:\\Users\\John\\AppData\\Local\\Temp\\00b01da492e36109df79809 ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\szgfw.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\szgfw.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\updater.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\updater.exe ", "nslookup gdcb.bit ns1.virmach.ru", "\"C:\\Users\\John\\AppData\\Local\\Temp\\papers.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\papers.exe ", "WYZX", "C:\\Users\\John\\AppData\\Local\\Temp\\00fdb1dca56d4f06ec36452b.exe WYZX", "\"C:\\Users\\John\\UgoAQQAk\\mMIUIsUE.exe\"", "\"C:\\ProgramData\\OGQgwook\\FKcUoEQI.exe\"", "\"C:\\Users\\John\\AppData\\Local\\Temp\\00fdb1dca56d4f06ec36452b\"", "C:\\Windows\\system32\\cmd.exe /c \"C:\\Users\\John\\AppData\\Local\\Temp\\00fdb1dca56d4f06ec36452b\"", "reg add HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced /f /v HideFileExt /t REG_DWORD /d 1", "reg add HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced /f /v Hidden /t REG_DWORD /d 2", "reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System /v EnableLUA /d 0 /t REG_DWORD /f", "SWLD", "C:\\Users\\John\\UgoAQQAk\\mMIUIsUE.exe SWLD", "KFNR", "C:\\ProgramData\\OGQgwook\\FKcUoEQI.exe KFNR", "C:\\Users\\John\\AppData\\Local\\Temp\\00fdb1dca56d4f06ec36452b", "C:\\Users\\John\\AppData\\Local\\Temp\\00fe0f738dc6b44eeb542de ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\0100105ce52b48a3a42fa455.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\0100105ce52b48a3a42fa455.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\hummy.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\hummy.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\015c80930c8e27ceeb95802d.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\015c80930c8e27ceeb95802d.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\ahyguys.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\ahyguys.exe ", "cmd.exe /c ftype comfile=C:\\Users\\John\\AppData\\Local\\Temp\\016a1ddd6b8383ba259f9bd7.exe", "cmd.exe /c ftype zipfile=C:\\Users\\John\\AppData\\Local\\Temp\\016a1ddd6b8383ba259f9bd7.exe", "cmd.exe /c ftype jpgfile=C:\\Users\\John\\AppData\\Local\\Temp\\016a1ddd6b8383ba259f9bd7.exe", "cmd.exe /c ftype txtfile=C:\\Users\\John\\AppData\\Local\\Temp\\016a1ddd6b8383ba259f9bd7.exe", "\"C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\0176a0157ddc052cbf8ed3fd.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\0176a0157ddc052cbf8ed3fd.exe ", "C:\\Windows\\splwow64.exe 8192", "C:\\Users\\John\\AppData\\Local\\Temp\\017d9d8876465dde5f0ea39 ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\vokfg.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\vokfg.exe ", "c:\\users\\john\\appdata\\local\\temp\\\\wmpscfgs.exe", "C:\\Program Files (x86)\\Adobe\\acrord32.exe", "C:\\Program Files (x86)\\Adobe\\acrord32.exe C:\\Program Files (x86)\\Adobe\\acrord32.exe", "C:\\Program Files (x86)\\Adobe\\AcrobatInfo.exe", "C:\\Program Files (x86)\\Adobe\\AcrobatInfo.exe C:\\Program Files (x86)\\Adobe\\AcrobatInfo.exe", "C:\\Program Files (x86)\\Internet Explorer\\wmpscfgs.exe", "C:\\Program Files (x86)\\Internet Explorer\\wmpscfgs.exe C:\\Program Files (x86)\\Internet Explorer\\wmpscfgs.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\01ad39e45535509f73672d4 ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\pdfmarks.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\pdfmarks.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\01d698c765371a84ef679497.exe\" silent pause", "C:\\Users\\John\\AppData\\Local\\Temp\\01d698c765371a84ef679497.exe silent pause", "C:\\Users\\John\\AppData\\Local\\Temp\\01de1e99ebb0497f0e663db ", "/c sc stop WinDefend", "C:\\Windows\\system32\\cmd.exe /c sc stop WinDefend", "/c sc delete WinDefend", "C:\\Windows\\system32\\cmd.exe /c sc delete WinDefend", "/c powershell Set-MpPreference -DisableRealtimeMonitoring $true", "C:\\Windows\\system32\\cmd.exe /c powershell Set-MpPreference -DisableRealtimeMonitoring $true", "sc stop WinDefend", "sc delete WinDefend", "powershell Set-MpPreference -DisableRealtimeMonitoring $true", "\"C:\\Users\\John\\AppData\\Local\\Temp\\01e154bd0accf2e378cb31e0.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\01e154bd0accf2e378cb31e0.exe ", "cmd.exe /c ftype comfile=C:\\Users\\John\\AppData\\Local\\Temp\\01e4e94c2d08e77faec8383b.exe", "cmd.exe /c ftype zipfile=C:\\Users\\John\\AppData\\Local\\Temp\\01e4e94c2d08e77faec8383b.exe", "cmd.exe /c ftype jpgfile=C:\\Users\\John\\AppData\\Local\\Temp\\01e4e94c2d08e77faec8383b.exe", "cmd.exe /c ftype txtfile=C:\\Users\\John\\AppData\\Local\\Temp\\01e4e94c2d08e77faec8383b.exe", "c:\\windows\\system\\explorer.exe", "\"C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\01f71799ac75ac9788dbedf7.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\01f71799ac75ac9788dbedf7.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\01f8fc13833c8dbb4fa0ff0 ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\020c35e6efff24073a493c19.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\020c35e6efff24073a493c19.exe ", "cmd.exe /c ftype comfile=C:\\Users\\John\\AppData\\Local\\Temp\\021752af253362b760c510c8.exe", "cmd.exe /c ftype zipfile=C:\\Users\\John\\AppData\\Local\\Temp\\021752af253362b760c510c8.exe", "cmd.exe /c ftype jpgfile=C:\\Users\\John\\AppData\\Local\\Temp\\021752af253362b760c510c8.exe", "cmd.exe /c ftype txtfile=C:\\Users\\John\\AppData\\Local\\Temp\\021752af253362b760c510c8.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\0246e74c0a3acce69f4f7b9 ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\_uinsey.bat\"", "C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Users\\John\\AppData\\Local\\Temp\\_uinsey.bat\" \"", "C:\\Users\\John\\AppData\\Local\\Temp\\_uinsey.bat ", "C:\\Program Files (x86)\\8e9df131\\jusched.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\ntprint.exe", "\"C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegAsm.exe\"", "\"C:\\Windows\\System32\\cmd.exe\" /c TimeOut 1 & Del /F \"C:\\Users\\John\\AppData\\Local\\Temp\\0280a438998b6122b624af74.exe\"", "cmd /c TimeOut 1 & Del /F \"C:\\Users\\John\\AppData\\Local\\Temp\\0280a438998b6122b624af74.exe\"", "TimeOut 1", "C:\\Windows\\system32\\timeout.exe TimeOut 1", "/c del \"C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegAsm.exe\"", "C:\\Windows\\SysWOW64\\cmd.exe /c del \"C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegAsm.exe\"", "\"C:\\Users\\John\\AppData\\Local\\Temp\\02894225fed3c9f85d90eb3e.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\02894225fed3c9f85d90eb3e.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\02a3ae564fbb1eaeee734e1 ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\02c26bb15ffb1e2925f2a23c.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\02c26bb15ffb1e2925f2a23c.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\02d6d7a4859a2de5221b965 ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\02fb6ada0fac1dfa52d1a168.exe\"", "cmd /c wmic ntdomain get domainname", "cmd /c net localgroup administrators", "cmd /c net group \"domain admins\" /domain", "C:\\Windows\\SysNative\\WindowsPowerShell\\v1.0\\powershell.exe -exec bypass \"import-module C:\\Users\\John\\AppData\\Local\\Temp\\m2.ps1\"", "wmic ntdomain get domainname", "C:\\Windows\\System32\\Wbem\\WMIC.exe wmic ntdomain get domainname", "net localgroup administrators", "C:\\Windows\\system32\\net1 localgroup administrators", "net group \"domain admins\" /domain", "C:\\Windows\\system32\\net1 group \"domain admins\" /domain", "C:\\ ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\0319c8f27285fb3c2ed276d7.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\0319c8f27285fb3c2ed276d7.exe ", "cmd.exe /c ftype comfile=C:\\Users\\John\\AppData\\Local\\Temp\\031ba776b04d0795fc7dbf4b.exe", "cmd.exe /c ftype zipfile=C:\\Users\\John\\AppData\\Local\\Temp\\031ba776b04d0795fc7dbf4b.exe", "cmd.exe /c ftype jpgfile=C:\\Users\\John\\AppData\\Local\\Temp\\031ba776b04d0795fc7dbf4b.exe", "cmd.exe /c ftype txtfile=C:\\Users\\John\\AppData\\Local\\Temp\\031ba776b04d0795fc7dbf4b.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\031eabaa5592cac7d34848f ", "powershell.exe -command \"Invoke-WebRequest \"https://raw.githubusercontent.com/\" \"", "mshta vbscript:msgbox(\"\\xce\\xc4\\xbc\\xfe\\xcb\\xf0\\xbb\\xb5\",16,\"\")(window.close)", "C:\\Users\\John\\AppData\\Local\\Temp\\035148f5220ae59cf691735 ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\retro.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\retro.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\weyjba.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\weyjba.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\03675f2e0f7d25abe87ad935.exe", "cmd.exe /c ftype comfile=C:\\Users\\John\\AppData\\Local\\Temp\\037193903cf0c63f7d0fffee.exe", "cmd.exe /c ftype zipfile=C:\\Users\\John\\AppData\\Local\\Temp\\037193903cf0c63f7d0fffee.exe", "cmd.exe /c ftype jpgfile=C:\\Users\\John\\AppData\\Local\\Temp\\037193903cf0c63f7d0fffee.exe", "cmd.exe /c ftype txtfile=C:\\Users\\John\\AppData\\Local\\Temp\\037193903cf0c63f7d0fffee.exe", "\"C:\\Users\\John\\AppData\\Local\\Temp\\kyyjs.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\kyyjs.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\037bd286ca23da62310f52e9.exe\"", "\"C:\\Users\\John\\AppData\\Local\\Temp\\038ce1ccaa91b7eb1f74d313.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\038ce1ccaa91b7eb1f74d313.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\budha.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\budha.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\zbhnd.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\zbhnd.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\03a258be89c8fa7908b8fe6f.exe\" silent pause", "C:\\Users\\John\\AppData\\Local\\Temp\\03a258be89c8fa7908b8fe6f.exe silent pause", "C:\\Users\\John\\AppData\\Local\\Temp\\03ae8a55409934b5011c0de ", "C:\\Users\\John\\AppData\\Local\\Temp\\famudit.exe", "\"C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\03df930ac9de35f23bfe3672.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\03df930ac9de35f23bfe3672.exe ", "C:\\Program Files (x86)\\Java\\jre-09\\bin\\jusched.exe ", "cmd.exe /c ftype comfile=C:\\Users\\John\\AppData\\Local\\Temp\\03f61efd94a574accc7e28b4.exe", "cmd.exe /c ftype zipfile=C:\\Users\\John\\AppData\\Local\\Temp\\03f61efd94a574accc7e28b4.exe", "cmd.exe /c ftype jpgfile=C:\\Users\\John\\AppData\\Local\\Temp\\03f61efd94a574accc7e28b4.exe", "cmd.exe /c ftype txtfile=C:\\Users\\John\\AppData\\Local\\Temp\\03f61efd94a574accc7e28b4.exe", "\"C:\\Users\\John\\AppData\\Local\\Temp\\03fa4bf8a37a784d134ad32c.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\03fa4bf8a37a784d134ad32c.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\03fa601be60683073a3b374 ", "C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe \"C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe \"C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe\" C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe \"C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe\" C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe \"C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe\" C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe \"C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe\" C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe \"C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe\" C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe C:\\Users\\John\\AppData\\Local\\Temp\\0415bdd23a878f9232b08c73.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\043a343e87d9a089abb67a2 ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\043bef57c4b227b777dba9f4.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\043bef57c4b227b777dba9f4.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\044a79dd6f35d5aec9fbaa21.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\044a79dd6f35d5aec9fbaa21.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\asih.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\asih.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\0468e50ea2b1f20483c0b2b0.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\046f9d796767fa519248d5a ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\dofhir.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\dofhir.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\sanfdr.bat\"", "C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Users\\John\\AppData\\Local\\Temp\\sanfdr.bat\" \"", "C:\\Users\\John\\AppData\\Local\\Temp\\sanfdr.bat ", "C:\\Users\\John\\AppData\\Local\\Temp\\tmp5fdr.exe ", "cmd.exe /c ftype comfile=C:\\Users\\John\\AppData\\Local\\Temp\\048be7c3aec0bf66870b324d.exe", "cmd.exe /c ftype zipfile=C:\\Users\\John\\AppData\\Local\\Temp\\048be7c3aec0bf66870b324d.exe", "cmd.exe /c ftype jpgfile=C:\\Users\\John\\AppData\\Local\\Temp\\048be7c3aec0bf66870b324d.exe", "cmd.exe /c ftype txtfile=C:\\Users\\John\\AppData\\Local\\Temp\\048be7c3aec0bf66870b324d.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\04a5f52f0df033300e7393d ", "C:\\Users\\John\\AppData\\Local\\Temp\\04be8f997682b3ce5b4185a ", "cmd.exe /c ftype comfile=C:\\Users\\John\\AppData\\Local\\Temp\\04c12cef8c8362a5c6018da3.exe", "cmd.exe /c ftype zipfile=C:\\Users\\John\\AppData\\Local\\Temp\\04c12cef8c8362a5c6018da3.exe", "cmd.exe /c ftype jpgfile=C:\\Users\\John\\AppData\\Local\\Temp\\04c12cef8c8362a5c6018da3.exe", "cmd.exe /c ftype txtfile=C:\\Users\\John\\AppData\\Local\\Temp\\04c12cef8c8362a5c6018da3.exe", "attrib -r -s -h \"C:\\Users\\John\\AppData\\Local\\Temp\\04c4a6246fb72a189f653fe2.exe\"", "\"C:\\Users\\John\\AppData\\Local\\Temp\\htiof.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\htiof.exe ", "cmd.exe /c ftype comfile=C:\\Users\\John\\AppData\\Local\\Temp\\04ec38a63e28dfd61a9c17a3.exe", "cmd.exe /c ftype zipfile=C:\\Users\\John\\AppData\\Local\\Temp\\04ec38a63e28dfd61a9c17a3.exe", "cmd.exe /c ftype jpgfile=C:\\Users\\John\\AppData\\Local\\Temp\\04ec38a63e28dfd61a9c17a3.exe", "cmd.exe /c ftype txtfile=C:\\Users\\John\\AppData\\Local\\Temp\\04ec38a63e28dfd61a9c17a3.exe", "\"C:\\Windows\\System32\\reg.exe\" import C:\\Windows\\regedit.reg", "reg.exe import C:\\Windows\\regedit.reg", "\"C:\\Windows\\System32\\reg.exe\" export HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\srservice C:\\Windows\\regedit.reg", "reg.exe export HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\srservice C:\\Windows\\regedit.reg", "winzip32.exe -min -a -en -r \"C:\\Users\\Public\\Music\\angle.Zip\" \"C:\\Users\\Public\\Music\\angle.eXe\"", "rar.exe a -ao -ep \"C:\\Users\\Public\\Music\\angle.Zip\" \"C:\\Users\\Public\\Music\\angle.eXe\"", "\"C:\\Users\\Public\\Pictures\\svchost.eXe\"", "C:\\Users\\Public\\Pictures\\svchost.eXe ", "\"C:\\Users\\Public\\Music\\svchost.eXe\"", "C:\\Users\\Public\\Music\\svchost.eXe ", "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\msmsgs.eXe ", "C:\\Windows\\System32\\angle.eXe ", "C:\\Users\\John\\AppData\\Local\\Temp\\04ecf83369a38c5318e7cc4 ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\050135612489c7b482ec2ae9.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\050135612489c7b482ec2ae9.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\051229f5fbdd7048c18affe9.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\051229f5fbdd7048c18affe9.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\0512f8e0ed1db20d7854887 ", "C:\\Users\\John\\AppData\\Local\\Temp\\0522c9079ebb1c45755bb29 ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\wefujn.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\wefujn.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\057ccde89a0dd53f56a99faa.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\057ccde89a0dd53f56a99faa.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\057de3c52110087d80acf50 ", "\"C:\\ProgramData\\fyrfl.exe\"", "\"C:\\Users\\John\\AppData\\Local\\Temp\\0584b97e761a6318d438711e.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\0584b97e761a6318d438711e.exe ", "cmd.exe /c ftype comfile=C:\\Users\\John\\AppData\\Local\\Temp\\059f83a3f1278362a6c2ab35.exe", "cmd.exe /c ftype zipfile=C:\\Users\\John\\AppData\\Local\\Temp\\059f83a3f1278362a6c2ab35.exe", "cmd.exe /c ftype jpgfile=C:\\Users\\John\\AppData\\Local\\Temp\\059f83a3f1278362a6c2ab35.exe", "cmd.exe /c ftype txtfile=C:\\Users\\John\\AppData\\Local\\Temp\\059f83a3f1278362a6c2ab35.exe", "\"C:\\Users\\John\\AppData\\Local\\Temp\\05aa74bff300764d43f0eee6.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\05aeaa1e0680b099cae59ee ", "C:\\Users\\John\\AppData\\Local\\Temp\\05bf149963504a897f07373 ", "cmd.exe /c ftype comfile=C:\\Users\\John\\AppData\\Local\\Temp\\05cdc7534ed21d334f38e66b.exe", "cmd.exe /c ftype zipfile=C:\\Users\\John\\AppData\\Local\\Temp\\05cdc7534ed21d334f38e66b.exe", "cmd.exe /c ftype jpgfile=C:\\Users\\John\\AppData\\Local\\Temp\\05cdc7534ed21d334f38e66b.exe", "cmd.exe /c ftype txtfile=C:\\Users\\John\\AppData\\Local\\Temp\\05cdc7534ed21d334f38e66b.exe", "\"C:\\Users\\John\\AppData\\Local\\Temp\\misid.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\misid.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\05cfef9e01549f067f3786e ", "C:\\Users\\John\\AppData\\Local\\Temp\\05d2f69bf93d86a9dbe7dc3 ", "C:\\Users\\John\\AppData\\Local\\Temp\\0600a885e96526234af9d65 ", "\"C:\\ProgramData\\biyxph.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\061e3c5af6885ca4100fd4e8.exe", "nslookup zonealarm.bit ns1.corp-servers.ru", "nslookup ransomware.bit ns2.corp-servers.ru", "nslookup zonealarm.bit ns2.corp-servers.ru", "nslookup ransomware.bit ns1.corp-servers.ru", "C:\\Users\\John\\AppData\\Local\\Temp\\063dcff4c2c3fa4f855f07fd.exe", "winver", "\"C:\\Users\\John\\AppData\\Local\\Temp\\065c94f62c67bf4427b4f34b.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\065c94f62c67bf4427b4f34b.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\ekrakdeep.exe", "\"C:\\Users\\John\\AppData\\Local\\Temp\\java.exe\"", "\"C:\\Users\\John\\AppData\\Local\\Temp\\svchost.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\06650ce538d1d6a216e2dac7 ", "C:\\Windows\\MSY4C7N.{645FF040-5081-101B-9F08-00AA002F954E}\\service.exe ", "C:\\Windows\\MSY4C7N.{645FF040-5081-101B-9F08-00AA002F954E}\\smss.exe ", "C:\\Windows\\MSY4C7N.{645FF040-5081-101B-9F08-00AA002F954E}\\system.exe ", "C:\\Windows\\MSY4C7N.{645FF040-5081-101B-9F08-00AA002F954E}\\winlogon.exe ", "C:\\Windows\\lsass.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\wsace.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\wsace.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\066c387e3a67959c0f66ecee.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\066c387e3a67959c0f66ecee.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\06b559b6620847c44f9a5b16.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\06b559b6620847c44f9a5b16.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\izilysa.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\06c24383c8835410d777658 ", "C:\\Windows\\Web\\Wallpaper\\ ", "C:\\Windows\\System32\\dllcache\\Recycler.{645FF040-5081-101B-9F08-00AA002F954E}\\Global.exe ", "\"C:\\Users\\John\\AppData\\Local\\WallpaperHd\\uninstall.exe\" /S _?=C:\\Users\\John\\AppData\\Local\\WallpaperHd", "\"C:\\Users\\John\\AppData\\Local\\WallpaperHd\\WallpaperHd.exe\" /install \"C:\\Users\\John\\AppData\\Local\\Temp\\06d7e3027acec5914bc89bec.exe\"", "\"C:\\Users\\John\\AppData\\Local\\WallpaperHd\\WallpaperHdHelper64.exe\" /install", "\"C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\06e0a80401572b6fa2801aa4.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\3582-490\\06e0a80401572b6fa2801aa4.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\update.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\update\\ ", "C:\\Users\\John\\AppData\\Local\\Temp\\06f280e69995d2eccaceb2e ", "C:\\Users\\John\\AppData\\Local\\Temp\\antifahib.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\06fa883c246531aa529b256 ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\0705543ae15a08167ca6832e.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\0705543ae15a08167ca6832e.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\conwurm.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\conwurm.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\sander.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\sander.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\_sannuyex.bat\"", "C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Users\\John\\AppData\\Local\\Temp\\_sannuyex.bat\" \"", "C:\\Users\\John\\AppData\\Local\\Temp\\_sannuyex.bat ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\ctfmom.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\ctfmom.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\_uninsep.bat\"", "C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Users\\John\\AppData\\Local\\Temp\\_uninsep.bat\" \"", "C:\\Users\\John\\AppData\\Local\\Temp\\_uninsep.bat ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\kgfdfjdk.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\kgfdfjdk.exe ", "commander.exe /C at 9:00 /interactive C:\\Windows\\svhost.exe", "commander.exe /C schtasks /run /tn at1", "\"C:\\Users\\John\\AppData\\Local\\Temp\\hromi.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\hromi.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\biudfw.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\biudfw.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\evhmc.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\evhmc.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\is-91CVQ.tmp\\backup.exe C:\\Users\\John\\AppData\\Local\\Temp\\is-91CVQ.tmp\\", "C:\\Users\\John\\AppData\\Local\\Temp\\is-LH3O1.tmp\\backup.exe C:\\Users\\John\\AppData\\Local\\Temp\\is-LH3O1.tmp\\", "\"C:\\Users\\John\\AppData\\Local\\Temp\\Low\\System Restore.exe\" C:\\Users\\John\\AppData\\Local\\Temp\\Low\\", "C:\\Users\\John\\AppData\\Local\\Temp\\Low\\System Restore.exe C:\\Users\\John\\AppData\\Local\\Temp\\Low\\", "C:\\Users\\John\\AppData\\Local\\Temp\\MozillaBackgroundTask-308046B0AF4A39CB-backgroundupdate\\backup.exe C:\\Users\\John\\AppData\\Local\\Temp\\MozillaBackgroundTask-308046B0AF4A39CB-backgroundupdate\\", "C:\\Users\\John\\AppData\\Local\\Temp\\v8-compile-cache\\backup.exe C:\\Users\\John\\AppData\\Local\\Temp\\v8-compile-cache\\", "C:\\Users\\John\\AppData\\Local\\Temp\\WPDNSE\\backup.exe C:\\Users\\John\\AppData\\Local\\Temp\\WPDNSE\\", "\\backup.exe \\", "\\System Restore.exe \\", "\\update.exe \\", "\\data.exe \\", "C:\\Users\\John\\AppData\\Local\\Temp\\v8-compile-cache\\8.5.210.26-electron.0\\backup.exe C:\\Users\\John\\AppData\\Local\\Temp\\v8-compile-cache\\8.5.210.26-electron.0\\", "C:\\Users\\John\\AppData\\Local\\Temp\\yaxkodila.exe", "\"C:\\Users\\John\\AppData\\Local\\Temp\\huter.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\huter.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\fiotre.exe ", "C:\\Windows\\Fonts\\John 31 - 3 - 2022\\smss.exe", "C:\\Windows\\Fonts\\John 31 - 3 - 2022\\Gaara.exe", "C:\\Windows\\Fonts\\John 31 - 3 - 2022\\csrss.exe", "C:\\Windows\\system32\\drivers\\Kazekage.exe", "C:\\Windows\\system32\\drivers\\system32.exe", "winmine.exe", "ping -a -l www.rasasayang.com.my 65500", "ping -a -l www.duniasex.com 65500", "calc.exe", "C:\\Windows\\System32\\LSASSMGR.EXE ", "C:\\Windows\\svchost.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\Low\\backup.exe C:\\Users\\John\\AppData\\Local\\Temp\\Low\\", "\"C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe\"", "netsh firewall add allowedprogram \"C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe\" \"RegSvcs.exe\" ENABLE", "\"C:\\Users\\John\\AppData\\Local\\Temp\\lossy.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\lossy.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\MozillaBackgroundTask-308046B0AF4A39CB-backgroundupdate-1\\backup.exe C:\\Users\\John\\AppData\\Local\\Temp\\MozillaBackgroundTask-308046B0AF4A39CB-backgroundupdate-1\\", "C:\\Windows\\System\\LpUXoky.exe", "\"C:\\Users\\John\\AppData\\Local\\Temp\\hcbnaf.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\hcbnaf.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\legan.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\legan.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\Sysqemhzzph.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\Sysqemhzzph.exe ", "\"C:\\Users\\John\\AppData\\Local\\Temp\\Sysqemkhzot.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\Sysqemkhzot.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\olacweegim.exe", "\\\\.\\C:\\Users\\John\\AppData\\Local\\Temp\\Rar$EX7.sr77\\ashcv.exe", "\\\\.\\C:\\Users\\John\\AppData\\Local\\Temp\\Rar$EX7.sr77\\COM7.EXE", "C:\\Users\\John\\AppData\\Local\\Temp\\Rar$EX7.sr77\\vmcis.exe /stext \"C:\\Users\\John\\AppData\\Local\\Temp\\Rar$EX7.sr77\\vmcis.txt\"", "\"C:\\Windows\\System32\\reg.exe\" ADD HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run /f /t REG_SZ /v COM_LOADER /d \"\\\\.\\C:\\Program Files\\PDF_Reader\\bin\\COM7.EXE\"", "REG ADD HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run /f /t REG_SZ /v COM_LOADER /d \"\\\\.\\C:\\Program Files\\PDF_Reader\\bin\\COM7.EXE\"", "\"C:\\Users\\John\\AppData\\Local\\Temp\"", "\"C:\\Users\\John\\PGkcIwUA\\lSwQwMAo.exe\"", "\"C:\\ProgramData\\BucMccgo\\eMUMgsAw.exe\"", "cscript C:\\Users\\John\\AppData\\Local\\Temp/file.vbs", "\"C:\\Windows\\SysWOW64\\svchost.exe\"", "explorer.exe", "\"C:\\Users\\John\\RKMcgggk\\PoEQoAEI.exe\"", "\"C:\\ProgramData\\HWcAckgg\\QgQAYoYM.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\choco.exe", "C:\\Windows\\system32\\cmd.exe /c C:\\Users\\John\\AppData\\Local\\Temp\\choco.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\setup.exe", "C:\\Windows\\system32\\cmd.exe /c C:\\Users\\John\\AppData\\Local\\Temp\\setup.exe", "\"C:\\Users\\John\\AppData\\Local\\Temp\\setup.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\cpack.exe", "C:\\Windows\\system32\\cmd.exe /c C:\\Users\\John\\AppData\\Local\\Temp\\cpack.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\cver.exe", "C:\\Windows\\system32\\cmd.exe /c C:\\Users\\John\\AppData\\Local\\Temp\\cver.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\clist.exe", "C:\\Windows\\system32\\cmd.exe /c C:\\Users\\John\\AppData\\Local\\Temp\\clist.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\chocolatey.exe", "C:\\Windows\\system32\\cmd.exe /c C:\\Users\\John\\AppData\\Local\\Temp\\chocolatey.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\cinst.exe", "C:\\Windows\\system32\\cmd.exe /c C:\\Users\\John\\AppData\\Local\\Temp\\cinst.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\cpush.exe", "C:\\Windows\\system32\\cmd.exe /c C:\\Users\\John\\AppData\\Local\\Temp\\cpush.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\cuninst.exe", "C:\\Windows\\system32\\cmd.exe /c C:\\Users\\John\\AppData\\Local\\Temp\\cuninst.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\Setup.exe", "C:\\Windows\\system32\\cmd.exe /c C:\\Users\\John\\AppData\\Local\\Temp\\Setup.exe", "\"C:\\Users\\John\\AppData\\Local\\Temp\\Setup.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\SDKSetup.exe", "C:\\Windows\\system32\\cmd.exe /c C:\\Users\\John\\AppData\\Local\\Temp\\SDKSetup.exe", "\"C:\\Users\\John\\AppData\\Local\\Temp\\SDKSetup.exe\"", "C:\\Users\\John\\AppData\\Local\\Temp\\Setup.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\cup.exe", "C:\\Windows\\system32\\cmd.exe /c C:\\Users\\John\\AppData\\Local\\Temp\\cup.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\setup.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\SDKSetup.exe ", "C:\\Users\\John\\AppData\\Local\\Temp\\install.exe", "C:\\Windows\\system32\\cmd.exe /c C:\\Users\\John\\AppData\\Local\\Temp\\install.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\t64.exe", "C:\\Windows\\system32\\cmd.exe /c C:\\Users\\John\\AppData\\Local\\Temp\\t64.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\t32.exe", "C:\\Windows\\system32\\cmd.exe /c C:\\Users\\John\\AppData\\Local\\Temp\\t32.exe"], "write_keys": ["HKEY_LOCAL_MACHINE\\Software\\HP710C", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\VMIntel386", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\avscan", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SuperHidden", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\Advanced\\Folder\\HideFileExt\\DefaultValue", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\Advanced\\Folder\\HideFileExt\\UncheckedValue", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\comfile\\shell\\open\\command\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\txtfile\\shell\\open\\command\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell", "(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\regfile\\shell\\open\\command\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)", "ThreadingModel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\ShellServiceObjectDelayLoad\\Web Event Logger", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft\\xffae Windows\\xffae Operating System", "HKEY_CURRENT_USER\\Software\\VB and VBA Program Settings\\Explorer\\Process", "HKEY_CURRENT_USER\\Software\\VB and VBA Program Settings\\Explorer\\Process\\LO", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Search Helper", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\WDM", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{3DB408A3-ABF7-40B7-AC77-D2D6A3CF269F}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{3DB408A3-ABF7-40B7-AC77-D2D6A3CF269F}\\WpadDecisionReason", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{3DB408A3-ABF7-40B7-AC77-D2D6A3CF269F}\\WpadDecisionTime", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{3DB408A3-ABF7-40B7-AC77-D2D6A3CF269F}\\WpadDecision", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{3DB408A3-ABF7-40B7-AC77-D2D6A3CF269F}\\WpadNetworkName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\CTS", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{86639027-E931-4262-BED9-0EB0C34F1DA6}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{86639027-E931-4262-BED9-0EB0C34F1DA6}\\WpadDecisionReason", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{86639027-E931-4262-BED9-0EB0C34F1DA6}\\WpadDecisionTime", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{86639027-E931-4262-BED9-0EB0C34F1DA6}\\WpadDecision", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{86639027-E931-4262-BED9-0EB0C34F1DA6}\\WpadNetworkName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\\1.0\\0\\win32\\(Default)", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{A8FE60A0-D595-42A9-8EA8-83AD6A6E3710}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{A8FE60A0-D595-42A9-8EA8-83AD6A6E3710}\\WpadDecisionReason", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{A8FE60A0-D595-42A9-8EA8-83AD6A6E3710}\\WpadDecisionTime", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{A8FE60A0-D595-42A9-8EA8-83AD6A6E3710}\\WpadDecision", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{A8FE60A0-D595-42A9-8EA8-83AD6A6E3710}\\WpadNetworkName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{6F85D41E-8EB2-4608-8648-A7360A5E5DCC}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{6F85D41E-8EB2-4608-8648-A7360A5E5DCC}\\WpadDecisionReason", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{6F85D41E-8EB2-4608-8648-A7360A5E5DCC}\\WpadDecisionTime", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{6F85D41E-8EB2-4608-8648-A7360A5E5DCC}\\WpadDecision", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{6F85D41E-8EB2-4608-8648-A7360A5E5DCC}\\WpadNetworkName", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\LanguageList", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{B41DB860-8EE4-11D2-9906-E49FADC173CA} {000214E4-0000-0000-C000-000000000046} 0xFFFF", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\load", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{AB05CE41-DC42-451F-B7F3-B746D1D19C08}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{AB05CE41-DC42-451F-B7F3-B746D1D19C08}\\WpadDecisionReason", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{AB05CE41-DC42-451F-B7F3-B746D1D19C08}\\WpadDecisionTime", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{AB05CE41-DC42-451F-B7F3-B746D1D19C08}\\WpadDecision", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{AB05CE41-DC42-451F-B7F3-B746D1D19C08}\\WpadNetworkName", "HKEY_LOCAL_MACHINE\\Software\\HP710B", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{D3F32EF0-7EB8-461B-9DB4-F87AB98DFAD0}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{D3F32EF0-7EB8-461B-9DB4-F87AB98DFAD0}\\WpadDecisionReason", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{D3F32EF0-7EB8-461B-9DB4-F87AB98DFAD0}\\WpadDecisionTime", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{D3F32EF0-7EB8-461B-9DB4-F87AB98DFAD0}\\WpadDecision", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{D3F32EF0-7EB8-461B-9DB4-F87AB98DFAD0}\\WpadNetworkName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\Winlogon\\Userinit", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{A0BFF2C1-B879-4635-A678-41406EF40CFF}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{A0BFF2C1-B879-4635-A678-41406EF40CFF}\\WpadDecisionReason", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{A0BFF2C1-B879-4635-A678-41406EF40CFF}\\WpadDecisionTime", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{A0BFF2C1-B879-4635-A678-41406EF40CFF}\\WpadDecision", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{A0BFF2C1-B879-4635-A678-41406EF40CFF}\\WpadNetworkName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Run", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\TrayKey", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Setup\\Version", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\winxcfg.exe", "DisableSharing", "Dir98", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\Zvpebfbsg.Jvaqbjf.PbagebyCnary", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\HRZR_PGYFRFFVBA", "C:\\Program Files (x86)\\8e9df131\\jusched.exe", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\syscod", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\System-Service", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\SavedLegacySettings", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.3g2\\OpenWithProgids\\WMP11.AssocFile.3G2", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.3gp\\OpenWithProgids\\WMP11.AssocFile.3GP", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.3gp2\\OpenWithProgids\\WMP11.AssocFile.3G2", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.3gpp\\OpenWithProgids\\WMP11.AssocFile.3GP", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.AAC\\OpenWithProgids\\WMP11.AssocFile.ADTS", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ADT\\OpenWithProgids\\WMP11.AssocFile.ADTS", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ADTS\\OpenWithProgids\\WMP11.AssocFile.ADTS", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.aif\\OpenWithProgids\\WMP11.AssocFile.AIFF", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.aifc\\OpenWithProgids\\WMP11.AssocFile.AIFF", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.aiff\\OpenWithProgids\\WMP11.AssocFile.AIFF", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.asf\\OpenWithProgids\\WMP11.AssocFile.ASF", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.asx\\OpenWithProgids\\WMP11.AssocFile.ASX", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.au\\OpenWithProgids\\WMP11.AssocFile.AU", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.avi\\OpenWithProgids\\WMP11.AssocFile.AVI", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.bmp\\OpenWithProgids\\Paint.Picture", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.cab\\OpenWithProgids\\WinRAR", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.contact\\OpenWithProgids\\contact_wab_auto_file", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.css\\OpenWithProgids\\CSSfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dib\\OpenWithProgids\\Paint.Picture", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dll\\OpenWithProgids\\dllfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.docx\\OpenWithProgids\\docxfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.DVR\\OpenWithProgids\\MediaCenter.DVR", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.DVR-MS\\OpenWithProgids\\MediaCenter.DVR-MS", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dwfx\\OpenWithProgids\\Windows.XPSReachViewer", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.easmx\\OpenWithProgids\\Windows.XPSReachViewer", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.edrwx\\OpenWithProgids\\Windows.XPSReachViewer", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.emf\\OpenWithProgids\\emffile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.eprtx\\OpenWithProgids\\Windows.XPSReachViewer", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\OpenWithProgids\\exefile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.fon\\OpenWithProgids\\fonfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.gif\\OpenWithProgids\\giffile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.htm\\OpenWithProgids\\FirefoxHTML-308046B0AF4A39CB", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\OpenWithProgids\\FirefoxHTML-308046B0AF4A39CB", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ico\\OpenWithProgids\\icofile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ini\\OpenWithProgids\\inifile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jfif\\OpenWithProgids\\pjpegfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jpe\\OpenWithProgids\\jpegfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jpeg\\OpenWithProgids\\jpegfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jpg\\OpenWithProgids\\jpegfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jtx\\OpenWithProgids\\Windows.XPSReachViewer", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.lnk\\OpenWithProgids\\lnkfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.m1v\\OpenWithProgids\\WMP11.AssocFile.MPEG", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.M2T\\OpenWithProgids\\WMP11.AssocFile.M2TS", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.M2TS\\OpenWithProgids\\WMP11.AssocFile.M2TS", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.M2V\\OpenWithProgids\\WMP11.AssocFile.MPEG", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.m3u\\OpenWithProgids\\WMP11.AssocFile.m3u", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.m4a\\OpenWithProgids\\WMP11.AssocFile.M4A", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.m4v\\OpenWithProgids\\WMP11.AssocFile.MP4", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mht\\OpenWithProgids\\mhtmlfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mhtml\\OpenWithProgids\\mhtmlfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mid\\OpenWithProgids\\WMP11.AssocFile.MIDI", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.midi\\OpenWithProgids\\WMP11.AssocFile.MIDI", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.MOD\\OpenWithProgids\\WMP11.AssocFile.MPEG", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mov\\OpenWithProgids\\WMP11.AssocFile.MOV", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mp2\\OpenWithProgids\\WMP11.AssocFile.MP3", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mp2v\\OpenWithProgids\\WMP11.AssocFile.MPEG", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mp3\\OpenWithProgids\\WMP11.AssocFile.MP3", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mp4\\OpenWithProgids\\WMP11.AssocFile.MP4", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mp4v\\OpenWithProgids\\WMP11.AssocFile.MP4", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mpa\\OpenWithProgids\\WMP11.AssocFile.MPEG", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mpe\\OpenWithProgids\\WMP11.AssocFile.MPEG", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mpeg\\OpenWithProgids\\WMP11.AssocFile.MPEG", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mpg\\OpenWithProgids\\WMP11.AssocFile.MPEG", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mpv2\\OpenWithProgids\\WMP11.AssocFile.MPEG", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.MTS\\OpenWithProgids\\WMP11.AssocFile.M2TS", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ocx\\OpenWithProgids\\ocxfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.odt\\OpenWithProgids\\odtfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.otf\\OpenWithProgids\\otffile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.png\\OpenWithProgids\\pngfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ps1xml\\OpenWithProgids\\Microsoft.PowerShellXMLData.1", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.rle\\OpenWithProgids\\rlefile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.rmi\\OpenWithProgids\\WMP11.AssocFile.MIDI", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.rtf\\OpenWithProgids\\rtffile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.scf\\OpenWithProgids\\SHCmdFile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.search-ms\\OpenWithProgids\\SearchFolder", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.shtml\\OpenWithProgids\\FirefoxHTML-308046B0AF4A39CB", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.snd\\OpenWithProgids\\WMP11.AssocFile.AU", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.sys\\OpenWithProgids\\sysfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.tif\\OpenWithProgids\\TIFImage.Document", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.tiff\\OpenWithProgids\\TIFImage.Document", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.TS\\OpenWithProgids\\WMP11.AssocFile.TTS", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ttc\\OpenWithProgids\\ttcfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ttf\\OpenWithProgids\\ttffile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.TTS\\OpenWithProgids\\WMP11.AssocFile.TTS", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.txt\\OpenWithProgids\\txtfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wav\\OpenWithProgids\\WMP11.AssocFile.WAV", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wax\\OpenWithProgids\\WMP11.AssocFile.WAX", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wdp\\OpenWithProgids\\wdpfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wm\\OpenWithProgids\\WMP11.AssocFile.ASF", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wma\\OpenWithProgids\\WMP11.AssocFile.WMA", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wmf\\OpenWithProgids\\wmffile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wmv\\OpenWithProgids\\WMP11.AssocFile.WMV", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wmx\\OpenWithProgids\\WMP11.AssocFile.ASX", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wpl\\OpenWithProgids\\WMP11.AssocFile.WPL", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.WTV\\OpenWithProgids\\MediaCenter.WTVFile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wvx\\OpenWithProgids\\WMP11.AssocFile.WVX", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xml\\OpenWithProgids\\xmlfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xps\\OpenWithProgids\\Windows.XPSReachViewer", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xsl\\OpenWithProgids\\xslfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.zip\\OpenWithProgids\\WinRAR.ZIP", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}.check.101\\CheckSetting", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{41EF6C28-B2B9-4CE2-ADA9-BBC50C1E46D4}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{41EF6C28-B2B9-4CE2-ADA9-BBC50C1E46D4}\\WpadDecisionReason", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{41EF6C28-B2B9-4CE2-ADA9-BBC50C1E46D4}\\WpadDecisionTime", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{41EF6C28-B2B9-4CE2-ADA9-BBC50C1E46D4}\\WpadDecision", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{41EF6C28-B2B9-4CE2-ADA9-BBC50C1E46D4}\\WpadNetworkName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\AntiVirusOverride", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\AntiVirusDisableNotify", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\FirewallDisableNotify", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\FirewallOverride", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\UpdatesDisableNotify", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\UacDisableNotify", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\Svc\\AntiVirusOverride", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\Svc\\AntiVirusDisableNotify", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\Svc\\FirewallDisableNotify", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\Svc\\FirewallOverride", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\Svc\\UpdatesDisableNotify", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\Svc\\UacDisableNotify", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\GlobalUserOffline", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1\\WHCIconStartup", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\pbz.fdhveery.Grnzf.Grnzf", "HKEY_CURRENT_USER\\Software\\AppsIDs", "HKEY_CURRENT_USER\\Software\\AppsIDs\\values100", "HKEY_CURRENT_USER\\Software\\maijiaxiuhuigou\\rs", "HKEY_CURRENT_USER\\Software\\maijiaxiuhuigou\\rs\\state2", "HKEY_CURRENT_USER\\Software\\AppsIDs\\id", "HKEY_CURRENT_USER\\Software\\quandashi\\bs", "HKEY_CURRENT_USER\\Software\\quandashi\\bs\\state2", "HKEY_CURRENT_USER\\Software\\Microsoft\\Multimedia\\Audio Compression Manager\\", "HKEY_CURRENT_USER\\Software\\Microsoft\\Multimedia\\Audio Compression Manager\\MSACM", "HKEY_CURRENT_USER\\Software\\Microsoft\\Multimedia\\Audio Compression Manager\\Priority v4.00", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{CF07CE59-A735-4B89-B34F-FCB1AF9DCB76}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{CF07CE59-A735-4B89-B34F-FCB1AF9DCB76}\\WpadDecisionReason", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{CF07CE59-A735-4B89-B34F-FCB1AF9DCB76}\\WpadDecisionTime", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{CF07CE59-A735-4B89-B34F-FCB1AF9DCB76}\\WpadDecision", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{CF07CE59-A735-4B89-B34F-FCB1AF9DCB76}\\WpadNetworkName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Content\\CachePrefix", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Cookies\\CachePrefix", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\History\\CachePrefix", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Setup\\workfile", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inffile\\shell\\open\\command\\(Default)", "C:\\Program Files (x86)\\Java\\jre-09\\bin\\jusched.exe", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\autoload", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\ntuser", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\autoload", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\ntuser", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Schedule\\ImagePath", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{127B4FEF-7EF8-4EA1-A2E1-FB02181BA2EE}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{127B4FEF-7EF8-4EA1-A2E1-FB02181BA2EE}\\WpadDecisionReason", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{127B4FEF-7EF8-4EA1-A2E1-FB02181BA2EE}\\WpadDecisionTime", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{127B4FEF-7EF8-4EA1-A2E1-FB02181BA2EE}\\WpadDecision", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{127B4FEF-7EF8-4EA1-A2E1-FB02181BA2EE}\\WpadNetworkName", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{E8433B72-5842-4d43-8645-BC2C35960837}.check.103\\CheckSetting", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{E8433B72-5842-4d43-8645-BC2C35960837}.check.100\\CheckSetting", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{E8433B72-5842-4d43-8645-BC2C35960837}.check.102\\CheckSetting", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{852FB1F8-5CC6-4567-9C0E-7C330F8807C2}.check.100\\CheckSetting", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{852FB1F8-5CC6-4567-9C0E-7C330F8807C2}.check.101\\CheckSetting", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0\\CheckSetting", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.100\\CheckSetting", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{945a8954-c147-4acd-923f-40c45405a658}.check.42\\CheckSetting", "HKEY_CURRENT_USER\\Qmdvucpg^Rmnkakgq^Okapmqmdv^Uklfmuq^Q{qvgo", "HKEY_CURRENT_USER\\Qmdvucpg^Rmnkakgq^Okapmqmdv^Uklfmuq^Q{qvgo\\Fkqc`ngAOF", "Layersecurity Servicemonitor", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\RNG", "HKEY_CURRENT_USER\\Control Panel\\Desktop\\SCRNSAVE.EXE", "HKEY_CURRENT_USER\\Control Panel\\Desktop\\ScreenSaveTimeOut", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\workfile", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CabinetState\\FullPath", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{E88DCCE0-B7B3-11D1-A9F0-00AA0060FA31} {000214E6-0000-0000-C000-000000000046} 0xFFFF", "HKEY_CURRENT_USER\\Control Panel\\Desktop\\ConvertedWallpaper", "HKEY_CURRENT_USER\\Control Panel\\Desktop\\Wallpaper", "HKEY_CURRENT_USER\\Control Panel\\Desktop\\WallpaperStyle", "HKEY_CURRENT_USER\\Control Panel\\Screen Saver.Marquee", "HKEY_CURRENT_USER\\Control Panel\\Screen Saver.Marquee\\BackgroundColor", "HKEY_CURRENT_USER\\Control Panel\\Screen Saver.Marquee\\Font", "HKEY_CURRENT_USER\\Control Panel\\Screen Saver.Marquee\\Mode.EXE", "HKEY_CURRENT_USER\\Control Panel\\Screen Saver.Marquee\\Size", "HKEY_CURRENT_USER\\Control Panel\\Screen Saver.Marquee\\Speed", "HKEY_CURRENT_USER\\Control Panel\\Screen Saver.Marquee\\Text", "HKEY_CURRENT_USER\\Control Panel\\Screen Saver.Marquee\\TextColor", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Window Title", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\DesertSand", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\FreeAV", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\644r4", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\SystemRun", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CabinetState\\FullPathAddress", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Folder", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Folder\\Type", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\Advanced\\Folder\\Type", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\ProductId", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\RegisteredOrganization", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\RegisteredOwner", "HKEY_CURRENT_USER\\Software\\Microsoft\\MS Setup (ACME)\\User Info", "HKEY_CURRENT_USER\\Software\\Microsoft\\MS Setup (ACME)\\User Info\\DefCompany", "HKEY_CURRENT_USER\\Software\\Microsoft\\MS Setup (ACME)\\User Info\\DefName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Gaara-The-Kazekage", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Gaara-The-Kazekage\\Dedicated", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Gaara-The-Kazekage\\Developer", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Gaara-The-Kazekage\\Mission", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Gaara-The-Kazekage\\From", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Gaara-The-Kazekage\\Codename", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VBSFile\\Shell\\Open\\Command\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VBSFile\\Shell\\Open2\\Command\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VBSFile\\Shell\\Edit\\Command\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\inffile\\shell\\Install\\command\\(Default)", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\dhcpqec.dll,-100", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\dhcpqec.dll,-101", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\dhcpqec.dll,-103", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\dhcpqec.dll,-102", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\napipsec.dll,-1", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\napipsec.dll,-2", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\napipsec.dll,-4", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\napipsec.dll,-3", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\tsgqec.dll,-100", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\tsgqec.dll,-101", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\tsgqec.dll,-102", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\tsgqec.dll,-103", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\eapqec.dll,-100", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\eapqec.dll,-101", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\eapqec.dll,-102", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\F\\52C64B7E\\@%SystemRoot%\\system32\\eapqec.dll,-103", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\PoEQoAEI.exe", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\QgQAYoYM.exe", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit"], "files": ["\\Device\\KsecDD", "C:\\Boot\\memtest.exe", "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls", "C:\\", "C:\\Users", "\\??\\MountPointManager", "C:\\Users\\John", "C:\\Users\\John\\AppData", "C:\\Users\\John\\AppData\\Local", "C:\\Users\\John\\AppData\\Local\\Temp", "C:\\Windows\\SysWOW64\\en-US\\KERNELBASE.dll.mui", "C:\\*", "\\Device\\RdpDr", "\\??\\PIPE\\wkssvc", "\\Device\\LanmanDatagramReceiver", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\background.png", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\device.png", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\overlay.png", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\superbar.png", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\background.png", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\watermark.png", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile10.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile11.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile12.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile13.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile14.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile15.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile16.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile17.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile18.bmp", "C:\\tmpa3vx5wa7\\bin\\execsc.exe", "C:\\tmpa3vx5wa7\\bin\\flashplayer.exe", "C:\\tmpa3vx5wa7\\bin\\krbRAhZs.exe", "C:\\tmpa3vx5wa7\\bin\\lKMXtLd.exe", "C:\\tmpa3vx5wa7\\bin\\loader.exe", "C:\\tmpa3vx5wa7\\bin\\loader_x64.exe", "C:\\tmpa3vx5wa7\\bin\\Procmon.exe", "C:\\tmpa3vx5wa7\\bin\\psexec.exe", "C:\\tmpa3vx5wa7\\bin\\signtool.exe", "C:\\tmpexryqjkw\\bin\\EvYVbXX.exe", "C:\\tmpexryqjkw\\bin\\execsc.exe", "C:\\tmpexryqjkw\\bin\\flashplayer.exe", "C:\\tmpexryqjkw\\bin\\loader.exe", "C:\\tmpexryqjkw\\bin\\loader_x64.exe", "C:\\tmpexryqjkw\\bin\\Procmon.exe", "C:\\tmpexryqjkw\\bin\\psexec.exe", "C:\\tmpexryqjkw\\bin\\rGvaINUr.exe", "C:\\tmpexryqjkw\\bin\\signtool.exe", "C:\\tmpw3qc5zo4\\bin\\execsc.exe", "C:\\tmpw3qc5zo4\\bin\\flashplayer.exe", "C:\\tmpw3qc5zo4\\bin\\loader.exe", "C:\\tmpw3qc5zo4\\bin\\loader_x64.exe", "C:\\tmpw3qc5zo4\\bin\\LTDvmMKK.exe", "C:\\tmpw3qc5zo4\\bin\\Procmon.exe", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\background.png", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\device.png", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\overlay.png", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\superbar.png", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\background.png", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\watermark.png", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile10.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile11.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile12.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile13.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile14.bmp", "C:\\Windows\\SysWOW64\\en-US\\reg.exe.mui", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\*", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\clr.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorwks.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\sysnative\\api-ms-win-appmodel-runtime-l1-1-2.dll", "C:\\Windows\\sysnative\\api-ms-win-appmodel-runtime-l1-1-0.dll", "C:\\Windows\\assembly\\pubpol4.dat", "C:\\Windows\\assembly\\GAC\\PublisherPolicy.tme", "C:\\$Recycle.Bin\\*", "C:\\$Recycle.Bin\\S-1-5-21-1249488040-416823385-3057894055-500\\*", "C:\\$Recycle.Bin\\S-1-5-21-2897422521-4031036550-1004500545-1000\\*", "C:\\$Recycle.Bin\\S-1-5-21-3047202784-114954003-3208681637-500\\*", "C:\\aPnMrnpmSY\\*", "C:\\aPnMrnpmSY\\CAPE\\*", "C:\\aPnMrnpmSY\\drop\\*", "C:\\aPnMrnpmSY\\files\\*", "C:\\aPnMrnpmSY\\logs\\*", "C:\\aPnMrnpmSY\\memory\\*", "C:\\aPnMrnpmSY\\shots\\*", "C:\\BgrMbIpK\\*", "C:\\BgrMbIpK\\CAPE\\*", "C:\\BgrMbIpK\\drop\\*", "C:\\BgrMbIpK\\files\\*", "C:\\BgrMbIpK\\logs\\*", "C:\\BgrMbIpK\\memory\\*", "C:\\BgrMbIpK\\shots\\*", "C:\\Boot\\*", "C:\\Boot\\cs-CZ\\*", "C:\\Boot\\da-DK\\*", "C:\\Boot\\de-DE\\*", "C:\\Boot\\el-GR\\*", "C:\\Boot\\en-US\\*", "C:\\Boot\\es-ES\\*", "C:\\Boot\\fi-FI\\*", "C:\\Boot\\Fonts\\*", "C:\\Boot\\fr-FR\\*", "C:\\Boot\\hu-HU\\*", "C:\\Boot\\it-IT\\*", "C:\\Boot\\ja-JP\\*", "C:\\Boot\\ko-KR\\*", "C:\\cdQPgPwTtZ\\*", "C:\\cdQPgPwTtZ\\CAPE\\*", "C:\\cdQPgPwTtZ\\drop\\*", "C:\\cdQPgPwTtZ\\files\\*", "C:\\cdQPgPwTtZ\\logs\\*", "C:\\cdQPgPwTtZ\\memory\\*", "C:\\cdQPgPwTtZ\\shots\\*", "C:\\Documents and Settings\\*", "C:\\PerfLogs\\*", "C:\\ProgramData\\*", "C:\\ProgramData\\Application Data\\*", "C:\\ProgramData\\Desktop\\*", "C:\\ProgramData\\Documents\\*", "C:\\ProgramData\\Favorites\\*", "C:\\ProgramData\\Microsoft\\*", "C:\\ProgramData\\Microsoft\\Assistance\\*", "C:\\ProgramData\\Microsoft\\Assistance\\Client\\*", "C:\\ProgramData\\Microsoft\\Assistance\\Client\\1.0\\*", "C:\\ProgramData\\Microsoft\\Assistance\\Client\\1.0\\en-US\\*", "C:\\ProgramData\\Microsoft\\Crypto\\*", "C:\\ProgramData\\Microsoft\\Crypto\\DSS\\*", "C:\\ProgramData\\Microsoft\\Crypto\\DSS\\MachineKeys\\*", "C:\\ProgramData\\Microsoft\\Crypto\\Keys\\*", "C:\\ProgramData\\Microsoft\\Crypto\\PCPKSP\\*", "C:\\ProgramData\\Microsoft\\Crypto\\RSA\\*", "C:\\ProgramData\\Microsoft\\Crypto\\RSA\\MachineKeys\\*", "C:\\ProgramData\\Microsoft\\Crypto\\RSA\\S-1-5-18\\*", "C:\\ProgramData\\Microsoft\\Device Stage\\*", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\*", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\*", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\background.png.exe", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\device.png.exe", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\overlay.png.exe", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\superbar.png.exe", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\*", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\background.png.exe", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\watermark.png.exe", "C:\\ProgramData\\Microsoft\\Device Stage\\Task\\*", "C:\\ProgramData\\Microsoft\\Device Stage\\Task\\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\\*", "C:\\ProgramData\\Microsoft\\Device Stage\\Task\\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\\en-US\\*", "C:\\ProgramData\\Microsoft\\Device Stage\\Task\\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\\*", "C:\\ProgramData\\Microsoft\\Device Stage\\Task\\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\\en-US\\*", "C:\\ProgramData\\Microsoft\\DeviceSync\\*", "C:\\ProgramData\\Microsoft\\Diagnosis\\*", "C:\\ProgramData\\Microsoft\\DRM\\*", "C:\\ProgramData\\Microsoft\\DRM\\Server\\*", "C:\\ProgramData\\Microsoft\\eHome\\*", "C:\\ProgramData\\Microsoft\\eHome\\logs\\*", "C:\\ProgramData\\Microsoft\\IdentityCRL\\*", "C:\\ProgramData\\Microsoft\\IlsCache\\*", "C:\\ProgramData\\Microsoft\\Media Player\\*", "C:\\ProgramData\\Microsoft\\MF\\*", "C:\\ProgramData\\Microsoft\\NetFramework\\*", "C:\\ProgramData\\Microsoft\\NetFramework\\BreadcrumbStore\\*", "C:\\ProgramData\\Microsoft\\Network\\*", "C:\\ProgramData\\Microsoft\\Network\\Connections\\*", "C:\\ProgramData\\Microsoft\\Network\\Downloader\\*", "C:\\ProgramData\\Microsoft\\RAC\\*", "C:\\ProgramData\\Microsoft\\RAC\\Outbound\\*", "C:\\ProgramData\\Microsoft\\RAC\\PublishedData\\*", "C:\\ProgramData\\Microsoft\\RAC\\StateData\\*", "C:\\ProgramData\\Microsoft\\Search\\*", "C:\\ProgramData\\Microsoft\\Search\\Data\\*", "C:\\ProgramData\\Microsoft\\User Account Pictures\\*", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\*", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile10.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile11.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile12.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile13.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile14.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile15.bmp.exe", "C:\\Recovery\\*", "C:\\System Volume Information\\*", "C:\\tmpa3vx5wa7\\*", "C:\\tmpa3vx5wa7\\bin\\*", "C:\\tmpexryqjkw\\*", "C:\\tmpexryqjkw\\bin\\*", "C:\\tmpw3qc5zo4\\*", "C:\\tmpw3qc5zo4\\bin\\*", "C:\\Users\\*", "C:\\Users\\All Users\\*", "C:\\Users\\All Users\\Application Data\\*", "C:\\Users\\All Users\\Desktop\\*", "C:\\Users\\All Users\\Documents\\*", "C:\\Users\\All Users\\Favorites\\*", "C:\\Users\\All Users\\Microsoft\\*", "C:\\Users\\All Users\\Microsoft\\Assistance\\*", "C:\\Users\\All Users\\Microsoft\\Assistance\\Client\\*", "C:\\Users\\All Users\\Microsoft\\Assistance\\Client\\1.0\\*", "C:\\Users\\All Users\\Microsoft\\Assistance\\Client\\1.0\\en-US\\*", "C:\\Users\\All Users\\Microsoft\\Crypto\\*", "C:\\Users\\All Users\\Microsoft\\Crypto\\DSS\\*", "C:\\Users\\All Users\\Microsoft\\Crypto\\DSS\\MachineKeys\\*", "C:\\Users\\All Users\\Microsoft\\Crypto\\Keys\\*", "C:\\Users\\All Users\\Microsoft\\Crypto\\PCPKSP\\*", "C:\\Users\\All Users\\Microsoft\\Crypto\\RSA\\*", "C:\\Users\\All Users\\Microsoft\\Crypto\\RSA\\MachineKeys\\*", "C:\\Users\\All Users\\Microsoft\\Crypto\\RSA\\S-1-5-18\\*", "C:\\Users\\All Users\\Microsoft\\Device Stage\\*", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\*", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\*", "D:\\*", "C:\\Boot\\nb-NO\\*", "C:\\Boot\\nl-NL\\*", "C:\\Boot\\pl-PL\\*", "C:\\Boot\\pt-BR\\*", "C:\\Boot\\pt-PT\\*", "C:\\Boot\\ru-RU\\*", "C:\\Boot\\sv-SE\\*", "C:\\Boot\\tr-TR\\*", "C:\\Boot\\zh-CN\\*", "C:\\Boot\\zh-HK\\*", "C:\\Boot\\zh-TW\\*", "\\??\\PIPE\\samr", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\*", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Task\\*", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Task\\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\\*", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Task\\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\\en-US\\*", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Task\\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\\*", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Task\\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\\en-US\\*", "C:\\Users\\All Users\\Microsoft\\DeviceSync\\*", "C:\\Users\\All Users\\Microsoft\\Diagnosis\\*", "C:\\Users\\All Users\\Microsoft\\DRM\\*", "C:\\Users\\All Users\\Microsoft\\DRM\\Server\\*", "C:\\Users\\All Users\\Microsoft\\eHome\\*", "C:\\Users\\All Users\\Microsoft\\eHome\\logs\\*", "C:\\Users\\All Users\\Microsoft\\IdentityCRL\\*", "C:\\Users\\All Users\\Microsoft\\IlsCache\\*", "C:\\Users\\All Users\\Microsoft\\Media Player\\*", "C:\\Users\\All Users\\Microsoft\\MF\\*", "C:\\Users\\All Users\\Microsoft\\NetFramework\\*", "C:\\Users\\All Users\\Microsoft\\NetFramework\\BreadcrumbStore\\*", "C:\\Users\\All Users\\Microsoft\\Network\\*", "C:\\Users\\All Users\\Microsoft\\Network\\Connections\\*", "C:\\Users\\All Users\\Microsoft\\Network\\Downloader\\*", "C:\\Users\\All Users\\Microsoft\\RAC\\*", "C:\\Users\\All Users\\Microsoft\\RAC\\Outbound\\*", "C:\\Users\\All Users\\Microsoft\\RAC\\PublishedData\\*", "C:\\Users\\All Users\\Microsoft\\RAC\\StateData\\*", "C:\\Users\\All Users\\Microsoft\\Search\\*", "C:\\Users\\All Users\\Microsoft\\Search\\Data\\*", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\*", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\*", "C:\\ProgramData\\XyogosAE", "C:\\ProgramData\\XyogosAE\\EEIEsYos.exe", "C:\\ProgramData\\AKwE.txt", "C:\\tmpa3vx5wa7\\data\\*", "C:\\tmpa3vx5wa7\\data\\yara\\*", "C:\\tmpa3vx5wa7\\dll\\*", "C:\\tmpa3vx5wa7\\lib\\*", "C:\\tmpa3vx5wa7\\lib\\api\\*", "C:\\tmpa3vx5wa7\\lib\\api\\__pycache__\\*", "C:\\tmpa3vx5wa7\\lib\\common\\*", "C:\\tmpa3vx5wa7\\lib\\common\\__pycache__\\*", "C:\\tmpa3vx5wa7\\lib\\core\\*", "C:\\tmpa3vx5wa7\\lib\\core\\__pycache__\\*", "C:\\tmpa3vx5wa7\\lib\\__pycache__\\*", "C:\\tmpa3vx5wa7\\modules\\*", "C:\\tmpa3vx5wa7\\modules\\auxiliary\\*", "C:\\tmpa3vx5wa7\\modules\\auxiliary\\__pycache__\\*", "C:\\tmpa3vx5wa7\\modules\\packages\\*", "C:\\tmpa3vx5wa7\\modules\\packages\\__pycache__\\*", "C:\\tmpa3vx5wa7\\modules\\__pycache__\\*", "C:\\tmpexryqjkw\\data\\*", "C:\\tmpexryqjkw\\data\\yara\\*", "C:\\tmpexryqjkw\\dll\\*", "C:\\tmpexryqjkw\\lib\\*", "C:\\tmpexryqjkw\\lib\\api\\*", "C:\\tmpexryqjkw\\lib\\api\\__pycache__\\*", "C:\\tmpexryqjkw\\lib\\common\\*", "C:\\tmpexryqjkw\\lib\\common\\__pycache__\\*", "C:\\tmpexryqjkw\\lib\\core\\*", "C:\\tmpexryqjkw\\lib\\core\\__pycache__\\*", "C:\\tmpexryqjkw\\lib\\__pycache__\\*", "C:\\tmpexryqjkw\\modules\\*", "C:\\tmpexryqjkw\\modules\\auxiliary\\*", "C:\\tmpexryqjkw\\modules\\auxiliary\\__pycache__\\*", "C:\\tmpexryqjkw\\modules\\packages\\*", "C:\\tmpexryqjkw\\modules\\packages\\__pycache__\\*", "C:\\tmpexryqjkw\\modules\\__pycache__\\*", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\background.png.exe", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\device.png.exe", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\overlay.png.exe", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\superbar.png.exe", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\background.png.exe", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\watermark.png.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile10.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile11.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile12.bmp.exe", "C:\\Users\\John\\RKMcgggk", "C:\\Users\\John\\RKMcgggk\\PoEQoAEI", "C:\\ProgramData\\HWcAckgg", "C:\\ProgramData\\HWcAckgg\\QgQAYoYM", "C:\\Users\\John\\RKMcgggk\\PoEQoAEI.exe", "C:\\ProgramData\\HWcAckgg\\QgQAYoYM.exe", "C:\\ProgramData\\HWcAckgg\\*", "C:\\Users\\All Users\\HWcAckgg\\*"], "read_files": ["C:\\Windows\\Fonts\\staticcache.dat", "\\Device\\KsecDD", "C:\\Boot\\memtest.exe", "C:\\Windows\\WindowsShell.Manifest", "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls", "C:\\Windows\\SysWOW64\\shell32.dll", "C:\\Windows\\SysWOW64\\en-US\\KERNELBASE.dll.mui", "C:\\Windows\\System32\\tzres.dll", "C:\\Windows\\SysWOW64\\en-US\\cmd.exe.mui", "\\??\\PIPE\\wkssvc", "\\Device\\LanmanDatagramReceiver", "\\??\\PIPE\\DAV RPC SERVICE", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\background.png", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\device.png", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\overlay.png", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\superbar.png", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\background.png", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\watermark.png", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile10.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile11.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile12.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile13.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile14.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile15.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile16.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile17.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile18.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile19.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile20.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile21.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile22.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile23.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile24.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile25.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile26.