魔盾安全分析报告 URL信息 特征 运行截图 网络分析 访问主机记录
Transcrição
魔盾安全分析报告 分析类型 开始时间 结束时间 持续时间 分析引擎版本 URL 2016-05-11 13:20:34 2016-05-11 13:23:05 151 秒 1.4-Maldun 虚拟机机器名 标签 虚拟机管理 开机时间 关机时间 win7-sp1-x64 win7-sp1-x64 KVM 2016-05-11 13:20:34 2016-05-11 13:23:05 魔盾分数 2.0 正常的 URL信息 URL http://www.18183.com/yxzjol/201604/566007.html?soucre=bdald VirusTotal VirusTotal无域名信息 特征 尝试更改浏览器安全设置 运行截图 网络分析 访问主机记录 直接访问 IP地址 国家名 是 74.125.23.113 United States 是 74.125.23.100 United States 否 68.232.45.201 United States 否 42.156.140.209 China 否 36.42.32.63 China 否 222.73.134.114 China 否 222.73.134.113 China 否 220.181.7.190 China 否 198.41.215.186 United States 否 180.76.187.26 China 否 180.76.139.200 China 否 140.205.155.34 China 否 140.205.153.72 China 否 134.170.50.247 United States 否 122.228.237.175 China 否 122.228.22.171 China 否 117.23.51.73 China 域名解析 域名 响应 dns.msftncsi.com A 131.107.255.255 www.18183.com CNAME site86.18183.com A 180.76.139.200 js.18183.duoku.com CNAME 1st.dlmix.ourdvs.com A 122.228.237.175 CNAME js.18183.duoku.com.wscdns.com A 117.23.2.80 A 122.228.22.171 A 36.42.32.63 A 122.228.233.195 A 183.136.208.39 A 122.228.22.179 A 117.23.51.73 urs.microsoft.com CNAME urs.microsoft.com.nsatc.net A 134.170.50.247 dns.msftncsi.com AAAA fd3e:4f5a:5b81::1 ocsp.msocsp.com A 198.41.214.185 CNAME hostedocsp.globalsign.com A 198.41.214.186 A 198.41.214.187 A 198.41.215.183 A 198.41.215.182 A 198.41.215.185 A 198.41.214.183 A 198.41.215.184 A 198.41.215.186 A 198.41.214.184 gg.18183.com CNAME site92.18183.com A 180.76.187.26 img1.18183.duoku.com CNAME img1.18183.duoku.com.wscdns.com img.18183.duoku.com CNAME img.18183.duoku.com.wscdns.com img3.18183.duoku.com CNAME img3.18183.duoku.com.wscdns.com hm.baidu.com CNAME hm.e.shifen.com A 220.181.7.190 w.cnzz.com A 222.73.134.113 A 222.73.134.114 CNAME all.cnzz.com.danuoyi.tbcache.com CNAME c.cnzz.com mscrl.microsoft.com CNAME certrevoc.vo.msecnd.net CNAME cs3.wpc.v0cdn.net A 68.232.45.201 hqs1.cnzz.com CNAME q.gds.cnzz.com CNAME q.cnzz.com CNAME q3.cnzz.com A 42.156.140.209 c.cnzz.com hqs9.cnzz.com CNAME q7.cnzz.com q14.cnzz.com CNAME q4.cnzz.com cnzz.mmstat.com CNAME log.mmstat.com A 140.205.153.72 CNAME log.gds.mmstat.com pcookie.cnzz.com CNAME pcookie.taobao.com A 140.205.155.34 CNAME pcookie.gds.taobao.com TCP连接 IP地址 端口 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 117.23.51.73 80 122.228.22.171 80 122.228.22.171 80 122.228.22.171 80 122.228.22.171 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 122.228.237.175 80 134.170.50.247 443 134.170.50.247 443 134.170.50.247 443 134.170.50.247 443 140.205.153.72 80 140.205.155.34 80 180.76.139.200 80 180.76.139.200 80 180.76.139.200 80 180.76.139.200 80 180.76.187.26 80 198.41.215.186 80 198.41.215.186 80 220.181.7.190 80 222.73.134.113 80 222.73.134.114 80 36.42.32.63 80 42.156.140.209 80 42.156.140.209 80 42.156.140.209 80 68.232.45.201 80 UDP连接 IP地址 端口 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.1 53 192.168.122.255 138 224.0.0.252 5355 239.255.255.250 1900 52.169.179.91 HTTP请求 URL http://www.18183.com/yxzjol/201604/566007.html?soucre=bdald 123 http://js.18183.duoku.com/common/css/base.css http://js.18183.duoku.com/common/js/jquery/jquery-1.8.3.min.js http://js.18183.duoku.com/pc/yxzj/css/arc.css http://js.18183.duoku.com/uploads/pc/yxzjol/bg_body.jpg http://js.18183.duoku.com/common/js/top_toolbar.js?v1.2 http://www.18183.com/templets/all/top_toolbar/images/3jj.gif http://js.18183.duoku.com/uploads/common/appdwn.png http://js.18183.duoku.com/common/js/maruko.js http://www.18183.com/templets/all/top_toolbar/images/appdwn.png http://js.18183.duoku.com/uploads/common/ico-toptoolbar.png http://gg.18183.com/js.php?pid=2 http://gg.18183.com/base.php?pid=2&time=1462943934&codeid=1366163266 http://www.18183.com/templets/index2014/images/bg_close.png http://gg.18183.com/ping.gif?t?=1?t?