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile27.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile28.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile29.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile30.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile31.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile32.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile33.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile34.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile35.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile36.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile37.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile38.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile39.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile40.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile41.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile42.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile43.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile44.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\guest.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\user.bmp", "C:\\ProgramData\\Package Cache\\{282975d8-55fe-4991-bbbb-06a72581ce58}\\VC_redist.x64.exe", "C:\\ProgramData\\Package Cache\\{e31cb1a4-76b5-46a5-a084-3fa419e82201}\\VC_redist.x86.exe", "C:\\tmpa3vx5wa7\\bin\\execsc.exe", "C:\\tmpa3vx5wa7\\bin\\flashplayer.exe", "C:\\tmpa3vx5wa7\\bin\\krbRAhZs.exe", "C:\\tmpa3vx5wa7\\bin\\lKMXtLd.exe", "C:\\tmpa3vx5wa7\\bin\\loader.exe", "C:\\tmpa3vx5wa7\\bin\\loader_x64.exe", "C:\\tmpa3vx5wa7\\bin\\Procmon.exe", "C:\\tmpa3vx5wa7\\bin\\psexec.exe", "C:\\tmpa3vx5wa7\\bin\\signtool.exe", "C:\\tmpexryqjkw\\bin\\EvYVbXX.exe", "C:\\tmpexryqjkw\\bin\\execsc.exe", "C:\\tmpexryqjkw\\bin\\flashplayer.exe", "C:\\tmpexryqjkw\\bin\\loader.exe", "C:\\tmpexryqjkw\\bin\\loader_x64.exe", "C:\\tmpexryqjkw\\bin\\Procmon.exe", "C:\\tmpexryqjkw\\bin\\psexec.exe", "C:\\tmpexryqjkw\\bin\\rGvaINUr.exe", "C:\\tmpexryqjkw\\bin\\signtool.exe", "C:\\tmpw3qc5zo4\\bin\\execsc.exe", "C:\\tmpw3qc5zo4\\bin\\flashplayer.exe", "C:\\tmpw3qc5zo4\\bin\\loader.exe", "C:\\tmpw3qc5zo4\\bin\\loader_x64.exe", "C:\\tmpw3qc5zo4\\bin\\LTDvmMKK.exe", "C:\\tmpw3qc5zo4\\bin\\Procmon.exe", "C:\\tmpw3qc5zo4\\bin\\psexec.exe", "C:\\tmpw3qc5zo4\\bin\\RMjGQay.exe", "C:\\tmpw3qc5zo4\\bin\\signtool.exe", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\background.png", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\device.png", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\overlay.png", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\superbar.png", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\background.png", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\watermark.png", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile10.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile11.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile12.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile13.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile14.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile15.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile16.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile17.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile18.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile19.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile20.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile21.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile22.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile23.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile24.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile25.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile26.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile27.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile28.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile29.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile30.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile31.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile32.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile33.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile34.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile35.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile36.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile37.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile38.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile39.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile40.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile41.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile42.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile43.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile44.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\guest.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\user.bmp", "C:\\Users\\All Users\\Package Cache\\{282975d8-55fe-4991-bbbb-06a72581ce58}\\VC_redist.x64.exe", "C:\\Users\\All Users\\Package Cache\\{e31cb1a4-76b5-46a5-a084-3fa419e82201}\\VC_redist.x86.exe", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\aapocclcgogkmnckokdopfmhonfmgoek\\0.10_0\\icon_128.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\aapocclcgogkmnckokdopfmhonfmgoek\\0.10_0\\icon_16.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\aohghmighlieiainnegkcijnfilokake\\0.10_0\\icon_128.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\aohghmighlieiainnegkcijnfilokake\\0.10_0\\icon_16.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\apdfllckaahabafndbhieahigkjlhalf\\14.5_0\\128.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.8_0\\128.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\felcaaldnbdncclmgdcncolpebgiejap\\1.2_0\\icon_128.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\felcaaldnbdncclmgdcncolpebgiejap\\1.2_0\\icon_16.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ghbmnnjooekpmoecnnnilnnbdlolhkhi\\1.33.0_0\\128.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\1.0.0.6_0\\images\\flapper.gif", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\1.0.0.6_0\\images\\icon_128.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\1.0.0.6_0\\images\\icon_16.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\1.0.0.6_0\\images\\topbar_floating_button.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\1.0.0.6_0\\images\\topbar_floating_button_close.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\1.0.0.6_0\\images\\topbar_floating_button_hover.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\1.0.0.6_0\\images\\topbar_floating_button_maximize.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\1.0.0.6_0\\images\\topbar_floating_button_pressed.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\8.3_0\\128.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\12x12-available.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\12x12-away.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\12x12-busy.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\12x12-dnd.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\12x12-reset.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\20x20-available.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\20x20-away.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\20x20-busy.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\20x20-dnd.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_1.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_2.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_3.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_4.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_5.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_6.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_7.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_8.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_9.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_9plus.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\dlp_user_profile.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Error-Systray16x16@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Error-Taskbar@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\favicon.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\favicon_white.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\macos\\touchbar\\BreakoutRoom@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\macos\\touchbar\\LowerHand@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\macos\\touchbar\\Messages@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\macos\\touchbar\\MicMuted@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\macos\\touchbar\\MicOn@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\macos\\touchbar\\Participants@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\macos\\touchbar\\RaiseHand@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\macos\\touchbar\\Share@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\macos\\touchbar\\ShareCloseTray@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\macos\\touchbar\\SpeakerOff@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\macos\\touchbar\\StopShare@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\macos\\touchbar\\Video off@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\macos\\touchbar\\Video@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\MicrosoftTeams-static.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-Activity-Systray16x16@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-Available-Systray16x16@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-Available-Taskbar@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-Away-Systray16x16@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-Away-Taskbar@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-Busy-Systray16x16@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-Busy-Taskbar@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-DnD-Systray16x16@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-DND-Taskbar@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-NoActivity-Systray16x16@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-Offline-Systray16x16@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-Offline-Taskbar@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-OffShift-Systray16x16@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-OffShift-Taskbar@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-OnShift-Systray16x16@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Presence-OnShift-Taskbar@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\send.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Taskbar.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\TrayIconTemplate.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\TrayIconTemplate@2x.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\urgent-icon.png", "C:\\Windows\\SysWOW64\\en-US\\reg.exe.mui", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\Update.exe", "C:\\Users\\John\\AppData\\Local\\Package Cache\\{8ba65a8c-cb48-4716-bc24-47c148808015}\\python-3.6.0.exe", "C:\\Users\\John\\AppData\\Roaming\\Microsoft\\Installer\\{C7D63030-7738-499A-A0D2-8549174D2B70}\\idle.exe", "C:\\Users\\John\\Downloads\\ChromeSetup.exe", "C:\\Users\\John\\Downloads\\python-3.10.0-amd64.exe", "C:\\Users\\John\\Downloads\\python-3.6.0-amd64.exe", "C:\\Users\\John\\Downloads\\python-3.6.0.exe", "C:\\Users\\John\\Downloads\\Teams_windows_x64.exe", "C:\\Users\\John\\Downloads\\winrar-x64-602.exe", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clr.dll", "C:\\Windows\\sysnative\\MSVCR120_CLR0400.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Config\\machine.config", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\mscorlib\\a6021ef6892ab519b334a17992542017\\mscorlib.ni.dll.aux", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\mscorlib\\a6021ef6892ab519b334a17992542017\\mscorlib.ni.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\clrjit.dll", "C:\\Windows\\assembly\\pubpol4.dat", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\c8227b97c5e5cac9c44c21a70cfec07a\\System.ni.dll.aux", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\c8227b97c5e5cac9c44c21a70cfec07a\\System.ni.dll", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Core\\36ff32e1829fe4ccb6583b193a91adeb\\System.Core.ni.dll.aux", "C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Core\\36ff32e1829fe4ccb6583b193a91adeb\\System.Core.ni.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\nlssorting.dll", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SortDefault.nlp", "C:\\Windows\\SysWOW64\\cscript.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Large_120.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Large_144.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Large_192.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Large_96.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Small_120.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Small_144.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Small_192.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Small_96.png", "\\??\\PIPE\\samr", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Large_120.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Large_144.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Large_192.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Large_96.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Small_120.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Small_144.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Small_192.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\meeting-addin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Small_96.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Large_120.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Large_144.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Large_192.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Large_96.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Small_120.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Small_144.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Small_192.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x64\\Assets\\NewMeeting_Small_96.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Large_120.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Large_144.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Large_192.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Large_96.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Small_120.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Small_144.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Small_192.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\1.0.21161.4\\x86\\Assets\\NewMeeting_Small_96.png", "C:\\Users\\John\\AppData\\Local\\Temp\\setup.exe", "C:\\ProgramData\\XyogosAE\\EEIEsYos.exe", "C:\\ProgramData\\AKwE.txt", "C:\\Users\\John\\AppData\\Local\\Temp\\file.vbs", "C:\\tmpcd9bps0i\\bin\\EDdLGBX.exe", "C:\\tmpcd9bps0i\\bin\\execsc.exe", "C:\\tmpcd9bps0i\\bin\\flashplayer.exe", "C:\\tmpcd9bps0i\\bin\\loader.exe", "C:\\tmpcd9bps0i\\bin\\loader_x64.exe", "C:\\tmpcd9bps0i\\bin\\Procmon.exe", "C:\\Users\\John\\RKMcgggk\\PoEQoAEI", "C:\\ProgramData\\HWcAckgg\\QgQAYoYM", "C:\\Users\\John\\RKMcgggk\\PoEQoAEI.exe", "C:\\ProgramData\\HWcAckgg\\QgQAYoYM.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\choco.exe", "C:\\Users\\John\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\oyr1ulp8.default-release\\thumbnails\\f6546de9cac3c8fe95cfa0b2917a6817.png", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\guest.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\user.bmp.exe", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\aapocclcgogkmnckokdopfmhonfmgoek\\0.10_0\\icon_128.png.exe", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\aohghmighlieiainnegkcijnfilokake\\0.10_0\\icon_128.png.exe", "C:\\Users\\Public\\Music\\Sample Music\\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Large.jpg", "C:\\Users\\Public\\Music\\Sample Music\\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Small.jpg", "C:\\Users\\Public\\Music\\Sample Music\\Kalimba.mp3", "C:\\Users\\John\\AppData\\Local\\Temp\\choco.exe.config", "C:\\Users\\Public\\Music\\Sample Music\\Maid with the Flaxen Hair.mp3", "C:\\Users\\Public\\Music\\Sample Music\\Sleep Away.mp3", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Chrysanthemum.jpg", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Desert.jpg", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Hydrangeas.jpg", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Jellyfish.jpg", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Koala.jpg", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Lighthouse.jpg", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Penguins.jpg", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Tulips.jpg"], "started_services": ["VaultSvc"], "created_services": ["YMGUZYG.EXE", "IPFILTERDRIVER", "amsint32", "GTFFM.EXE", "RJR.EXE", "RZS.EXE", "LQMSH.EXE", "PJIMV.EXE", "TIFLZTS.EXE", "IVVW.EXE", "MUXQB.EXE", "LDF.EXE", "MFO.EXE", "MXPF.EXE", "RDOXY.EXE", "NZLBKJ.EXE", "QRJGPH.EXE", "GRCAGB.EXE", "EPOXVH.EXE"], "write_files": ["C:\\ProgramData\\Mozilla\\ysokqrk.exe", "C:\\ProgramData\\Saaaalamm\\Mira.h", "\\??\\PIPE\\wkssvc", "\\Device\\LanmanDatagramReceiver", "\\??\\PIPE\\DAV RPC SERVICE", "C:\\$Recycle.Bin\\S-1-5-21-2897422521-4031036550-1004500545-1000\\$IZXAGEI.py", "C:\\$Recycle.Bin\\S-1-5-21-2897422521-4031036550-1004500545-1000\\$RZXAGEI.py", "C:\\Boot\\memtest.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\7za.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\poweroff-vm-default.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\poweron-vm-default.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\resume-vm-default.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\rpctool.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\serviceDiscovery\\scripts\\get-connection-info.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\serviceDiscovery\\scripts\\get-iis-ports-info.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\serviceDiscovery\\scripts\\get-listening-pids-helper.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\serviceDiscovery\\scripts\\get-listening-pids.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\serviceDiscovery\\scripts\\get-listening-process-info.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\serviceDiscovery\\scripts\\get-parent-child-rels.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\serviceDiscovery\\scripts\\get-performance-metrics.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\serviceDiscovery\\scripts\\get-version.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\serviceDiscovery\\scripts\\get-versions.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\serviceDiscovery\\scripts\\net-share.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\serviceDiscovery\\scripts\\uniq.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\suspend-vm-default.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\vmtoolsd.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMToolsHookProc.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VmUpgradeHelper.bat", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMware VGAuth\\VGAuthCLI.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMware VGAuth\\VGAuthService.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMware VGAuth\\VMwareAliasImport.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMwareNamespaceCmd.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMwareResolutionSet.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMwareToolboxCmd.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMwareXferlogs.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\ConvertInkStore.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\FlickLearningWizard.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\InkWatson.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\InputPersonalization.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\mip.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\ShapeCollector.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\TabTip.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\MSInfo\\msinfo32.exe", "C:\\Program Files\\Common Files\\q40bqc0qmn\\Drivers\\video_wddm\\Vista\\vm3dservice.exe", "C:\\Program Files\\Common Files\\q40bqc0qmn\\Drivers\\vss\\comreg.exe", "C:\\Program Files\\DVD Maker\\DVDMaker.exe", "C:\\Program Files\\Google\\Chrome\\Application\\94.0.4606.81\\chrome_pwa_launcher.exe", "C:\\Program Files\\Google\\Chrome\\Application\\94.0.4606.81\\elevation_service.exe", "C:\\Program Files\\Google\\Chrome\\Application\\94.0.4606.81\\Installer\\chrmstp.exe", "C:\\Program Files\\Google\\Chrome\\Application\\94.0.4606.81\\Installer\\setup.exe", "C:\\Program Files\\Google\\Chrome\\Application\\94.0.4606.81\\nacl_irt_x86_64.nexe", "C:\\Program Files\\Google\\Chrome\\Application\\94.0.4606.81\\notification_helper.exe", "C:\\Program Files\\Google\\Chrome\\Application\\chrome.exe", "C:\\Program Files\\Google\\Chrome\\Application\\chrome_proxy.exe", "C:\\Program Files\\Internet Explorer\\iediagcmd.exe", "C:\\Program Files\\Internet Explorer\\ieinstal.exe", "C:\\Program Files\\Internet Explorer\\ielowutil.exe", "C:\\Program Files\\Internet Explorer\\iexplore.exe", "C:\\Program Files\\Mozilla Firefox\\crashreporter.exe", "C:\\Program Files\\Mozilla Firefox\\default-browser-agent.exe", "C:\\Program Files\\Mozilla Firefox\\firefox.exe", "C:\\Program Files\\Mozilla Firefox\\maintenanceservice.exe", "C:\\Program Files\\Mozilla Firefox\\maintenanceservice_installer.exe", "C:\\Program Files\\Mozilla Firefox\\minidump-analyzer.exe", "C:\\Program Files\\Mozilla Firefox\\pingsender.exe", "C:\\Program Files\\Mozilla Firefox\\plugin-container.exe", "C:\\Program Files\\Mozilla Firefox\\uninstall\\helper.exe", "C:\\Program Files\\Mozilla Firefox\\updater.exe", "C:\\Program Files\\Windows Defender\\MpCmdRun.exe", "C:\\Program Files\\Windows Defender\\MSASCui.exe", "C:\\Program Files\\Windows Mail\\wab.exe", "C:\\Program Files\\Windows Mail\\wabmig.exe", "C:\\Program Files\\Windows Photo Viewer\\ImagingDevices.exe", "C:\\Program Files (x86)\\Common Files\\microsoft shared\\ink\\mip.exe", "C:\\Program Files (x86)\\Common Files\\microsoft shared\\MSInfo\\msinfo32.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleCrashHandler.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleCrashHandler64.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleUpdate.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleUpdateBroker.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleUpdateComRegisterShell64.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleUpdateCore.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleUpdateOnDemand.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleUpdateSetup.exe", "C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe", "C:\\Program Files (x86)\\Internet Explorer\\ieinstal.exe", "C:\\Program Files (x86)\\Internet Explorer\\ielowutil.exe", "C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe", "C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe", "C:\\Program Files (x86)\\Mozilla Maintenance Service\\Uninstall.exe", "C:\\Program Files (x86)\\Windows Mail\\wab.exe", "C:\\Program Files (x86)\\Windows Mail\\wabmig.exe", "C:\\Program Files (x86)\\Windows Media Player\\setup_wm.exe", "C:\\Program Files (x86)\\Windows Media Player\\wmlaunch.exe", "C:\\Program Files (x86)\\Windows Media Player\\wmpconfig.exe", "C:\\Program Files (x86)\\Windows Media Player\\WMPDMC.exe", "C:\\Program Files (x86)\\Windows Media Player\\wmplayer.exe", "C:\\Program Files (x86)\\Windows Media Player\\wmprph.exe", "C:\\Program Files (x86)\\Windows Media Player\\wmpshare.exe", "C:\\Program Files (x86)\\Windows NT\\Accessories\\wordpad.exe", "C:\\Program Files (x86)\\Windows Photo Viewer\\ImagingDevices.exe", "C:\\$Recycle.Bin .exe", "C:\\aPnMrnpmSY .exe", "C:\\BgrMbIpK .exe", "C:\\Boot .exe", "C:\\bootmgr .exe", "C:\\BOOTSECT.BAK .exe", "C:\\cdQPgPwTtZ .exe", "C:\\Documents and Settings .exe", "C:\\pagefile.sys .exe", "C:\\PerfLogs .exe", "C:\\Program Files .exe", "C:\\Program Files (x86) .exe", "C:\\ProgramData .exe", "C:\\Recovery .exe", "C:\\System Volume Information .exe", "C:\\tmpa3vx5wa7 .exe", "C:\\tmpexryqjkw .exe", "C:\\tmpw3qc5zo4 .exe", "C:\\Users .exe", "C:\\Windows .exe", "C:\\ProgramData\\Package Cache\\{282975d8-55fe-4991-bbbb-06a72581ce58}\\VC_redist.x64.exe", "C:\\ProgramData\\Package Cache\\{e31cb1a4-76b5-46a5-a084-3fa419e82201}\\VC_redist.x86.exe", "C:\\tmpa3vx5wa7\\bin\\flashplayer.exe", "C:\\tmpa3vx5wa7\\bin\\Procmon.exe", "C:\\tmpexryqjkw\\bin\\flashplayer.exe", "C:\\tmpexryqjkw\\bin\\Procmon.exe", "C:\\tmpw3qc5zo4\\bin\\flashplayer.exe", "C:\\tmpw3qc5zo4\\bin\\Procmon.exe", "C:\\Users\\All Users\\Package Cache\\{282975d8-55fe-4991-bbbb-06a72581ce58}\\VC_redist.x64.exe", "C:\\Users\\All Users\\Package Cache\\{e31cb1a4-76b5-46a5-a084-3fa419e82201}\\VC_redist.x86.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\Update.exe", "C:\\Users\\John\\AppData\\Local\\Package Cache\\{8ba65a8c-cb48-4716-bc24-47c148808015}\\python-3.6.0.exe", "C:\\Users\\John\\AppData\\Roaming\\Microsoft\\Installer\\{C7D63030-7738-499A-A0D2-8549174D2B70}\\idle.exe", "C:\\Users\\John\\Downloads\\ChromeSetup.exe", "C:\\Users\\John\\Downloads\\winrar-x64-602.exe", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\background.png.exe", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\device.png.exe", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\overlay.png.exe", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\superbar.png.exe", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\background.png.exe", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\watermark.png.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile10.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile11.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile12.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile13.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile14.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile15.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile16.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile17.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile18.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile19.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile20.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile21.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile22.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile23.bmp.exe", "\\??\\PIPE\\samr", "C:\\Users\\John\\AppData\\Roaming\\Microsoft\\rmigca.exe", "C:\\ProgramData\\XyogosAE\\EEIEsYos.exe", "C:\\ProgramData\\AKwE.txt", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile24.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile25.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile26.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile27.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile28.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile29.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile30.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile31.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile32.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile33.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile34.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile35.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile36.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile37.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile38.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile39.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile40.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile41.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile42.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile43.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile44.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\guest.bmp.exe", "C:\\ProgramData\\Microsoft\\User Account Pictures\\user.bmp.exe", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\background.png.exe", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\device.png.exe", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\overlay.png.exe", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\superbar.png.exe", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\background.png.exe", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\watermark.png.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile10.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile11.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile12.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile13.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile14.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile15.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile16.bmp.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\file.vbs", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\choco.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\choco.exe.ignore", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\chocolatey.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\chocolatey.exe.ignore", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\cinst.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\cinst.exe.ignore", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\clist.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\clist.exe.ignore", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\cpack.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\cpack.exe.ignore", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\cpush.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\cpush.exe.ignore", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\cuninst.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\cuninst.exe.ignore", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\cup.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\cup.exe.ignore", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\cver.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\cver.exe.ignore", "C:\\Users\\John\\AppData\\Local\\Temp\\tools\\7z.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\tools\\7z.exe.ignore", "C:\\Users\\John\\AppData\\Local\\Temp\\tools\\7z.exe.manifest", "C:\\Users\\John\\AppData\\Local\\Temp\\tools\\checksum.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\tools\\checksum.exe.config", "C:\\Users\\John\\AppData\\Local\\Temp\\tools\\checksum.exe.ignore", "C:\\Users\\John\\AppData\\Local\\Temp\\tools\\shimgen.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\tools\\shimgen.exe.ignore", "C:\\Users\\John\\AppData\\Local\\Temp\\choco.exe.manifest", "C:\\Users\\John\\AppData\\Local\\Temp\\logs\\chocolatey.log", "C:\\Users\\John\\AppData\\Local\\Temp\\logs\\choco.summary.log", "C:\\Users\\John\\AppData\\Local\\Temp\\config\\chocolatey.config", "C:\\Users\\John\\AppData\\Local\\Temp\\config\\chocolatey.config.backup", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\chocolateyInstaller.psm1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\chocolateyProfile.psm1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Format-FileSize.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Get-CheckSumValid.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Get-ChocolateyUnzip.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Get-ChocolateyWebFile.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Get-FtpFile.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Get-OSArchitectureWidth.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Get-UACEnabled.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Get-VirusCheckValid.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Get-WebFile.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Get-WebHeaders.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Install-ChocolateyDesktopLink.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Install-ChocolateyEnvironmentVariable.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Install-ChocolateyExplorerMenuItem.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Install-ChocolateyFileAssociation.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Install-ChocolateyInstallPackage.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Install-ChocolateyPackage.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Install-ChocolateyPath.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Install-ChocolateyPinnedTaskBarItem.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Install-ChocolateyPowershellCommand.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Install-ChocolateyShortcut.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Install-ChocolateyVsixPackage.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Install-ChocolateyZipPackage.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Start-ChocolateyProcessAsAdmin.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Uninstall-ChocolateyPackage.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\UnInstall-ChocolateyZipPackage.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Update-SessionEnvironment.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Write-ChocolateyFailure.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Write-ChocolateySuccess.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Write-FileUpdateLog.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Get-EnvironmentVariable.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Get-EnvironmentVariableNames.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Set-EnvironmentVariable.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Test-ProcessAdminRights.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Install-BinFile.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Uninstall-BinFile.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\chocolateyScriptRunner.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Get-WebFileName.