=2,53,1660,1321|2,9,5308,4088|2,222,0,0|2,7,5312,4092|2,5,563,210|2,57,0,0|2,162,5258,4002|2,10,4509,3453|2,6,5087,3913|2,208,0,0|2,198,3649,2748|2,12,1984,2654|2,200,0,0 =www.18183.com?t?=http%3A%2F%2Fwww.18183.com%2Fyxzjol%2F201604%2F566007.html%3Fsoucre%3Dbdald?t?=?t?=?t?= http://www.18183.com/uploads/160224/36-1602241G24W19.jpg http://js.18183.duoku.com/uploads/pc/index2016/all_tl_bg.png http://js.18183.duoku.com/uploads/pc/index2016/X.png http://img1.18183.duoku.com/uploads/2016/05/14628768855622.jpg http://img1.18183.duoku.com/uploads/2016/02/14544096519373.jpg http://js.18183.duoku.com/uploads/pc/yxzjol/cov_v.png http://js.18183.duoku.com/uploads/pc/yxzjol/cov_70.png http://js.18183.duoku.com/uploads/pc/yxzjol/bg_header_xz.png http://js.18183.duoku.com/uploads/pc/yxzjol/bg_header_02.jpg http://img.18183.duoku.com/uploads/151120/36-151120195921355.jpg http://img.18183.duoku.com/uploads/allimg/160506/36-1605061121090-L.jpg http://img.18183.duoku.com/uploads/allimg/160427/36-16042GR033.jpg http://img.18183.duoku.com/uploads/151120/36-15112020242M52.jpg http://img.18183.duoku.com/uploads/151120/36-151120194JVJ.jpg http://img.18183.duoku.com/uploads/160405/70-1604051055461D.png http://js.18183.duoku.com/uploads/pc/yxzjol/bg_info_line_01.png http://js.18183.duoku.com/uploads/pc/yxzjol/ico_search.png http://img1.18183.duoku.com/uploads/2016/05/14629365731420.jpg http://js.18183.duoku.com/uploads/pc/yxzjol/bg_info_tab.png http://img.18183.duoku.com/uploads/151120/36-151120195233R1.jpg http://img.18183.duoku.com/uploads/151120/36-15112020062D41.jpg http://img.18183.duoku.com/uploads/allimg/160114/36-160114113125.jpg http://img1.18183.duoku.com/uploads/2015/10/14448186091968.jpg http://js.18183.duoku.com/common/js/bottom_toolbar.js http://js.18183.duoku.com/uploads/pc/yxzjol/bg_info_hero_01.png http://js.18183.duoku.com/uploads/pc/yxzjol/bg_bzrd_links.png http://js.18183.duoku.com/uploads/pc/yxzjol/cov_60.png http://js.18183.duoku.com/uploads/pc/yxzjol/ico_arc.png http://js.18183.duoku.com/uploads/pc/yxzjol/blank.gif http://img.18183.duoku.com/uploads/allimg/151130/36-1511301159450-L.jpg http://img.18183.duoku.com/uploads/allimg/151210/36-151210163I00-L.jpg http://img3.18183.duoku.com/assets/games/1445842259_324.jpg http://img.18183.duoku.com/uploads/allimg/160413/36-160413111H5.jpg http://img.18183.duoku.com/uploads/151120/36-15112019493X13.jpg http://img.18183.duoku.com/uploads/allimg/160413/36-160413111950.jpg http://img.18183.duoku.com/uploads/allimg/151210/36-1512101636260-L.jpg http://js.18183.duoku.com/uploads/pc/yxzjol/bg_header_01.jpg http://img.18183.duoku.com/uploads/allimg/151121/36-1511211552160-L.jpg http://js.18183.duoku.com/uploads/pc/index2016/icons.png http://js.18183.duoku.com/uploads/pc/yxzjol/bg_header_bbs.png http://js.18183.duoku.com/uploads/pc/yxzjol/cov_50.png http://img.18183.duoku.com/uploads/151120/36-151120192621D6.jpg http://img.18183.duoku.com/uploads/151120/36-15112019202XQ.jpg http://img.18183.duoku.com/uploads/common/img/gt.gif http://img.18183.duoku.com/uploads/151120/36-151120194430346.jpg http://img.18183.duoku.com/uploads/151120/36-15112020104Q94.jpg http://img.18183.duoku.com/uploads/allimg/151215/36-1512151332240-L.jpg http://img.18183.duoku.com/uploads/151120/36-151120194210628.jpg http://img.18183.duoku.com/uploads/160510/70-1605101IZ1C2.jpg http://img.18183.duoku.com/uploads/151120/36-151120200433543.jpg http://img.18183.duoku.com/uploads/151120/36-15112019242YD.jpg http://img.18183.duoku.com/uploads/160509/70-1605091Q034W6.jpg http://img.18183.duoku.com/uploads/160405/70-16040510545QP.png http://img.18183.duoku.com/uploads/151120/36-15112019553I60.jpg http://img.18183.duoku.com/uploads/151120/36-151120195156428.jpg http://img.18183.duoku.com/uploads/allimg/160413/36-160413111951.jpg http://img.18183.duoku.com/uploads/allimg/151120/36-1511202033120-L.jpg http://img.18183.duoku.com/uploads/allimg/160413/36-160413111950-50.jpg http://img.18183.duoku.com/uploads/151120/36-151120192K5F6.jpg http://img.18183.duoku.com/uploads/151207/36-15120G55434631.jpg http://img.18183.duoku.com/uploads/151120/36-1511201ZI43Q.jpg http://img.18183.duoku.com/uploads/151120/36-151120201334B1.jpg http://img.18183.duoku.com/uploads/151120/36-15112020143OT.jpg http://ocsp.msocsp.