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Get-ToolsLocation.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\ChocolateyTabExpansion.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Set-PowerShellExitCode.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Install-Vsix.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Uninstall-ChocolateyEnvironmentVariable.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Get-UninstallRegistryKey.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Write-FunctionCallLogMessage.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\helpers\\functions\\Get-PackageParameters.ps1", "C:\\Users\\John\\AppData\\Local\\Temp\\LICENSE.txt", "C:\\Users\\John\\AppData\\Local\\Temp\\tools\\7zip.license.txt", "C:\\Users\\John\\AppData\\Local\\Temp\\tools\\checksum.license.txt", "C:\\Users\\John\\AppData\\Local\\Temp\\tools\\shimgen.license.txt", "C:\\Users\\John\\AppData\\Local\\Temp\\redirects\\RefreshEnv.cmd", "C:\\Users\\John\\AppData\\Local\\Temp\\tools\\7z.dll", "C:\\Users\\John\\AppData\\Local\\Temp\\tools\\7z.dll.manifest", "C:\\tmpcd9bps0i\\bin\\flashplayer.exe", "C:\\tmpcd9bps0i\\bin\\Procmon.exe", "C:\\Users\\John\\RKMcgggk\\PoEQoAEI", "C:\\ProgramData\\HWcAckgg\\QgQAYoYM", "C:\\Users\\John\\RKMcgggk\\PoEQoAEI.exe", "C:\\ProgramData\\HWcAckgg\\QgQAYoYM.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\choco.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile17.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile18.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile19.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile20.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile21.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile22.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile23.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile24.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile25.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile26.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile27.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile28.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile29.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile30.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile31.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile32.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile33.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile34.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile35.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile36.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile37.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile38.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile39.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile40.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile41.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile42.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile43.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile44.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\guest.bmp.exe", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\user.bmp.exe", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\aapocclcgogkmnckokdopfmhonfmgoek\\0.10_0\\icon_128.png.exe", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\aohghmighlieiainnegkcijnfilokake\\0.10_0\\icon_128.png.exe", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\apdfllckaahabafndbhieahigkjlhalf\\14.5_0\\128.png.exe", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.8_0\\128.png.exe", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\felcaaldnbdncclmgdcncolpebgiejap\\1.2_0\\icon_128.png.exe", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ghbmnnjooekpmoecnnnilnnbdlolhkhi\\1.33.0_0\\128.png.exe", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\1.0.0.6_0\\images\\flapper.gif.exe", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\1.0.0.6_0\\images\\icon_128.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_1.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_2.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_3.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_4.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_5.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_6.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_7.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_8.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_9.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_9plus.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\dlp_user_profile.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\favicon.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\favicon_white.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\MicrosoftTeams-static.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\send.png.exe", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Taskbar.png.exe", "C:\\Users\\John\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\oyr1ulp8.default-release\\thumbnails\\f6546de9cac3c8fe95cfa0b2917a6817.png.exe", "C:\\Users\\Public\\Music\\Sample Music\\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Large.jpg.exe", "C:\\Users\\Public\\Music\\Sample Music\\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Small.jpg.exe", "C:\\Users\\Public\\Music\\Sample Music\\Kalimba.mp3.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\setup.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\cpack.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\cver.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\clist.exe", "C:\\Users\\Public\\Music\\Sample Music\\Maid with the Flaxen Hair.mp3.exe", "C:\\Users\\Public\\Music\\Sample Music\\Sleep Away.mp3.exe", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Chrysanthemum.jpg.exe", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Desert.jpg.exe", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Hydrangeas.jpg.exe", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Jellyfish.jpg.exe", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Koala.jpg.exe", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Lighthouse.jpg.exe", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Penguins.jpg.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\chocolatey.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\cinst.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\cpush.exe", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Tulips.jpg.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\cuninst.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\Setup.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\cup.exe"], "delete_keys": ["HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{3DB408A3-ABF7-40B7-AC77-D2D6A3CF269F}\\WpadDetectedUrl", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{86639027-E931-4262-BED9-0EB0C34F1DA6}\\WpadDetectedUrl", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{A8FE60A0-D595-42A9-8EA8-83AD6A6E3710}\\WpadDetectedUrl", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{6F85D41E-8EB2-4608-8648-A7360A5E5DCC}\\WpadDetectedUrl", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{AB05CE41-DC42-451F-B7F3-B746D1D19C08}\\WpadDetectedUrl", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{D3F32EF0-7EB8-461B-9DB4-F87AB98DFAD0}\\WpadDetectedUrl", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{A0BFF2C1-B879-4635-A678-41406EF40CFF}\\WpadDetectedUrl", "HKEY_CURRENT_USER\\Software\\Microsoft\\Fax\\017d71903e4626773bd9fb9c\\Recent File List\\File1", "HKEY_CURRENT_USER\\Software\\Microsoft\\Fax\\017d71903e4626773bd9fb9c\\Recent File List\\File2", "HKEY_CURRENT_USER\\Software\\Microsoft\\Fax\\017d71903e4626773bd9fb9c\\Recent File List\\File3", "HKEY_CURRENT_USER\\Software\\Microsoft\\Fax\\017d71903e4626773bd9fb9c\\Recent File List\\File4", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\DictionaryBoss\\bar\\pid2", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\DictionaryBoss\\bar\\un", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyServer", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyOverride", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoDetect", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{41EF6C28-B2B9-4CE2-ADA9-BBC50C1E46D4}\\WpadDetectedUrl", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFavoritesInitialSelection", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFeedsInitialSelection", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_0", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_0", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_0", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_0", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_1", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_1", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_1", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_1", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_2", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_2", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_2", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_2", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_3", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_3", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_3", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_3", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_4", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_4", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_4", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_4", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_5", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_5", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_5", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_5", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_6", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_6", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_6", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_6", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_7", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_7", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_7", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_7", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_8", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_8", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_8", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_8", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_9", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_9", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_9", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_9", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_10", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_10", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_10", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_10", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_11", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_11", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_11", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_11", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_12", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_12", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_12", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_12", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_13", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_13", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_13", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_13", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_14", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_14", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_14", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_14", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_15", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_15", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_15", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_15", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_16", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_16", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_16", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_16", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_17", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_17", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_17", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_17", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_18", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_18", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_18", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_18", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_19", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_19", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_19", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_19", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_20", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_20", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_20", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_20", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_21", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_21", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_21", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_21", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_22", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_22", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_22", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_22", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_23", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_23", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_23", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_23", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_24", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_24", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_24", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_24", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_25", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_25", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_25", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_25", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_26", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_26", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_26", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_26", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_27", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_27", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_27", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_27", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_28", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_28", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_28", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_28", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_29", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_29", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_29", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_29", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_30", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_30", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_30", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_30", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_31", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_31", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_31", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_31", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_32", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_32", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_32", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_32", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_33", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_33", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_33", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_33", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_34", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_34", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_34", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_34", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_35", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_35", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_35", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_35", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_36", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_36", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_36", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_36", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_37", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_37", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_37", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_37", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_38", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_38", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_38", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_38", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_39", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_39", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_39", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_39", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_40", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_40", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_40", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_40", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_41", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_41", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_41", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_41", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_42", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_42", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_42", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_42", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_43", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_43", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_43", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_43", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_44", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_44", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_44", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_44", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_45", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_45", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_45", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_45", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_46", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_46", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_46", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_46", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_47", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_47", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_47", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_47", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_48", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_48", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_48", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_48", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_49", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_49", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_49", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_49", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_50", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_50", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_50", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_50", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_51", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_51", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_51", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_51", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_52", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_52", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_52", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_52", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_53", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_53", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_53", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_53", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_54", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_54", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_54", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_54", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_55", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_55", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_55", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_55", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_56", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_56", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_56", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_56", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_57", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_57", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_57", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_57", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_58", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_58", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_58", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_58", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_59", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_59", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_59", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_59", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_60", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_60", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_60", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_60", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_61", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_61", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_61", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_61", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_62", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_62", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_62", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_62", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_63", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_63", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_63", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_63", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_64", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_64", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_64", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_64", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_65", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_65", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_65", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_65", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_66", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_66", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_66", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_66", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_67", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_67", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_67", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_67", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_68", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_68", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_68", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_68", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_69", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_69", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_69", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_69", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_70", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_70", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_70", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_70", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_71", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_71", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_71", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_71", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_72", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_72", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_72", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_72", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_73", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_73", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_73", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_73", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_74", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_74", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_74", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_74", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_75", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_75", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_75", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_75", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_76", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_76", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_76", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_76", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_77", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_77", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_77", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_77", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_78", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_78", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_78", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_78", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_79", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_79", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_79", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_79", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_80", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_80", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_80", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_80", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_81", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_81", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_81", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_81", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_82", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_82", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_82", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_82", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_83", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_83", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_83", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_83", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_84", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_84", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_84", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_84", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_85", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_85", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_85", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_85", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_86", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_86", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_86", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_86", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_87", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_87", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_87", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_87", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_88", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_88", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_88", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_88", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_89", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_89", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_89", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_89", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_90", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_90", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_90", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_90", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_91", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_91", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_91", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_91", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_92", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_92", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_92", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_92", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_93", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_93", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_93", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_93", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_94", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_94", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_94", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_94", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_95", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_95", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_95", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_95", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_96", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_96", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_96", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_96", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_97", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_97", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_97", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_97", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_98", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_98", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_98", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_98", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_99", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_99", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_99", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_99", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_100", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_100", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_100", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_100", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_101", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_101", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_101", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_101", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_102", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_102", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_102", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_102", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_103", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_103", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_103", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_103", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_104", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_104", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_104", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_104", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_105", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_105", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_105", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_105", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_106", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_106", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_106", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_106", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_107", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_107", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_107", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_107", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_108", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_108", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_108", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_108", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_109", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_109", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_109", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_109", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_110", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_110", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_110", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_110", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_111", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_111", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_111", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_111", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_112", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_112", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_112", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_112", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_113", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_113", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_113", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_113", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_114", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_114", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_114", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_114", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_115", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_115", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_115", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_115", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_116", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_116", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_116", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_116", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_117", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_117", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_117", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_117", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_118", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_118", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_118", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_118", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_119", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_119", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_119", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_119", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_120", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_120", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_120", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_120", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_121", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_121", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_121", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_121", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_122", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_122", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_122", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_122", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_123", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_123", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_123", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_123", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_124", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_124", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_124", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_124", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_125", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_125", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_125", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_125", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_126", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_126", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_126", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_126", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_127", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_127", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_127", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_127", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_128", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_128", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_128", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_128", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_129", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_129", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_129", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_129", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_130", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_130", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_130", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_130", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_131", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_131", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_131", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_131", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_132", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_132", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_132", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_132", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_133", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_133", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_133", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_133", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_134", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_134", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_134", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_134", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_135", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_135", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_135", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_135", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_136", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_136", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_136", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_136", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_137", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_137", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_137", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_137", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_138", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_138", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_138", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_138", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_139", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_139", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_139", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_139", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_140", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_140", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_140", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_140", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_141", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_141", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_141", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_141", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_142", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_142", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_142", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_142", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_143", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_143", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_143", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_143", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_144", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_144", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_144", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_144", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_145", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_145", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_145", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_145", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_146", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_146", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_146", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_146", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_147", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_147", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_147", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_147", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_148", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_148", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_148", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_148", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_149", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_149", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_149", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_149", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_150", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_150", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_150", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_150", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_151", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_151", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_151", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_151", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_152", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_152", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_152", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_152", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_153", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_153", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_153", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_153", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_154", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_154", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_154", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_154", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_155", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_155", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_155", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_155", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_156", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_156", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_156", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_156", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_157", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_157", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_157", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_157", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_158", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_158", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_158", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_158", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_159", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_159", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_159", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_159", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_160", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_160", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_160", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_160", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_161", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_161", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_161", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_161", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_162", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_162", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_162", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_162", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_163", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_163", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_163", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_163", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_164", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_164", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_164", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_164", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_165", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_165", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_165", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_165", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_166", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_166", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_166", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_166", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_167", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_167", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_167", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_167", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_168", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_168", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_168", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_168", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_169", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_169", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_169", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_169", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_170", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_170", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_170", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_170", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_171", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_171", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_171", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_171", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_172", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_172", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_172", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_172", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_173", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_173", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_173", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_173", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_174", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_174", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_174", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_174", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_175", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_175", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_175", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_175", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_176", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_176", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_176", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_176", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_177", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_177", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_177", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_177", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_178", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_178", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_178", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_178", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_179", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_179", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_179", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_179", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_180", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_180", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_180", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_180", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_181", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_181", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_181", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_181", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_182", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_182", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_182", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_182", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_183", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_183", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_183", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_183", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_184", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_184", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_184", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_184", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_185", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_185", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_185", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_185", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_186", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_186", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_186", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_186", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_187", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_187", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_187", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_187", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_188", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_188", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_188", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_188", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_189", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_189", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_189", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_189", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_190", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_190", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_190", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_190", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_191", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_191", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_191", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_191", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_192", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_192", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_192", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_192", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_193", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_193", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_193", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_193", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_194", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_194", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_194", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_194", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_195", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_195", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_195", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_195", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_196", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_196", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_196", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_196", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_197", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_197", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_197", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_197", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_198", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_198", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_198", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_198", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_199", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_199", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_199", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_199", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_200", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_200", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_200", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_200", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_201", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_201", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_201", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_201", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_202", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_202", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_202", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_202", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_203", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_203", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_203", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_203", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_204", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_204", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_204", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_204", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_205", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_205", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_205", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_205", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_206", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_206", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_206", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_206", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_207", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_207", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_207", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_207", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_208", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_208", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_208", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_208", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_209", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_209", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_209", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_209", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_210", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_210", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_210", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_210", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_211", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_211", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_211", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_211", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_212", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_212", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_212", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_212", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_213", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_213", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_213", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_213", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_214", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_214", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_214", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_214", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_215", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_215", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_215", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_215", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_216", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_216", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_216", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_216", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_217", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_217", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_217", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_217", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_218", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_218", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_218", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_218", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_219", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_219", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_219", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_219", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_220", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_220", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_220", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_220", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_221", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_221", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_221", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_221", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_222", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_222", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_222", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_222", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_223", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_223", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_223", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_223", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_224", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_224", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_224", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_224", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_225", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_225", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_225", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_225", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_226", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_226", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_226", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_226", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_227", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_227", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_227", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_227", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_228", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_228", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_228", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_228", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_229", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_229", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_229", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_229", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_230", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_230", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_230", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_230", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_231", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_231", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_231", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_231", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_232", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_232", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_232", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_232", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_233", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_233", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_233", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_233", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_234", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_234", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_234", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_234", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_235", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_235", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_235", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_235", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_236", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_236", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_236", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_236", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_237", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_237", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_237", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_237", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_238", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_238", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_238", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_238", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_239", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_239", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_239", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_239", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_240", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_240", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_240", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_240", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_241", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_241", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_241", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_241", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_242", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_242", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_242", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_242", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_243", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_243", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_243", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_243", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_244", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_244", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_244", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_244", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_245", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_245", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_245", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_245", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_246", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_246", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_246", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_246", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_247", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_247", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_247", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_247", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_248", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_248", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_248", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_248", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_249", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_249", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_249", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_249", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_250", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_250", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_250", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_250", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_251", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_251", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_251", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_251", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_252", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_252", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_252", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_252", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_253", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_253", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_253", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_253", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_254", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_254", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_254", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_254", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_255", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_255", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_255", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_255", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_256", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_256", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_256", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_256", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_257", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_257", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_257", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