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQmECJms4f7i5EbxtN7NbzQCBwAdAQUUa8kJpz0aCJXgCYrO0ZiFXsezKUCE1oAAL7TPPdnS2J1DUwAAQAAvtM%3D http://img.18183.duoku.com/uploads/151120/36-151120192120620.jpg http://img.18183.duoku.com/uploads/151120/36-15112020032R46.jpg http://img.18183.duoku.com/uploads/151120/36-151120195T5292.jpg http://img.18183.duoku.com/uploads/151120/36-151120200029251.jpg http://img.18183.duoku.com/uploads/160509/70-1605091QI23D.jpg http://img.18183.duoku.com/uploads/151120/36-151120201150Z9.jpg http://img.18183.duoku.com/uploads/160510/36-160510155JK05.jpg http://img.18183.duoku.com/uploads/151120/36-15112020021X28.jpg http://img.18183.duoku.com/uploads/allimg/151124/36-151124143I80-L.jpg http://img.18183.duoku.com/uploads/151120/36-151120202200192.jpg http://img.18183.duoku.com/uploads/151120/36-151120200ST33.jpg http://img.18183.duoku.com/uploads/160113/36-1601131916294W.jpg http://img.18183.duoku.com/uploads/151120/36-151120192930A7.jpg http://img.18183.duoku.com/uploads/160509/70-1605091Q35cW.jpg http://img.18183.duoku.com/uploads/allimg/160413/36-160413112314.jpg http://img.18183.duoku.com/uploads/151120/36-15112019112M25.jpg http://ocsp.msocsp.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQmECJms4f7i5EbxtN7NbzQCBwAdAQUUa8kJpz0aCJXgCYrO0ZiFXsezKUCE1oAAL7TPPdnS2J1DUwAAQAAvtM%3D http://mscrl.microsoft.com/pki/mscorp/crl/msitwww2.crl http://hm.baidu.com/h.js?3782151c2b39bc6837a4913c89752cbc http://w.cnzz.com/c.php?id=30070880 http://hm.baidu.com/hm.gif?cc=0&ck=1&cl=24-bit&ds=800x600&et=0&fl=20.0&ja=1&ln=zhcn&lo=0&nv=1&rnd=1230894189&si=3782151c2b39bc6837a4913c89752cbc&st=1&v=1.1.26&lv=1&tt=%E7%8E%8B%E8%80%85%E8%8D%A3%E8%80%80S3%E8%B5%9B%E5%AD%A3%E8%8B%B1%E9%9B%84% http://c.cnzz.com/core.php?web_id=30070880&t=q http://js.18183.duoku.com/pc/yxzj/js/main.js http://hqs1.cnzz.com/stat.htm?id=30070880&r=&lg=zh-cn&ntime=none&cnzz_eid=1476008741-1462938769&showp=800x600&t=%E7%8E%8B%E8%80%85%E8%8D%A3%E8%80%80S3%E8%B5%9B%E5%AD%A3%E8%8B%B1%E9%9B%84%E6%A2%AF%E9%98%9F%E6%8E%92%E8%A1%8C%E6%A6%9C_18183%E7%8E%8B http://w.cnzz.com/c.php?id=30081741 http://c.cnzz.com/core.php?web_id=30081741&t=q http://w.cnzz.com/c.php?id=1255763238 http://hqs9.cnzz.com/stat.htm?id=30081741&r=&lg=zh-cn&ntime=none&cnzz_eid=670092629-1462942773- &showp=800x600&t=%E7%8E%8B%E8%80%85%E8%8D%A3%E8%80%80S3%E8%B5%9B%E5%AD%A3%E8%8B%B1%E9%9B%84%E6%A2%AF%E9%98%9F%E6%8E%92%E8%A1%8C%E6%A6%9C_18183%E7%8E%8B http://c.cnzz.com/core.php?web_id=1255763238&t=q http://q14.cnzz.com/stat.htm?id=1255763238&r=&lg=zh-cn&ntime=none&cnzz_eid=1150070595-1462940960&showp=800x600&t=%E7%8E%8B%E8%80%85%E8%8D%A3%E8%80%80S3%E8%B5%9B%E5%AD%A3%E8%8B%B1%E9%9B%84%E6%A2%AF%E9%98%9F%E6%8E%92%E8%A1%8C%E6%A6%9C_18183%E7%8E%8B http://www.18183.com/favicon.ico http://cnzz.mmstat.com/9.gif?abc=1&rnd=457268234 http://pcookie.cnzz.com/app.gif?&cna=x10rDxSReXcCAXTjgpnYmdm7 http://js.18183.duoku.com/uploads/pc/yxzjol/bg_header_03.jpg http://js.18183.duoku.com/uploads/pc/yxzjol/bg_info_hero_02.png http://www.18183.com/templets/all/top_toolbar/images/d3j.gif 投放文件 gt[1].gif 文件名 相关文件 gt[1].gif C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\gt[1].gif 文件大小 3660 bytes 文件类型 GIF image data, version 89a, 50 x 50 MD5 e5ad4df537b8e3838c3b20e3150ec418 SHA1 6e6abfe827a902af626fea4df0073c8b329e6da5 SHA256 40a09a8ba1a88c2bfb4d224d4c4edaf99a6f43cf6681d98fb73d4f7e885c52ae SHA512 bd39ea6880cdf6e632ea84ce65e907265b73eb478a6a1c279af2c724e1fc7fa74209ab9ab24a58968acbd52997b25fb9b872d44aa862babb4bd181c70d0d5c2f Ssdeep 96:3KR3RCZSCuSZZtJHd2sihzoS77/+TOGr/t+2:6j8d27hn3cOGr/tT Yara 无匹配 VirusTotal 搜索相关分析 js[1].php 文件名 js[1].php 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\js[1].php 文件大小 192 bytes 文件类型 HTML document, ASCII text, with CRLF line terminators MD5 6b128b2e21b2712234176b02f9a80266 SHA1 97d49b34f9ca24d0e400a5a477dc138344b7bd7a SHA256 621eb034ad2859dcb9e12796d73e7cd8949ff75bf2756511242bd93eb1c27869 SHA512 ddd4252f068d9693aceb23f4c4578d053689902379bfc4b0f78efab7c915de863e136fcd2cf5f1170a198c76e886a57f8e85a06e7c7bff9341f4733cf04bce65 Ssdeep 3:jp+FHWpE+HvwZCLUdBIcuVHeAYn2bcRbWljB9nSladQ9LRmcpZBMkAqRAdu6/GYk:g2q6w8gd8VHe9n2cEd9/Q9L/pZVAqJmk Yara 无匹配 VirusTotal 搜索相关分析 36-160413111H5[1].jpg 文件名 36-160413111H5[1].jpg 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-160413111H5[1].jpg 文件大小 6245 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 9b1c831f387d5ca873df38dc6b5b9914 SHA1 8d01aed0555ee0618968ae6facb2c599c2191981 SHA256 37d6c0794a5d186644e7c215d81752909d875fe41cf53dcec2531c038cc0e34e SHA512 72530a55ac4282c130e2c4fef9ab8bcd44da2329aa03e5d0749fb39994baec8b9611835c28e2274e65804c89d5490db63b869a90a37e2897b22f965856a3c183 Ssdeep 192:AiSPpOLhFtdKzN/blIN31BXMd4aupWXv/:gOLhF+hSgdCWn Yara 无匹配 VirusTotal 搜索相关分析 core[1].php 文件名 core[1].php 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\core[1].php 文件大小 2616 bytes 文件类型 HTML document, ASCII text, with very long lines, with CRLF line terminators MD5 d690e9b00b41c86dc9db5018714022c9 SHA1 42a57728d57aaad62ff3b89357f74f2ead2d6e82 SHA256 7c4f3ef3ee9e635a2acad322d7bdd4c8bb3bea2efab6a99f2d57109a4f3217f9 SHA512 e2f7ebab37fc0dc672878b3b1a3a80aa4ad0f63974f2f71bda553fcda75439c442fae510553b6b9cf869b34ae70ffc30d32a23d96350e65b6377158c77f6228e Ssdeep 48:TAuaMl7D+pyVjkTBi2k+gXGfrgo+ufW+Emz7jUprCntFar5T25FNSLiiFs5vE:Tl+s8BEWtW+Em5/G25FaJN Yara 无匹配 VirusTotal 搜索相关分析 36-160510155JK05[1].jpg 文件名 36-160510155JK05[1].jpg 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-160510155JK05[1].jpg 文件大小 39222 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 bef0fafd1ce04a61fc0567347e7f2dd3 SHA1 6114310e079d0fd55faea34588a554a31d4b55d5 SHA256 2f4d6282ea87c38a1e416ef1bb462354b228633d27fa203a3741cde025010da8 SHA512 56c26c6220480db134fd434bfa1651736a44e4c6a801d56939706c03feb2b5d393328ae8edbac982266fd041780caa77b9765220cc6cd7058c286f1c110502f9 Ssdeep 768:91aHPUXTvwjNXumoKTW8sIS5b59ClAM4+skG0RX+cCKL05FTP8bXi/5ClcUbLVz:SvAIxTWEirlM4CG01+cC6rSTU1z Yara 无匹配 VirusTotal 搜索相关分析 bg_header_bbs[1].png 文件名 相关文件 bg_header_bbs[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\bg_header_bbs[1].png 文件大小 21266 bytes 文件类型 PNG image data, 211 x 97, 8-bit/color RGBA, non-interlaced MD5 926686cd43ad5045ebd2f6bcc7dbdbf1 SHA1 ed113fa17414e150450006378b410834f6740698 SHA256 88b94998b02c4e12345adee02662a393f69bc1a1f5bfb2a90877279777f1a2eb SHA512 36d177a47acbcc9ee06722cc460a4d11a9155fb4bbacefb3b02fe263e623a68749d5d190f1ffe6dc45d99509b4fd80a6694a4b829dbdf67abbf8e06795187223 Ssdeep 384:j3n77vFjdrZrWn4XczRtHwCxZBtXdPYL5GgytdHkaeiYHcHsUjZZgIAREFUjF5f0:j33jrZrXXVCxZrFYL5GgytdHQP8HR3gm Yara 无匹配 VirusTotal 搜索相关分析 stat[1].gif 文件名 相关文件 stat[1].gif C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\stat[1].gif C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\stat[1].gif C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\stat[1].gif 文件大小 43 bytes 文件类型 GIF image data, version 89a, 1 x 1 MD5 325472601571f31e1bf00674c368d335 SHA1 2daeaa8b5f19f0bc209d976c02bd6acb51b00b0a SHA256 b1442e85b03bdcaf66dc58c7abb98745dd2687d86350be9a298a1d9382ac849b SHA512 717ea0ff7f3f624c268eccb244e24ec1305ab21557abb3d6f1a7e183ff68a2d28f13d1d2af926c9ef6d1fb16dd8cbe34cd98cacf79091dddc7874dcee21ecfdc Ssdeep 3:CUkwltxlHh/:P/ Yara 无匹配 VirusTotal 搜索相关分析 36-151120195T5292[1].jpg 文件名 相关文件 36-151120195T5292[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-151120195T5292[1].jpg 文件大小 4510 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 bcd6f63849520966d5ec42b4d8906e9c SHA1 2b6188c5c2c62e14318713637560a44d549cdcd0 