_257", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_258", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_258", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_258", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_258", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_259", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_259", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_259", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_259", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_260", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_260", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_260", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_260", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_261", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_261", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_261", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_261", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_262", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_262", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_262", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_262", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_263", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_263", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_263", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_263", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_264", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_264", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_264", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_264", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_265", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_265", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_265", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_265", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_266", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_266", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_266", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_266", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_267", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_267", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_267", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_267", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_268", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_268", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_268", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_268", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_269", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_269", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_269", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_269", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_270", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_270", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_270", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_270", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_271", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_271", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_271", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_271", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_272", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_272", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_272", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_272", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_273", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_273", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_273", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_273", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_274", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_274", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_274", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_274", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_275", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_275", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_275", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_275", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_276", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_276", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_276", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_276", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_277", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_277", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_277", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_277", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_278", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_278", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_278", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_278", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_279", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_279", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_279", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_279", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_280", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_280", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_280", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_280", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_281", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_281", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_281", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_281", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_282", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_282", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_282", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_282", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_283", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_283", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_283", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_283", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_284", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_284", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_284", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_284", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_285", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_285", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_285", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_285", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_286", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_286", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_286", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_286", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_287", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_287", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_287", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_287", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_288", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_288", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_288", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_288", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_289", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_289", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_289", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_289", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_290", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_290", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_290", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_290", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_291", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_291", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_291", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_291", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_292", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_292", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_292", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_292", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_293", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_293", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_293", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_293", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_294", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_294", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_294", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_294", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_295", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_295", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_295", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_295", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_296", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_296", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_296", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_296", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_297", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_297", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_297", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_297", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_298", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_298", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_298", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_298", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_299", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_299", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_299", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_299", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_300", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_300", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_300", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_300", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_301", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_301", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_301", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_301", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_302", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_302", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_302", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_302", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_303", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_303", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_303", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_303", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_304", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_304", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_304", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_304", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_305", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_305", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_305", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_305", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_306", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_306", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_306", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_306", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_307", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_307", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_307", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_307", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_308", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_308", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_308", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_308", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_309", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_309", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_309", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_309", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_310", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_310", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_310", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_310", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_311", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_311", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_311", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_311", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_312", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_312", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_312", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_312", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_313", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_313", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_313", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_313", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_314", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_314", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_314", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_314", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_315", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_315", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_315", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_315", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_316", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_316", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_316", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_316", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_317", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_317", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_317", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_317", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_318", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_318", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_318", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_318", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_319", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_319", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_319", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_319", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_320", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_320", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_320", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_320", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_321", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_321", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_321", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_321", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_322", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_322", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_322", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_322", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_323", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_323", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_323", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_323", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_324", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_324", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_324", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_324", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_325", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_325", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_325", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_325", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_326", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_326", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_326", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_326", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_327", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_327", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_327", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_327", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_328", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_328", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_328", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_328", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_329", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_329", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_329", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_329", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_330", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_330", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_330", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_330", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_331", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_331", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_331", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_331", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_332", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_332", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_332", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_332", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_333", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_333", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_333", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_333", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_334", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_334", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_334", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_334", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_335", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_335", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_335", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_335", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_336", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_336", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_336", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_336", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_337", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_337", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_337", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_337", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_338", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_338", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_338", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_338", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_339", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_339", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_339", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_339", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_340", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_340", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_340", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_340", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_341", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_341", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_341", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_341", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_342", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_342", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_342", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_342", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_343", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_343", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_343", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_343", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_344", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_344", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_344", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_344", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_345", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_345", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_345", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_345", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_346", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_346", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_346", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_346", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_347", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_347", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_347", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_347", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_348", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_348", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_348", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_348", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_349", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_349", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_349", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_349", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_350", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_350", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_350", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_350", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_351", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_351", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_351", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_351", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_352", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_352", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_352", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_352", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_353", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_353", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_353", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_353", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_354", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_354", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_354", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_354", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_355", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_355", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_355", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_355", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_356", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_356", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_356", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_356", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_357", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_357", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_357", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_357", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_358", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_358", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_358", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_358", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_359", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_359", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_359", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_359", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_360", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_360", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_360", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_360", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_361", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_361", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_361", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_361", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_362", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_362", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_362", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_362", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_363", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_363", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_363", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_363", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_364", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_364", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_364", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_364", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_365", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_365", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_365", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_365", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_366", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_366", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_366", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_366", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_367", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_367", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_367", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_367", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_368", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_368", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_368", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_368", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_369", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_369", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_369", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_369", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_370", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_370", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_370", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_370", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_371", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_371", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_371", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_371", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_372", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_372", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_372", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_372", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_373", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_373", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_373", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_373", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_374", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_374", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_374", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_374", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_375", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_375", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_375", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_375", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_376", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_376", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_376", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_376", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_377", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_377", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_377", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_377", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_378", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_378", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_378", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_378", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_379", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_379", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_379", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_379", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_380", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_380", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_380", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_380", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_381", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_381", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_381", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_381", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_382", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_382", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_382", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_382", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_383", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_383", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_383", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_383", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_384", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_384", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_384", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_384", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_385", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_385", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_385", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_385", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_386", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_386", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_386", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_386", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_387", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_387", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_387", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_387", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_388", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_388", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_388", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_388", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_389", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_389", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_389", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_389", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_390", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_390", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_390", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_390", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_391", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_391", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_391", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_391", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_392", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_392", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_392", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_392", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_393", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_393", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_393", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_393", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_394", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_394", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_394", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_394", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_395", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_395", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_395", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_395", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_396", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_396", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_396", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_396", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_397", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_397", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_397", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_397", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_398", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_398", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_398", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_398", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_399", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_399", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_399", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_399", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_400", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_400", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_400", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_400", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_401", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_401", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_401", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_401", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_402", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_402", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_402", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_402", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_403", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_403", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_403", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