SHA256 dd46117e67f3b991f3d4bfcb25446919ad38aaefb4e9e51405437daae9b4953f SHA512 06b42b0ff2ddc4e5c3ab9632903e3196f9fb4d52f4cb149d742b5fb7573d66b698ad3a4ccd94e0fcb5cbcd7b8c1ee8a16f78262cac213aaf1303658f1d530736 Ssdeep 96:DE0Neka3xl9SKX97GInayovQ02nBYztzkeFEObyixmxGw6:40Neka37959SyoEnBKpkl69 Yara 无匹配 VirusTotal 搜索相关分析 h[1].js 文件名 相关文件 h[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\h[1].js 文件大小 23238 bytes 文件类型 ASCII text, with very long lines MD5 57352f07b6a40bdc0e7f4105d9e69452 SHA1 a13a4fa3f48d48e7f90a96fce910acb845bac6ae SHA256 be7b1c29bcb50f145ef9addc6b65bf3723344d5d94f906e7f5b7775b83190bf6 SHA512 bc855e37a1d7905bb776e60f70cf5271f8caf9b8d65b1a47160ed2e243d505467d1e6fc8437c745e5579de5ef908d714487719306d8c87c7301b7a64fff68663 Ssdeep 384:j7VJzyvjtcKx+8LH3cKlq2CKz6gyeguu+Fi+F+CZx0C3:OvjBx+8LH3cKlnCC+7+Fi+FR Yara 无匹配 VirusTotal 搜索相关分析 36-151210163I00-L[1].jpg 文件名 相关文件 36-151210163I00-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-151210163I00-L[1].jpg 文件大小 4391 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 0e43eef54884882cbe95e8386d7ba202 SHA1 1b64b454d19c89e24556dfebd371dd7819d735c7 SHA256 52dcf00d5122d8fc17c958b01eab64d649ea4927bb9769b233ebe0ffc2788f7e SHA512 8bc54f7685cf32e8db83237f26353cf84974283ef5b757f0931ef4f941ae5d2001d6e053d5c812b0ac593d7cf8c42fcf094812c1bdd3e03e75666fa3881311c9 Ssdeep 96:D8wUZByoaDVUPqPkaFjyu5buAkXOBWY2/FDA5jy4rzl:4w5oO26k0mIeYWB5IO4t Yara 无匹配 VirusTotal 搜索相关分析 test@cnzz[1].txt 文件名 相关文件 test@cnzz[1].txt C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\test@cnzz[1].txt 文件大小 92 bytes 文件类型 ASCII text MD5 b776a6d3a13634d8fa7a6467785b461a SHA1 5e329687335c6ce4db0266469146ad92025b135c SHA256 675d4e453d916d7ef871bc842960481f38ffdfc5256fdd85935f39b13d5f0972 SHA512 66f6bfdccf0a0d7737e65cfe1ed1dc4e70d0c8a1db913350408ba9df2ff9ba247ddf25d3adf09286fe0a60d6524c116c626b2f33acb35dcdfe67c310fb2ba679 Ssdeep 3:HMbXGTexGrFXv7Yciaq+W3yM5l:sKrrqaKygl Yara 无匹配 VirusTotal 搜索相关分析 36-151120192120620[1].jpg 文件名 相关文件 36-151120192120620[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-151120192120620[1].jpg 文件大小 8536 bytes 文件类型 JPEG image data, EXIF standard MD5 bb58eb514f01a9a09cb46dcdf6faa7c4 SHA1 73d71f8c5b46c489ef050e3ede681e9c5394b0d5 SHA256 40d763e2c7bb7230b69989792c7fba3afa11133f9393e532528e6058368f1e39 SHA512 e448c7edf5a6ebeb998a0af04eb97fbc1d62e3e84ad2479518f577e08c9b34d1d68d14b4b729bad8a65b342e52315166b4edb39ea423981e67a1bc98aafb92e1 Ssdeep 192:+Wwi3pgFRKvSEQ6wn6pWMg3s4ubw6AQ9beIj8S:+WVZ2KvSRn6msppAaeIjl Yara 无匹配 VirusTotal 搜索相关分析 appdwn[1].png 文件名 相关文件 appdwn[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\appdwn[1].png 文件大小 30393 bytes 文件类型 PNG image data, 284 x 563, 8-bit/color RGBA, non-interlaced MD5 319a524efa73d52f3b21537b507d702e SHA1 569b23df03a74c2cfd013740ba5b352e9d503020 SHA256 2abe89b07f1474af3fb3b60ec10ff4c9ae6cd90ec9d330830a46aa12eb68795e SHA512 a38d385352818f6a72b0e41a1336cdbbaba84de8102dd836252f0eef7a8d4a0ad5c805d35777a1879d28ddac899e0f28570a21517794b44cad3061c492062454 Ssdeep 768:sJUEd7q98J3hM0CzYrQGoDSLAKab3Lhla3xN:GE90q0olGoGLAKava3/ Yara 无匹配 VirusTotal 搜索相关分析 index.dat 文件名 相关文件 index.dat C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012005111620051117\index.dat 文件大小 32768 bytes 文件类型 Internet Explorer cache file version Ver 5.2 MD5 fce5a16f073ea21aba46df773946fcfc SHA1 d9d443b494855434a26a2ae57fc67ee1600a5979 SHA256 b80a1981879b1a82278e739812ff80de4d67c556ec4eb0b9adde994c68cd1425 SHA512 f957b8142d40a0883729a2a4a46cc659eb5a1760fbb94d0da3980c83a56eaba90e1aa81e0a746fa88ebe3f13871fd54377bf5f1018ae0d14d607323f97f2ae46 Ssdeep 12:qjR2Pqq3AXN2GG7YlTGDd73ACd2GG7YlG:qjRMqtX0OZadMCkO Yara 无匹配 VirusTotal 搜索相关分析 [email protected][2].txt 文件名 相关文件 [email protected][2].txt C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt 文件大小 87 bytes 文件类型 ASCII text MD5 6d2958df91352aa4fc9e2d8030e400d8 SHA1 b2f58fa2b4aeb5e7a894f8603310983b1111685c SHA256 531540493ce57f6237cf901ba0f9947a19cabb470fc859076726215b882b42d8 SHA512 c005eaf3b9481788ba34df29128cb3bbfb53ea9083282ba6e1824b0c2ed7508b5b95ac355c0cc712425755fda7f5755d55465eb7ef134d6976a3e9a9efc6d7ea Ssdeep 3:+mL1hcpjmg+QUQr1WG/5B7OVRiXXTvPvn:ZHun+Z4X5B3XXjX Yara 无匹配 VirusTotal 搜索相关分析 X[1].png 文件名 X[1].png 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\X[1].png 文件大小 411 bytes 文件类型 PNG image data, 31 x 31, 8-bit/color RGBA, non-interlaced MD5 f28d27414bd75263bd331381e7a82618 SHA1 64c07be67415cce651125f8e0d6904cff35f617a SHA256 ffffbd82a0da7ab90dfbfef18e175f0a8669bd36325a04f8abd5ad37758d383e SHA512 6bfc07fbb0eae2ff9201d01853a5a313104a725f7526af170aec89bc2d03b262a6caa91c657a7bfcc41e3efee6533c4b17d1859ab0267cead2071829ba191045 Ssdeep 6:6v/lhP/0QIsdXls5jOEyMt98iek5/OuPPA092EAbp+UqxQUL1h9OxU2M5WR/2TxK:6v/7nGsdy8MlX40Ip5p89m64/bFR7v1 Yara 无匹配 VirusTotal 搜索相关分析 icons[1].png 文件名 icons[1].png 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\icons[1].png 文件大小 32795 bytes 文件类型 PNG image data, 354 x 980, 8-bit colormap, non-interlaced MD5 37f7f749100302857f7f8c885721cc7e SHA1 16715a8030ee25bcf9ea4ad5327771c0d5d94fb9 SHA256 330ba6b5b4a279aa7520c6a885b71a65613a14334b88cff83bfbc9ea35a10757 SHA512 c8076438a6da0763dc33b4a72924bf2005bc5541be8325cf23839d9a0f31707c9b76bf53f13f8b053d8a300861ab48e66773d144c2ef126908c24509321768ab Ssdeep 768:zHuisfW0/LtHa9UijGrKOb7R5kzIyPkZKxpw3kRssIEjXKC8hqZ9K:zHpEz56+rVb7R5Xkkoxp/sSKC8hO8 Yara 无匹配 VirusTotal 搜索相关分析 36-151120194JVJ[1].jpg 文件名 相关文件 36-151120194JVJ[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151120194JVJ[1].jpg 文件大小 9350 bytes 文件类型 JPEG image data, EXIF standard MD5 95ea9c5de3178fe78befa10aac15aeff SHA1 e2605a573ad9033a209b53da583abbdefb041379 SHA256 c5ad0daef78c288722d757f1aef002ebbbe38e2e5c749a008ae686d9b69e5042 SHA512 1f137e46cc429e9a4d9fb553817c0227e08a0afb24a62a9bc8fc63eebf70392681e943947c010cdd70af21e61a021699b11e8cb139be4088b2ac25880c562a48 Ssdeep 192:+eqbcT18zcBs4FlR/nzM1b1xWRVFTuFVKwmeoMY:+U18gnzm1xWAVKFt Yara 无匹配 VirusTotal 搜索相关分析 36-151120194430346[1].jpg 文件名 相关文件 36-151120194430346[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-151120194430346[1].jpg 文件大小 6506 bytes 文件类型 JPEG image data, EXIF standard MD5 b47cf2503d3c90db1ae21cf1a25d4745 SHA1 971ee3c4c968c0adf9271a064871ec5900adb598 SHA256 451661ef9a0de7355a04856dc5bff5b25c30809dd2b657e7c5194d5f3e5a0c4b SHA512 bd915c8690283ff23920ef1b7c65ce47f5ab16d1c7d8fd2ae965c809aa7b4161f7255fc9fc574c38f31fd6c8a2852b2e0ab37f27d5f8b69f0864625c89150810 Ssdeep 192:+CKWf7ErgoFC13ezsOYfSVgkpsKUAF476LuIp:+ef4EkC13sYaVjjUAF42V Yara 无匹配 VirusTotal 搜索相关分析 36-15112020021X28[1].jpg 文件名 相关文件 36-15112020021X28[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-15112020021X28[1].jpg 文件大小 9281 bytes 文件类型 JPEG image data, EXIF standard MD5 7c7cb0b56d3f9d37058c33b6fde8178e SHA1 c3f9af81f4258f2e453623b3b0f658fc2d076dd7 SHA256 729be4e4ecd7882d5d8ac5698b6e42775f88d93a75cda77d255c602016cbd429 SHA512 f4424916e83257907aaeebfde1ccaf3258cf2cba95792fc1408cf07a3c4d09df42aedf229c8a0c7030315ba70a48a4a1342b0b6a650f5af3498d5410402fa644 Ssdeep 192:+oysUp/+4MLzhWwSrW7FnjpaYWsAWStUuiVlZDFa:+oyd/+4Cuy7Z9a6LK/inZDFa Yara 无匹配 VirusTotal 搜索相关分析 36-151120202200192[1].jpg 文件名 相关文件 36-151120202200192[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151120202200192[1].jpg 文件大小 7549 bytes 文件类型 JPEG image data, EXIF standard MD5 2d897881850353ded0a7de72f134a2b0 SHA1 412e48ce03782d8e79c30e7fdd0afa652fe0fa72 SHA256 f3a5ff9e772f025e4ba84fbfdac41d4bc96dd17680a1d99cff760ecda5b6b596 SHA512 ed81e5c4380bee5b14a65535c87ad66afd318bb0f7230ac89b7abe2291d760614e5add9eca2ac126b9b65141496856f40d22f3672c2ce829c47130b11bb5316e Ssdeep 192:+h2JBna9cw9wCuU5OjfKGjx5eCn1P3l3xU1:+QRa9ciOUJGjvbg1 Yara 无匹配 VirusTotal 搜索相关分析 36-151120195233R1[1].jpg 文件名 相关文件 36-151120195233R1[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-151120195233R1[1].jpg 文件大小 8192 bytes 文件类型 JPEG image