_403", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_404", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_404", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_404", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_404", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_405", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_405", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_405", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_405", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_406", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_406", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_406", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_406", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_407", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_407", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_407", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_407", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_408", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_408", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_408", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_408", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_409", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_409", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_409", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_409", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_410", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_410", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_410", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_410", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_411", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_411", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_411", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_411", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_412", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_412", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_412", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_412", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_413", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_413", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_413", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_413", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_414", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_414", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_414", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_414", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_415", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_415", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_415", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_415", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_416", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_416", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_416", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_416", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_417", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_417", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_417", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_417", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_418", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_418", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_418", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_418", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_419", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_419", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_419", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_419", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_420", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_420", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_420", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_420", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_421", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_421", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_421", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_421", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_422", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_422", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_422", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_422", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_423", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_423", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_423", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_423", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_424", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_424", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_424", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_424", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_425", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_425", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_425", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_425", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_426", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_426", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_426", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_426", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_427", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_427", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_427", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_427", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_428", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_428", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_428", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_428", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_429", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_429", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_429", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_429", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_430", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_430", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_430", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_430", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_431", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_431", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_431", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_431", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_432", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_432", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_432", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_432", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_433", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_433", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_433", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_433", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_434", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_434", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_434", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_434", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_435", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_435", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_435", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_435", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_436", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_436", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_436", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_436", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_437", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_437", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_437", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_437", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_438", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_438", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_438", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_438", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_439", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_439", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_439", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_439", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_440", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_440", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_440", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_440", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_441", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_441", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_441", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_441", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_442", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_442", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_442", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_442", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_443", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_443", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_443", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_443", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_444", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_444", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_444", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_444", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_445", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_445", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_445", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_445", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_446", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_446", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_446", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_446", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_447", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_447", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_447", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_447", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_448", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_448", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_448", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_448", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_449", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_449", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_449", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_449", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_450", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_450", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_450", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_450", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_451", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_451", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_451", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_451", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_452", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_452", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_452", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_452", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_453", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_453", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_453", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_453", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_454", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_454", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_454", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_454", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_455", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_455", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_455", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_455", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_456", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_456", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_456", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_456", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_457", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_457", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_457", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_457", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_458", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_458", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_458", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_458", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_459", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_459", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_459", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_459", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_460", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_460", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_460", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_460", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_461", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_461", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_461", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_461", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_462", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_462", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_462", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_462", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_463", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_463", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_463", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_463", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_464", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_464", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_464", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_464", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_465", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_465", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_465", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_465", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_466", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_466", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_466", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_466", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_467", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_467", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_467", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_467", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_468", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_468", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_468", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_468", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_469", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_469", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_469", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_469", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_470", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_470", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_470", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_470", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_471", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_471", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_471", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_471", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_472", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_472", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_472", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_472", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_473", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_473", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_473", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_473", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_474", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_474", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_474", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_474", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_475", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_475", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_475", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_475", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_476", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_476", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_476", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_476", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_477", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_477", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_477", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_477", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_478", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_478", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_478", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_478", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_479", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_479", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_479", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_479", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_480", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_480", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_480", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_480", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_481", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_481", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_481", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_481", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_482", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_482", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_482", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_482", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_483", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_483", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_483", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_483", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_484", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_484", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_484", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_484", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_485", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_485", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_485", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_485", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_486", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_486", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_486", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_486", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_487", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_487", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_487", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_487", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_488", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_488", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_488", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_488", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_489", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_489", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_489", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_489", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_490", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_490", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_490", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_490", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_491", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_491", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_491", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_491", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_492", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_492", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_492", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_492", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_493", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_493", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_493", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_493", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_494", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_494", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_494", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_494", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_495", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_495", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_495", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_495", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_496", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_496", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_496", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_496", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_497", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_497", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_497", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_497", "HKEY_CURRENT_USER\\Software\\Xjfk\\11_498", "HKEY_CURRENT_USER\\Software\\Xjfk\\12_498", "HKEY_CURRENT_USER\\Software\\Xjfk\\13_498", "HKEY_CURRENT_USER\\Software\\Xjfk\\14_498", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{CF07CE59-A735-4B89-B34F-FCB1AF9DCB76}\\WpadDetectedUrl", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{127B4FEF-7EF8-4EA1-A2E1-FB02181BA2EE}\\WpadDetectedUrl", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\internat.exe", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Load", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\2\\1\\MRUList", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\2\\1\\0\\MRUList", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\2\\1\\0\\0\\MRUList", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\2\\1\\0\\0\\0\\MRUList", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Streams\\Settings", "HKEY_CURRENT_USER\\Software\\Mozilla\\Firefox\\Installer\\308046B0AF4A39CB\\installer.taskbarpin.win10.enabled", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\Active\\{00000000-0000-0000-0000-000000000000}", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\MuiCache\\@%windir%\\System32\\ieframe.dll,-12385", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\MuiCache\\@C:\\Windows\\System32\\ieframe.dll,-12385", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\Deleted", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\TabbedBrowsing\\NewTabPage\\MFV", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\MsPatch", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\MsPatch", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\LoadService", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\LoadService", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\LoadServices", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\LoadServices", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\CCAPPS", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\CCAPPS", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\ccapp", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\ccapp", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\OSA", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\OSA", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\SymRun", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\SymRun", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\local service", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\local service", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Security", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\dkernel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\dkernel", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\dkernel.exe", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\dkernel.exe", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\lExplorer", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\lExplorer", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\iExplorer", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\iExplorer", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\DllHost", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\DllHost", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Pluto", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Pluto", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\SysRia", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\SysRia", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Sys_Romantic-Devil.R", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Sys_Romantic-Devil.R", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\SysDiaz", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\SysDiaz", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\SysYuni", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\SysYuni", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Adie Strio X", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Adie Strio X", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Adie Suka Kamu", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Adie Suka Kamu"], "read_keys": ["DisableUserModeCallbackFilter", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\WMR\\Disable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\GRE_Initialize\\DisableMetaFiles", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\DataStore_V1.0\\Disable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\DataStore_V1.0\\DataFilePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane2", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane3", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane4", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane6", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane7", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane8", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane9", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane10", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane11", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane12", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane13", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane14", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane15", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\LanguagePack\\SurrogateFallback\\Plane16", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SQMClient\\Windows\\CEIPEnable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\SQMClient\\Windows\\CEIPEnable", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Versions\\00060101.00060101", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\SafeProcessSearchMode", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ee82dad3-29d6-11ec-88e3-806e6f6e6963}\\Data", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ee82dad3-29d6-11ec-88e3-806e6f6e6963}\\Generation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ee82dad6-29d6-11ec-88e3-806e6f6e6963}\\Data", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ee82dad6-29d6-11ec-88e3-806e6f6e6963}\\Generation", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ee82dad2-29d6-11ec-88e3-806e6f6e6963}\\Data", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ee82dad2-29d6-11ec-88e3-806e6f6e6963}\\Generation", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Policies\\Explorer\\DontShowSuperHidden", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Policies\\Explorer\\NoWebView", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Policies\\Explorer\\ClassicShell", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Policies\\Explorer\\SeparateProcess", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetCrawling", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSimpleStartMenu", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Rpc\\Extensions\\NdrOleExtDLL", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0\\Disable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0\\DataFilePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane2", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane3", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane4", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane5", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane6", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane7", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane8", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane9", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane10", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane11", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane12", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane13", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane14", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane15", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\Plane16", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\932", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\949", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\950", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\936", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\\InitFolderHandler", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Desktop", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\\InitFolderHandler", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\CallForAttributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\RestrictedAttributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsFORDISPLAY", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HideFolderVerbs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\UseDropHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsFORPARSING", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsParseDisplayName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\QueryForOverlay", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\MapNetDriveVerbs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\QueryForInfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HideInWebView", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HideOnDesktopPerUser", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsAliasedNotifications", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\WantsUniversalDelegate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\NoFileFolderJunction", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\PinToNameSpaceTree", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\\ShellFolder\\HasNavigationEnum", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Category", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParentFolder", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Description", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\RelativePath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParsingName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InfoTip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalizedName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Icon", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Security", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResource", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResourceType", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalRedirectOnly", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Roamable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PreCreate", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Stream", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PublishExpandedPath", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Attributes", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\FolderTypeID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InitFolderHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\DisableUNCCheck", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\EnableExtensions", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\DelayedExpansion", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\DefaultColor", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\CompletionChar", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\PathCompletionChar", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\AutoRun", "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DisableUNCCheck", "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\EnableExtensions", "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DelayedExpansion", "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DefaultColor", "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\CompletionChar", "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\PathCompletionChar", "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\AutoRun", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\NetworkProvider\\HwOrder\\ProviderOrder", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPNP\\NetworkProvider\\name", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPNP\\NetworkProvider\\Class", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RDPNP\\NetworkProvider\\ProviderPath", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\NetworkProvider\\name", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\NetworkProvider\\Class", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\NetworkProvider\\ProviderPath", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\NetworkProvider\\name", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\NetworkProvider\\Class", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WebClient\\NetworkProvider\\ProviderPath", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\NetworkProvider\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\InprocServer32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\ThreadingModel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\InstallRoot", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\CLRLoadLogDir", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\UseLegacyV2RuntimeActivationPolicyDefaultValue", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\OnlyUseLatestCLR", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\NoClientChecks", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\NET