data, EXIF standard MD5 7ab4734b6d45cfbfa9293495aba4f5af SHA1 6f8087cc3bd5880299d84ffdc02d6b8b03b8ada2 SHA256 950ab293badabe1c88ea533f5977b336bbdba68846804519dc96cf5bb5f11504 SHA512 0c5738913f0f5884353ac69e3f4fab21203ef363b209b5e021cc2b2d0fd0ce426269b0cdbb808bd45d4c9cdc3e531f69751cfefddb72144d188fee537402ebb2 Ssdeep 192:+2v7xrf2dShRaB+sFowE3hvLn4sQN9vNSKvo3:+21NUFo93hvbpY9vNnvo3 Yara 无匹配 VirusTotal 搜索相关分析 {B75A4AC4-5660-11DA-8A10-52540043F29A}.dat 文件名 相关文件 {B75A4AC4-5660-11DA-8A10-52540043F29A}.dat C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{B75A4AC4-5660-11DA-8A10-52540043F29A}.dat 文件大小 5632 bytes 文件类型 Composite Document File V2 Document, No summary info MD5 ae346da1172c20c677f869853a3dc3cb SHA1 3a45a817720dd3baf4b5ea9e9028a645ee5e80ae SHA256 b93cabf23e821ea3a261d73f6c2789550518fe339ace18b1fbd87312d89bf461 SHA512 13ac003a1e7da2266d0dbf9008efb04972eb40232229e348529d022243adf6f5f4b03d1c2bbab97c2d06ca1435bbc4ac3eaafc4ef335f35fe0f3368d73a1e2bb Ssdeep 48:rsDDGShSXVk0eJqFJ9FJboDJJFJtoDJqeJY:F63qb9bbwJbtw9Y Yara 无匹配 VirusTotal 搜索相关分析 ico_arc[1].png 文件名 相关文件 ico_arc[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\ico_arc[1].png 文件大小 27813 bytes 文件类型 PNG image data, 178 x 582, 8-bit/color RGBA, non-interlaced MD5 502c3a4b2b15d4c49670cf7df2918a77 SHA1 f74c06b223f3eb157544eba6934562de4c3bfd34 SHA256 92e7666db9bf8cbf7c73dc665d53f69ba4276b1c22d3570bfc774847a7fdf705 SHA512 f75861c368009323686c23c1332c652505716385e14e2bc2071ec7a581f2816331f64c407384fc7e14c28088db3a5fc3b9d61a9f846fc00c1c7c9a50bb0cb145 Ssdeep 768:TJKRP7v9d2NVEOGP3GrxGJwfNQfClBqegDHhJpprwtm:EtVd2NyOGPG1LfNQfyr4HhJwtm Yara 无匹配 VirusTotal 搜索相关分析 36-15112019242YD[1].jpg 文件名 相关文件 36-15112019242YD[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-15112019242YD[1].jpg 文件大小 8081 bytes 文件类型 JPEG image data, EXIF standard MD5 f08b1cddca9ade477a669d3733943b4e SHA1 f1de007018e5732fd3f13459276eea2a52477715 SHA256 44d6ce4a6f4ba6e2089a7536fa181e1db365fc8cdb366100c7096d3ecb7b482a SHA512 212d860980be6e6ddfff78cd0e3163a8c5888a4b781c31cb19de7a484bbf88aa782b9e3519971e909ef375fe5ad09fdbc4e1901293b7685e8f1c5c1b3607874f Ssdeep 192:+xvV1ipseJGJFCUvr36G0pn8/XTdCv9XP6H75rEiG1:+hips+GRT369pcXBCv9f6a Yara 无匹配 VirusTotal 搜索相关分析 14544096519373[1].jpg 文件名 相关文件 14544096519373[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\14544096519373[1].jpg 文件大小 27771 bytes 文件类型 JPEG image data, EXIF standard MD5 5c75a2810887100c1b7576c9fbcd03ce SHA1 186034de2ff6fdfcca53ddf238eb4a70a603986f SHA256 faa8560ff5f70a32712eb89784a1d96812fc650f770acd751f8d4ea06dba6815 SHA512 021213f98c9a31ca18bc54adbbff68564f5ef9ec70711d6678f91ef7f1344bc5964058894ddc4d7d4d30855770bb410bc4e9db5f1d7b5e45a9c1d27e6e39b5ec Ssdeep 384:wIqjoZw7tWQMSJIPM3CuR2edRkQRtH8hxrsntodsnY+1uzRBVPVvIDGA+AM0ZTX:wbsC7cQiM3n9RTRh83OGvzdtv8hX Yara 无匹配 VirusTotal 搜索相关分析 70-16040510545QP[1].png 文件名 相关文件 70-16040510545QP[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\70-16040510545QP[1].png 文件大小 15644 bytes 文件类型 PNG image data, 150 x 150, 8-bit colormap, non-interlaced MD5 f6cf0a887c14aea37443d2688a4286a5 SHA1 f80d6d8a0aa80cdd8f2186f71ceaf3e3a471a3d1 SHA256 9a9dc9212b36c6785e82fc74f3b8b3a1ba92dffb34a92d15610b57f7a92de8de SHA512 6d146b63401ac2e4b7e662ae0f9db92be7c8b6295424c519afea9c5b53e5ff18d20fe41fe7737e137be76a6b3b56c9fdb285288742744c6b71416a5699a0af28 Ssdeep 384:U9MolqfYXw4gTmiMzzSZhz/i/6uVIdHwyjo:Ul1lfncz/iyuVYzk Yara 无匹配 VirusTotal 搜索相关分析 index.dat 文件名 相关文件 index.dat C:\Users\test\AppData\Local\Microsoft\Feeds Cache\index.dat 文件大小 32768 bytes 文件类型 Internet Explorer cache file version Ver 5.2 MD5 0aee387ca0a52dcdd8f8a29ea76edb42 SHA1 5df81547dcadb2a7b8bc689da8e1383ba1a84cb9 SHA256 c31bc37e102b70a472837d530ec80bdaea28b0fefda3e9aa8c8cda98c4200c4e SHA512 101bdb7178e031b1fbd78d595d778d06174749246cdcb70eb4b92af534910e30e0627147260ec319bccecf7a105c814b6b32c077a777fb5e90bd1459c78dcdf9 Ssdeep 