Framework Setup\\NDP\\v4\\Full\\Release", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\DisableConfigCache", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\CacheLocation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\DownloadCacheQuotaInKB", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\EnableLog", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\LoggingLevel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\ForceLog", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\LogFailures", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\LogResourceBinds", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\FileInUseRetryAttempts", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\FileInUseMillisecondsBetweenRetries", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\UseLegacyIdentityFormat", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\DisableMSIPeek", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\Image File Execution Options\\DevOverrideEnable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\NGen\\Policy\\v4.0\\OptimizeUsedBinaries", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\UseRyuJIT", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\.NETFramework\\FeatureSIMD", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\Latest", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\index4", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\Fusion\\PublisherPolicy\\Default\\LegacyPolicyTimeStamp", "HKEY_LOCAL_MACHINE\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\Winlogon\\Userinit", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows Script Host\\Settings\\IgnoreUserSettings", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Script Host\\Settings\\Enabled", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows Script Host\\Settings\\Enabled", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Script Host\\Settings\\LogSecuritySuccesses", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows Script Host\\Settings\\LogSecuritySuccesses", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Script Host\\Settings\\TrustPolicy", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Script Host\\Settings\\UseWINSAFER", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows Script Host\\Settings\\TrustPolicy", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows Script Host\\Settings\\UseWINSAFER", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows Script Host\\Settings\\Timeout", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows Script Host\\Settings\\DisplayLogo", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Script Host\\Settings\\Timeout", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Script Host\\Settings\\DisplayLogo", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.vbs\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VBSFile\\ScriptEngine\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\VBScript\\CLSID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\InstallRoot", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\CLRLoadLogDir", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\UseLegacyV2RuntimeActivationPolicyDefaultValue", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\OnlyUseLatestCLR", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NoClientChecks", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\DisableConfigCache", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\CacheLocation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\DownloadCacheQuotaInKB", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\EnableLog", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\LoggingLevel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\ForceLog", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\LogFailures", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\LogResourceBinds", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\UseLegacyIdentityFormat", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\DisableMSIPeek", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\DevOverrideEnable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\Latest", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\index4", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\PublisherPolicy\\Default\\LegacyPolicyTimeStamp", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\Enabled", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy", "HKEY_CURRENT_USER\\Control Panel\\International\\Geo\\Nation", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\NET Framework Setup\\NDP\\v4\\Full\\Release", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\FileInUseRetryAttempts", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\FileInUseMillisecondsBetweenRetries", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\NGen\\Policy\\v4.0\\OptimizeUsedBinaries", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\UseRyuJIT", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\FeatureSIMD", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit"], "delete_files": ["C:\\Program Files\\1qtepma820\\VMware Tools\\vmtoolsd.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMToolsHookProc.exe", "C:\\stop", "C:\\Miram", "C:\\Miraj", "C:\\Miray", "C:\\Mirab", "C:\\Mirap", "C:\\Mirae", "C:\\Mirau", "C:\\Mirav", "C:\\Mirad", "C:\\Mirai", "C:\\Mirar", "C:\\Miras", "C:\\Miraw", "C:\\Mirax", "C:\\Mirat", "C:\\Mirah", "C:\\Miran", "C:\\Miraf", "C:\\Mirac", "C:\\Mirak", "C:\\Miraa", "C:\\Mirao", "C:\\Miraq", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\background.png", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\device.png", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\overlay.png", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\superbar.png", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\background.png", "C:\\ProgramData\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\watermark.png", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile10.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile11.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile12.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile13.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile14.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile15.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile16.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile17.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile18.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile19.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile20.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile21.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile22.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile23.bmp", "C:\\Mirag", "C:\\Miral", "C:\\Users\\John\\AppData\\Local\\Temp", "C:\\Users\\John\\AppData\\Local\\microsoft\\Teams\\update.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\wmpscfgs.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\7za.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\rpctool.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMware VGAuth\\VGAuthCLI.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMware VGAuth\\VGAuthService.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMware VGAuth\\VMwareAliasImport.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMwareNamespaceCmd.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMwareResolutionSet.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMwareToolboxCmd.exe", "C:\\Program Files\\1qtepma820\\VMware Tools\\VMwareXferlogs.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\ConvertInkStore.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\FlickLearningWizard.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\InkWatson.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\InputPersonalization.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\mip.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\ShapeCollector.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\TabTip.exe", "C:\\Program Files\\Common Files\\Microsoft Shared\\MSInfo\\msinfo32.exe", "C:\\Program Files\\Common Files\\q40bqc0qmn\\Drivers\\video_wddm\\Vista\\vm3dservice.exe", "C:\\Program Files\\Common Files\\q40bqc0qmn\\Drivers\\vss\\comreg.exe", "C:\\Program Files\\DVD Maker\\DVDMaker.exe", "C:\\Program Files\\Google\\Chrome\\Application\\94.0.4606.81\\chrome_pwa_launcher.exe", "C:\\Program Files\\Google\\Chrome\\Application\\94.0.4606.81\\elevation_service.exe", "C:\\Program Files\\Google\\Chrome\\Application\\94.0.4606.81\\Installer\\chrmstp.exe", "C:\\Program Files\\Google\\Chrome\\Application\\94.0.4606.81\\Installer\\setup.exe", "C:\\Program Files\\Google\\Chrome\\Application\\94.0.4606.81\\notification_helper.exe", "C:\\Program Files\\Google\\Chrome\\Application\\chrome.exe", "C:\\Program Files\\Google\\Chrome\\Application\\chrome_proxy.exe", "C:\\Program Files\\Internet Explorer\\iediagcmd.exe", "C:\\Program Files\\Internet Explorer\\ieinstal.exe", "C:\\Program Files\\Internet Explorer\\ielowutil.exe", "C:\\Program Files\\Internet Explorer\\iexplore.exe", "C:\\Program Files\\Mozilla Firefox\\crashreporter.exe", "C:\\Program Files\\Mozilla Firefox\\default-browser-agent.exe", "C:\\Program Files\\Mozilla Firefox\\firefox.exe", "C:\\Program Files\\Mozilla Firefox\\maintenanceservice.exe", "C:\\Program Files\\Mozilla Firefox\\maintenanceservice_installer.exe", "C:\\Program Files\\Mozilla Firefox\\minidump-analyzer.exe", "C:\\Program Files\\Mozilla Firefox\\pingsender.exe", "C:\\Program Files\\Mozilla Firefox\\plugin-container.exe", "C:\\Program Files\\Mozilla Firefox\\uninstall\\helper.exe", "C:\\Program Files\\Mozilla Firefox\\updater.exe", "C:\\Program Files\\Windows Defender\\MpCmdRun.exe", "C:\\Program Files\\Windows Defender\\MSASCui.exe", "C:\\Program Files\\Windows Mail\\wab.exe", "C:\\Program Files\\Windows Mail\\wabmig.exe", "C:\\Program Files\\Windows Media Player\\setup_wm.exe", "C:\\Program Files\\Windows Media Player\\wmlaunch.exe", "C:\\Program Files\\Windows Media Player\\wmpconfig.exe", "C:\\Program Files\\Windows Media Player\\WMPDMC.exe", "C:\\Program Files\\Windows Media Player\\wmpenc.exe", "C:\\Program Files\\Windows Media Player\\wmplayer.exe", "C:\\Program Files\\Windows Media Player\\wmpnetwk.exe", "C:\\Program Files\\Windows Media Player\\wmpnscfg.exe", "C:\\Program Files\\Windows Media Player\\wmprph.exe", "C:\\Program Files\\Windows Media Player\\wmpshare.exe", "C:\\Program Files\\Windows Media Player\\WMPSideShowGadget.exe", "C:\\Program Files\\Windows NT\\Accessories\\wordpad.exe", "C:\\Program Files\\Windows Photo Viewer\\ImagingDevices.exe", "C:\\Program Files\\Windows Sidebar\\sidebar.exe", "C:\\Program Files\\WinRAR\\Rar.exe", "C:\\Program Files\\WinRAR\\Uninstall.exe", "C:\\Program Files\\WinRAR\\UnRAR.exe", "C:\\Program Files\\WinRAR\\WinRAR.exe", "C:\\Program Files (x86)\\Common Files\\microsoft shared\\ink\\mip.exe", "C:\\Program Files (x86)\\Common Files\\microsoft shared\\ink\\pipanel.exe", "C:\\Program Files (x86)\\Common Files\\microsoft shared\\ink\\TabTip32.exe", "C:\\Program Files (x86)\\Common Files\\microsoft shared\\MSInfo\\msinfo32.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleCrashHandler.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleCrashHandler64.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleUpdate.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleUpdateBroker.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleUpdateComRegisterShell64.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleUpdateCore.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleUpdateOnDemand.exe", "C:\\Program Files (x86)\\Google\\Update\\1.3.36.112\\GoogleUpdateSetup.exe", "C:\\Program Files (x86)\\Google\\Update\\Download\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\94.0.4606.81\\94.0.4606.81_chrome_installer.exe", "C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe", "C:\\Program Files (x86)\\Internet Explorer\\ExtExport.exe", "C:\\Program Files (x86)\\Internet Explorer\\ieinstal.exe", "C:\\Program Files (x86)\\Internet Explorer\\ielowutil.exe", "C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe", "C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe", "C:\\Program Files (x86)\\Mozilla Maintenance Service\\Uninstall.exe", "C:\\Program Files (x86)\\Windows Mail\\wab.exe", "C:\\Program Files (x86)\\Windows Mail\\wabmig.exe", "C:\\Program Files (x86)\\Windows Media Player\\setup_wm.exe", "C:\\Program Files (x86)\\Windows Media Player\\wmlaunch.exe", "C:\\Program Files (x86)\\Windows Media Player\\wmpconfig.exe", "C:\\Program Files (x86)\\Windows Media Player\\WMPDMC.exe", "C:\\Program Files (x86)\\Windows Media Player\\wmpenc.exe", "C:\\Program Files (x86)\\Windows Media Player\\wmplayer.exe", "C:\\Program Files (x86)\\Windows Media Player\\wmprph.exe", "C:\\Program Files (x86)\\Windows Media Player\\wmpshare.exe", "C:\\Program Files (x86)\\Windows NT\\Accessories\\wordpad.exe", "C:\\Program Files (x86)\\Windows Photo Viewer\\ImagingDevices.exe", "C:\\Program Files (x86)\\Windows Sidebar\\sidebar.exe", "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegAsm.exe", "C:\\Windows\\System32\\explorer.exe", "C:\\Users\\John\\AppData\\Local\\Temp\\HGDraw.dll", "C:\\Users\\John\\AppData\\Local\\Temp\\sanfdr.bat", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile24.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile25.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile26.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile27.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile28.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile29.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile30.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile31.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile32.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile33.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile34.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile35.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile36.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile37.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile38.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile39.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile40.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile41.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile42.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile43.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\Default Pictures\\usertile44.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\guest.bmp", "C:\\ProgramData\\Microsoft\\User Account Pictures\\user.bmp", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\background.png", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\device.png", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\overlay.png", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{113527a4-45d4-4b6f-b567-97838f1b04b0}\\superbar.png", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\background.png", "C:\\Users\\All Users\\Microsoft\\Device Stage\\Device\\{8702d817-5aad-4674-9ef3-4d3decd87120}\\watermark.png", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile10.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile11.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile12.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile13.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile14.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile15.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile16.bmp", "C:\\Users\\John\\AppData\\Local\\Temp\\config\\chocolatey.config", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile17.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile18.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile19.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile20.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile21.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile22.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile23.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile24.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile25.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile26.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile27.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile28.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile29.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile30.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile31.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile32.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile33.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile34.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile35.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile36.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile37.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile38.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile39.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile40.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile41.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile42.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile43.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\Default Pictures\\usertile44.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\guest.bmp", "C:\\Users\\All Users\\Microsoft\\User Account Pictures\\user.bmp", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\aapocclcgogkmnckokdopfmhonfmgoek\\0.10_0\\icon_128.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\aohghmighlieiainnegkcijnfilokake\\0.10_0\\icon_128.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\apdfllckaahabafndbhieahigkjlhalf\\14.5_0\\128.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.8_0\\128.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\felcaaldnbdncclmgdcncolpebgiejap\\1.2_0\\icon_128.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ghbmnnjooekpmoecnnnilnnbdlolhkhi\\1.33.0_0\\128.png", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\1.0.0.6_0\\images\\flapper.gif", "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\1.0.0.6_0\\images\\icon_128.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_1.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_2.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_3.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_4.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_5.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_6.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_7.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_8.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_9.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Badge_9plus.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\dlp_user_profile.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\favicon.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\favicon_white.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\MicrosoftTeams-static.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\send.png", "C:\\Users\\John\\AppData\\Local\\Microsoft\\Teams\\current\\resources\\assets\\Taskbar.png", "C:\\Users\\John\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\oyr1ulp8.default-release\\thumbnails\\f6546de9cac3c8fe95cfa0b2917a6817.png", "C:\\RCX7ADA.tmp", "C:\\Users\\Public\\Music\\Sample Music\\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Large.jpg", "C:\\Users\\Public\\Music\\Sample Music\\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Small.jpg", "C:\\RCX852C.tmp", "C:\\Users\\Public\\Music\\Sample Music\\Kalimba.mp3", "C:\\Users\\Public\\Music\\Sample Music\\Maid with the Flaxen Hair.mp3", "C:\\Users\\Public\\Music\\Sample Music\\Sleep Away.mp3", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Chrysanthemum.jpg", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Desert.jpg", "C:\\RCX789A.tmp", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Hydrangeas.jpg", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Jellyfish.jpg", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Koala.jpg", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Lighthouse.jpg", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Penguins.jpg", "C:\\RCX85E1.tmp", "C:\\RCX897E.tmp", "C:\\RCX8BBC.tmp", "C:\\Users\\Public\\Pictures\\Sample Pictures\\Tulips.jpg", "C:\\RCX9753.tmp", "C:\\RCX1F91.tmp", "C:\\RCX73C4.tmp", "C:\\RCX79D2.tmp", "C:\\RCX6854.tmp", "C:\\RCX5D9C.tmp", "C:\\RCX74B0.tmp", "C:\\RCX77CF.tmp", "C:\\RCX8E17.tmp", "C:\\RCXA534.tmp", "C:\\RCX3170.tmp", "C:\\RCX4C61.tmp", "C:\\RCX2A3A.tmp", "C:\\RCX2D1A.tmp", "C:\\RCX3577.tmp", "C:\\RCX5D7A.tmp", "C:\\RCX6653.tmp", "C:\\RCX7BF6.tmp", "C:\\RCXA55D.tmp", "C:\\RCX2B18.tmp", "C:\\RCX453A.tmp", "C:\\RCX906C.tmp", "C:\\RCX967A.tmp", "C:\\RCX7B40.tmp", "C:\\RCX7C26.tmp", "C:\\RCX72DE.tmp", "C:\\RCX8007.tmp", "C:\\RCX5659.tmp", "C:\\RCX72CD.tmp", "C:\\RCX4B54.tmp", "C:\\RCX4A1C.tmp", "C:\\RCX1F5B.tmp", "C:\\Windows\\SysWOW64\\shell32.dll", "C:\\RCX433A.tmp", "C:\\RCX73EB.tmp", "C:\\RCX6B4F.tmp", "C:\\RCXE36F.tmp", "C:\\RCX8709.tmp", "C:\\RCX75BC.tmp", "C:\\RCX68FF.tmp", "C:\\RCX99C8.tmp", "C:\\RCX69DD.tmp", "C:\\RCXDE13.tmp", "C:\\RCX5A51.tmp", "C:\\RCX5764.tmp", "C:\\RCX7DD2.tmp", "C:\\RCXA7C7.tmp", "C:\\RCX2745.tmp", "C:\\RCX7464.tmp", "C:\\RCX53FD.tmp", "C:\\RCX50DF.tmp", "C:\\RCXA61F.tmp", "C:\\RCXA4A7.tmp", "C:\\RCXC5AF.tmp", "C:\\RCX80C6.tmp", "C:\\RCX15AF.tmp", "C:\\RCX96B7.tmp", "C:\\RCX9424.tmp", "C:\\RCXA094.tmp", "C:\\RCXE59D.tmp", "C:\\RCX3D21.tmp", "C:\\RCX6D89.tmp", "C:\\RCXE0F0.tmp", "C:\\RCX8F48.tmp", "C:\\RCX21D5.tmp", "C:\\RCXA921.tmp", "C:\\RCX7B37.tmp", "C:\\RCX7622.tmp", "C:\\RCX65B6.tmp", "C:\\RCX6A1F.tmp", "C:\\RCX8C30.tmp", "C:\\RCX9BC8.tmp", "C:\\RCX26E4.tmp"], "mutexes": ["Local\\DirectSound DllMain mutex (0x000004C8)", "CicLoadWinStaWinSta0", "Local\\MSCTF.CtfMonitorInstMutexDefault1", "webpass01", "KingKarton_10", "mutex666", "Local\\ZonesCacheCounterMutex", "Local\\ZonesLockedCacheCounterMutex", "DefaultTabtip-MainUI", "EnM8HM3Y", "sIRC4", "ENGEL_12", "Global\\pc_group=WORKGROUP&ransom_id=fe9bd2dc8e9df0fa", "Global\\3pc6RWOgectGTFqCowxjeGy3XIGPtLwNrsr2zDctYD4hAU5pj4GW7rm8gHrHyTB6", "Local\\RstrMgr3887CAB8-533F-4C85-B0DC-3E5639F8D511", "Local\\RstrMgr-3887CAB8-533F-4C85-B0DC-3E5639F8D511-Session0000", "l0r2", "Global\\CLR_CASOFF_MUTEX", "HGwAYAgg", "AwwgYkIY", "\\xae\\xe5@", "\\xb6\\xe5@", "\\xbe\\xe5@", "\\xc6\\xe5@", "\\xce\\xe5@", "AScYYkcs1", "JkcYwwoQ1", "sfdkjjhgkdsfhgjksd", "MutexPolesskayaGlush*.*\\x90svchost.com\\x90\\xb5\\xe1\\xd9n\\xca\\x12X\\xfd\\xb1\\x15.\\x161t\\xdbN\\xf3\\xc4\\x17et\\x201c\\xee\\xe2h\\xee\\x11\\x201e\\x2039\\xc0`\\x2c6\\xb2\\xf2T\\xf85\\xfd\\x153\\x2018@", "Local\\WinSpl64To32Mutex_1c90a_0_2000", "Global\\wmpproc1998", "Global\\wmpinst1998", "BagarBubba", "8e9ee3cd00000e50", "Global\\{3492473cd35c8bdceed8}", "8e9ee3cd00000120", "8e9ee3cd00000168", "8e9ee3cd00000190", "8e9ee3cd000001a4", "8e9ee3cd000001d0", "8e9ee3cd000001f8", "8e9ee3cd00000200", "8e9ee3cd00000210", "8e9ee3cd0000027c", "8e9ee3cd000002cc", "8e9ee3cd00000328", "8e9ee3cd00000360", "8e9ee3cd0000037c", "8e9ee3cd00000398", "8e9ee3cd00000198", "8e9ee3cd0000040c", "8e9ee3cd00000438", "8e9ee3cd000004a0", "8e9ee3cd000006f8", "8e9ee3cd00000764", "8e9ee3cd00000778", "8e9ee3cd000007b4", "8e9ee3cd000007dc", "8e9ee3cd0000060c", "8e9ee3cd00000794", "8e9ee3cd000006ac", "8e9ee3cd00000848", "8e9ee3cd00000898", "8e9ee3cd000008e8", "8e9ee3cd0000095c", "8e9ee3cd000009bc", "8e9ee3cd000009c4", "8e9ee3cd000009e0", "8e9ee3cd00000a2c", "8e9ee3cd00000aac", "8e9ee3cd000009a8", "8e9ee3cd00000324", "8e9ee3cd00000bac", "8e9ee3cd00000370", "8e9ee3cd0000093c", "8e9ee3cd00000bd4", "8e9ee3cd000005b4", "8e9ee3cd00000d60", "8e9ee3cd0000080c", "8e9ee3cd00000f74", "8e9ee3cd00000870", "8e9ee3cd00000f4c", "8e9ee3cd00000f64", "8e9ee3cd00000fe4", "8e9ee3cd00000ba8", "8e9ee3cd00000810", "Local\\__DDrawExclMode__", "Local\\__DDrawCheckExclMode__", "J", "S-1-5-21-2897422-2512554278515", "Global\\C::Users:John:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex", "Global\\C::Users:John:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer", "Global\\C::Users:John:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer", "Global\\C::Users:John:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer", "Global\\C::Users:John:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer", "Global\\C::Users:John:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer", "Global\\C::Users:John:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit", "Global\\C::Users:John:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwReaderRefs", "746N6S3R-5ZJDE6I", "9-8Q15BE02468WZz", "zwj19940929.f3322.org:2017:NetRoot", "dsi382ud", "ainuhfoekc", "byrqdvatgg", "ctsxexvnkh", "cftsahrawy", "ckrmkvajuj", "dmpssgxdic", "dofyahftwh", "duharqaurb", "esghgacpjb", "fscexavlyr", "guvxxsswya", "gddblxsxae", "gswaffnhhf", "hmbfyubrup", "ccktbkeiyh", "ymwgahpejw", "ynellsagdl", "ywftnnyvnh", "yumtdaildm", "ymgnfrkbdv", "ynlfppbhyn", "yolkgsgjar", "aglmanmjub", "yvohubnxxx", "ystcmsnjsy", "ypnxoqnskq", "awontbcwuh", "arlhrbpekc", "appejmjgal", "aovssgiyfr", "avnndagghw", "axedubhxpq", "aumnoylqds", "akfxxvopdf", "aoobernbce", "anpdoabmll", "gqiqeohntf", "aspniwuxdb", "gvddwjfitc", "avmkpxpfld", "bwbyolxgqp", "yolbrklndp", "bgmsagsufe", "bclklgcuda", "asntdfpbyk", "avxhviturh", "bflndgxeac", "yfeuksgorg", "mjxhgnm20180313-1_MUTEX", "Global\\D0E858DF-985E-4907-B7FB-8D732C3FC3B8}", "uxJLpe1m", "smss.exeM_288_", "csrss.exeM_356_", "wininit.exeM_396_", "csrss.exeM_420_", "winlogon.exeM_464_", "services.exeM_504_", "lsass.exeM_512_", "lsm.exeM_524_", "svchost.exeM_632_", "svchost.exeM_712_", "svchost.exeM_808_", "svchost.exeM_840_", "svchost.exeM_868_", "svchost.exeM_916_", "svchost.exeM_348_", "spoolsv.exeM_1032_", "svchost.exeM_1060_", "svchost.exeM_1152_", "taskeng.exeM_1856_", "dwm.exeM_1912_", "googleupdate.exeM_1944_", "taskhost.exeM_1976_", "explorer.exeM_1108_", "pyw.exeM_220_", "wmiprvse.exeM_492_", "svchost.exeM_2444_", "searchindexer.exeM_2620_", "sppsvc.exeM_2368_", "svchost.exeM_2420_", "wmpnetwk.exeM_1144_", "wmiprvse.exeM_1284_", "searchfilterhost.exeM_2132_", "searchprotocolhost.exeM_2196_", "taskhost.exeM_3036_", "02fc28527a3a9de5f737beb4.exeM_1572_", "compattelrunner.exeM_1884_", "conhost.exeM_2544_", "compattelrunner.exeM_1780_", "Ap1mutx7", "compattelrunner.exeM_2464_", "devicedisplayobjectprovider.exeM_2044_", "svchost.exeM_804_", "searchprotocolhost.exeM_308_", "searchfilterhost.exeM_2980_", "googleupdate.exeM_2412_", "Local\\Shell.CMruPidlList", "Global\\C::Users:John:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!010894", "qdsqc20190523-1_MUTEX", "sfdkjjhgkdsfhgjkjjsd", "!IECompat!Mutex", "Cmj6MD4Nmm", "8tUwhLYlyz", "kISPcBAtbM", "nQb4TkgOwr", "cj6IxhfRGX", "1tVNQZplFJ", "eEswEAAYkS", "RFBLXS0PkG", "bIz65OPXoJ", "Local\\WERReportingForProcess1344", "Global\\\\x5210\\x444", "BA5615A8B0EA6F1CF50ADAAD", "qqpass7", "ctrl.mtx.rbt", "I-Worm.PlutonX", "Global\\\\x51b0\\x45e", "Local\\WERReportingForProcess2596", "Global\\\\x5210\\x43b", "errorbf007", "LSS001", "KK_11", "pubG", "vV3klyV1Pq", "Fg73XWvxvW", "uPjtTAA1iD", "LwLs246ddJ", "9VmlS6itDm", "us50PQoivq", "7EtjeaHl9q", "HZmq7pciJE", "qf3gQUdPEG", "qazwsxedc", "ECD5C793", "Windows svchost", "Global\\.net clr networking", "u3xPWxkk", "AMResourceMutex3", "LDLLMAIN", "5E0::DAC0E73EEB", "5E0:DAF", "Local\\WERReportingForProcess3400", "Global\\\\x5210\\x1b", "jdebuxptkgueswnrjkefcvy", "ZMn89MuZ", "Pro3", "LSS37", "LSSUPD", "Global\\AmInst__Runing_1", "XTREMEUPDATE", "GcHhnx", "ZEEPP93d", "searchprotocolhost.exeM_2752_", "0a5d51a21e836a0df300ad03.exeM_2356_", "taskhost.exeM_2240_", "compattelrunner.exeM_2964_", "conhost.exeM_2124_", "compattelrunner.exeM_2224_", "compattelrunner.exeM_1688_", "devicedisplayobjectprovider.exeM_1328_", "svchost.exeM_3060_", "searchprotocolhost.exeM_2044_", "searchfilterhost.exeM_2168_", "googleupdate.exeM_1748_", "googleupdate.exeM_2220_", "05387337392A20730D545F6985EB80691B51F7690E5FFF65803ABB6E015474081D15482073A5C76715", "fa34", "A44::DAC0E73EEB", "A44:DAF", "Local\\MSIMGSIZECacheMutex", "pomdfghrt", "TInfoHttpFrm", "bthpanapi", "RV_MUTEX-GaKuSAtYBxGgZ", "ucsvc", "{d23d29ad-c0ec-4092-85bd-cbc7e760cedf}", "Local\\WERReportingForProcess2700", "Global\\\\x5210\\x420", "{2337FE2F-1E3B-C74C-9E7A-274C61E65EE1}", "{23380426-1E3B-C74C-9E7A-274C61E65EE1}", "LSS35", "Local\\WERReportingForProcess188", "Global\\\\x5210\\x427", "Semaphore_157862", "StikyNot_yakuza", "MDMAppInstaller", "Remcos_Mutex_Inj", "Remcos-S1KNPZ", "Startup_shellcode_006", "8e9ee3cd00000bb4", "8e9ee3cd00000414", "8e9ee3cd00000164", "8e9ee3cd0000018c", "8e9ee3cd000001c8", "8e9ee3cd0000020c", "8e9ee3cd0000026c", "8e9ee3cd000002c0", "8e9ee3cd00000314", "8e9ee3cd00000344", "8e9ee3cd00000364", "8e9ee3cd00000408", "8e9ee3cd00000424", "8e9ee3cd00000484", "8e9ee3cd00000714", "8e9ee3cd0000072c", "8e9ee3cd0000077c", "8e9ee3cd00000788", "8e9ee3cd00000288", "8e9ee3cd000007e8", "8e9ee3cd000003d0", "8e9ee3cd000006c4", "8e9ee3cd000008b0", "8e9ee3cd000008f4", "8e9ee3cd00000940", "8e9ee3cd00000a24", "8e9ee3cd00000a70", "8e9ee3cd00000a98", "8e9ee3cd00000ae0", "8e9ee3cd00000af4", "8e9ee3cd00000b5c", "8e9ee3cd00000904", "8e9ee3cd0000082c", "8e9ee3cd00000a1c", "8e9ee3cd00000480", "8e9ee3cd00000c98", "8e9ee3cd00000e74", "8e9ee3cd00000e88", "8e9ee3cd00000eb4", "F5D6B36B", "424934e1df2943dfbc1679b7916a81d5", "Local\\TeamViewer_LogMutex", "345rdxcvgt567yhjm", "pctaubwpctaubwpctaubwpctau", "4cad00898e83b5ca86cd4000a82f9e90", "Local\\SHResolveLibrary:C:/Users/John/AppData/Roaming/Microsoft/Windows/Libraries/Documents.library-ms", "8e9ee3cd00000d40", "8e9ee3cd00000e24", "8e9ee3cd00000208", "8e9ee3cd00000268", "8e9ee3cd000002bc", "8e9ee3cd00000318", "8e9ee3cd00000340", "8e9ee3cd00000378", "8e9ee3cd00000174", "8e9ee3cd00000404", "8e9ee3cd00000420", "8e9ee3cd00000474", "8e9ee3cd000006f4", "8e9ee3cd00000720", "8e9ee3cd00000744", "8e9ee3cd00000770", "8e9ee3cd000004c4", "8e9ee3cd00000688", "8e9ee3cd000000dc", "8e9ee3cd00000840", "8e9ee3cd00000888", "8e9ee3cd000008d0", "8e9ee3cd00000958", "8e9ee3cd000009b4", "8e9ee3cd00000a8c", "8e9ee3cd00000a88", "8e9ee3cd00000af8", "8e9ee3cd00000bc8", "8e9ee3cd00000ac8", "8e9ee3cd00000948", "8e9ee3cd000006f0", "8e9ee3cd00000b9c", "8e9ee3cd00000dec", "8e9ee3cd00000fb8", "8e9ee3cd00000fcc", "8e9ee3cd00000ffc", "Local\\WERReportingForProcess3424", "Global\\\\x5210\\x426", "Global\\71620C25a", "Global\\{bad8dcfd-8695-4086-9493-aaf04f41465a}", "Nateoffsadk", "cjZ5MXgw", "Global\\\\x51b0\\x478", "Remcos-00GA1C", "Local\\WERReportingForProcess2356", "Global\\\\x5210\\x431", "+/vn+r34Bfm9AACf", "sivulnankesb", "624::DAC0E73EEB", "624:DAF", "KeYwoEIk", "PkIwEgss", "\\xf5)@", "\\xfd)@", "\\x05*@", "\r*@", "\\x15*@", "Worm.P2P.Google", "7321baaff10c1ea75810eb114d0daa00", "uPPZ8x8W", "MutexNPA_UnitVersioning_2356", "H3ZukaYE", "Serpiei", "Wpgt55AE", "Global\\{3b9d060d-bbe7-44ae-8057-2329f7f8d9fc}", "Global\\\\x5210\\x1c5", "Global\\\\x69b0\\x1c9", "AHK Keybd", "MUTEX394039_4830023", "Local\\DirectSound DllMain mutex (0x00000DFC)", "Global\\{bd59231e-97d1-4fc0-a975-80c3fed498b7}", "Local\\WinSpl64To32Mutex_1ef74_0_2000", "8e9ee3cd00000be8", "8e9ee3cd000001a8", "8e9ee3cd000001d4", "8e9ee3cd00000214", "8e9ee3cd00000270", "8e9ee3cd00000348", "8e9ee3cd000003a4", "8e9ee3cd00000478", "8e9ee3cd000007a4", "8e9ee3cd000004d0", "8e9ee3cd00000750", "8e9ee3cd00000a20", "8e9ee3cd00000a5c", "8e9ee3cd00000560", "8e9ee3cd000009d0", "8e9ee3cd00000b98", "8e9ee3cd00000ba0", "8e9ee3cd000005b8", "8e9ee3cd00000b04", "8e9ee3cd000008fc", "8e9ee3cd0000068c", "8e9ee3cd00000830", "8e9ee3cd00000988", "S-1-5-21-2897422-1928554278515", "csrss.exeM_360_", "wininit.exeM_400_", "csrss.exeM_424_", "winlogon.exeM_460_", "services.exeM_508_", "lsass.exeM_516_", "lsm.exeM_528_", "svchost.exeM_628_", "svchost.exeM_708_", "svchost.exeM_844_", "svchost.exeM_872_", "svchost.exeM_904_", "svchost.exeM_380_", "svchost.exeM_1136_", "taskhost.exeM_1792_", "taskeng.exeM_1816_", "dwm.exeM_1884_", "explorer.exeM_1960_", "googleupdate.exeM_1080_", "googleupdate.exeM_1640_", "svchost.exeM_1588_", "pyw.exeM_1280_", "wmiprvse.exeM_2120_", "teams.exeM_2196_", "teams.exeM_2376_", "teams.exeM_2452_", "teams.exeM_2528_", "teams.exeM_2644_", "teams.exeM_2708_", "searchindexer.exeM_2824_", "searchfilterhost.exeM_2912_", "searchprotocolhost.exeM_2952_", "googleupdate.exeM_2276_", "teams.exeM_3044_", "sppsvc.exeM_1132_", "svchost.exeM_2900_", "wmpnetwk.exeM_2432_", "wmiprvse.exeM_2608_", "02fc28527a3a9de5f737beb4.exeM_3400_", "taskhost.exeM_2968_", "compattelrunner.exeM_3064_", "conhost.exeM_3828_", "searchprotocolhost.exeM_3840_", "searchfilterhost.exeM_2924_", "compattelrunner.exeM_4092_", "wmiadap.exeM_3420_", "srWeUnPjZF", "k28vBKwPP4", "5qVx4ft4Dp", "u6n1ihL7Zi", "P2HNmPNIDL", "vxr49MPX21", "uzmE7UxXj0", "SLDfUPSXRz", "vijF8vJLCw", "UzU5czDwjl", "aQrhdxQyZa", "qAPOKbILKx", "RbI1wzRQPb", "QcPztreLob", "xIRPOfrVRr", "EQT3hPt779", "YGDQvYtaus", "lnPsH3Iyra", "RasPbFile", "345432-123rvr4", "8123456734827_v3453425", "__wqrsdwetrwetlkgsdv", "\\x081@", "\\x101@", "\\x181@", " 1@", "DCoIEEEw1", "bMoYgwEU1", "\\xe80@", "\\xf00@", "\\xf80@", "\\xc1)@", "\\xc9)@", "\\xd1)@", "\\xd9)@", "\\xe1)@", "SDKSetupExeE9ACDB27-0244-8547-4AAA-64F33CD7E0AB", "SetupWatson_Mutex_Name", "CQ@", "KQ@", "SQ@", "[Q@", "cQ@"]}