12:qjtSaFpbZli3zIoYDPO7em4GZj03W/cKYDPOCG5A30WUsOXQDG9YRm4GZ5:qj4avEIoYTCebGZ7ZYTlEJ0oQQ4bGZ Yara 无匹配 VirusTotal 搜索相关分析 all_tl_bg[1].png 文件名 相关文件 all_tl_bg[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\all_tl_bg[1].png 文件大小 924 bytes 文件类型 PNG image data, 1 x 1, 8-bit/color RGBA, non-interlaced MD5 d4e8c98a953065d2f84e19cd1d6e974c SHA1 3118d44eb3aa758be893123edf77d8bf53d3fb24 SHA256 9a217b79c603e476e2c72025ac84cec04d325e2391a2617a59f952be505e2711 SHA512 797a84bef96d31fca6731c1ccd28d04041457caa801a500429fb3e2daad2bf52d03b2dfca5d4e04e8453dc4f7d1b23876290c279ba3793a8d0369c09fe61a2cc Ssdeep 24:ey1he91Wwjx82lY2T3ouVDsmyJ3VDrgWGqe:ewqQNn2x1SJ31JI Yara 无匹配 VirusTotal 搜索相关分析 36-151120201334B1[1].jpg 文件名 36-151120201334B1[1].jpg 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-151120201334B1[1].jpg 文件大小 3912 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 42882d07332600eb29933fc756595c1e SHA1 d0f2269e486d669644723e80eb92966e1a7850d0 SHA256 20ca0b5fd532d6f2216d0652f1c93c7911f564b61ff0763228135ebbca4f7d21 SHA512 030a93e7b8eb951acfa09fcc5d3c6a05c87eadaaae64c6d07ecea9904501f12286359491746f2bcfe0bfd2463dc67187a3be2afedbf9a5bbe96f2a6c67031d93 Ssdeep 96:DBznXdMuD5Oa8npwmE8Zlls4EcqYDJ4Ms:hnXaulnUpxbZsO143 Yara 无匹配 VirusTotal 搜索相关分析 36-15112019202XQ[1].jpg 文件名 36-15112019202XQ[1].jpg 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-15112019202XQ[1].jpg 文件大小 8203 bytes 文件类型 JPEG image data, EXIF standard MD5 709f3301766d1ddc1fd46c31d3799421 SHA1 34ec8b652fedacb2d141fc319d342e5a38db8f20 SHA256 4cd22d2fc97fceb2c95a47e1e70ac5c90446356307bbf7742cfb9a43fc9e7879 SHA512 b407b7f8c084399b9df2d877c2d1c8198149ac2066dd952332d5942180a746cc656df576847ff286b44d554c6199b2d12c54185a00a7ad1147ad034a25c0f779 Ssdeep 192:+kv/ahlQEfKiJEZyoKNq8jKwSiVnoAijS3qVUhQVuPLxnqLzu:+LQEyiJE1Kq8jBpUJVUhiW Yara 无匹配 VirusTotal 搜索相关分析 bg_info_hero_02[1].png 文件名 bg_info_hero_02[1].png 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\bg_info_hero_02[1].png 文件大小 726 bytes 文件类型 PNG image data, 70 x 70, 8-bit colormap, non-interlaced MD5 f807a2c4747f863b809049960ce2f039 SHA1 bf80d1c006da91979399872f904f9a48078e7b4d SHA256 c7ad4151ca36a5ab5574f3cfc19fdfbca2ab71eb6bb63c0b4c5477885e65576e SHA512 1b37f775662f7babf9304865eecf0895646d60e455b1f4fe571acd4376b1777c8a3a4c6291837bbf9f7944809c9cbbc34a237e6c0dec653d43c959b4a827db76 Ssdeep 12:6v/7kmUcqUUoGi0whCGJ1xh1+cQEJUobC/wec:HcqUUOhC21iwec Yara 无匹配 VirusTotal 搜索相关分析 36-151120200ST33[1].jpg 文件名 36-151120200ST33[1].jpg 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151120200ST33[1].jpg 文件大小 7047 bytes 文件类型 JPEG image data, EXIF standard MD5 0136ec1b0b9b0c867923fe4d40e9d2c3 SHA1 6ee12f5ddfeb95971f6299ccd1ccbcaae6284fdc SHA256 cef535c8d03afe9e93dc30ebd2ec7c469f7c40875cb38576cc952e2ca8c430b1 SHA512 f20156643071a014176067c62a5f51a463924a102b14a50cea7695c3ec3be90934b715d5eb99aca2c6b6e397cc91a42fb574a4341098327aeb652deea229251d Ssdeep 96:rCEOKBqlPM6VTSw441BNj9cCfpmBhnUzBT/OEaK/UkCTUNx8Z/t+fA2Pu:+QqBMmTZDj9cgpihUzB3aGCEI2Pu Yara 无匹配 VirusTotal 搜索相关分析 14448186091968[1].jpg 文件名 相关文件 14448186091968[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\14448186091968[1].jpg 文件大小 38677 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 7be54cdb39be80ceac9c8c95ce75ab99 SHA1 bb8ff760425258ffb108e3e50fb2f17d850f5f19 SHA256 abe05c1aeaf53927fe8592eb7d6b3bf045de2cc8869f23bb077d1ad59455087c SHA512 5fca2f0985ff7c060e3b9ef865ea46fea7b06ac1f4198519389737f16d3339953967a367214c98b05c6972f5d8ada2585f227cfb205a1d37342d02a52d6c83e2 Ssdeep 768:hzhvjkCKFJDw+HnXdcGLAbJEo9KO0/3xh:xtSHDwgn6vJf9Kl3xh Yara 无匹配 VirusTotal 搜索相关分析 core[1].php 文件名 相关文件 core[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\core[1].php 文件大小 2618 bytes 文件类型 HTML document, ASCII text, with very long lines, with CRLF line terminators MD5 9636baff363453abdbb79826d23a5722 SHA1 20b40100f927a0888eec961878a99bcac3b77c12 SHA256 54976d5d5063ccca9e0daff270fff6a516155a31913c593cae114918bfb67fdb SHA512 3eaa58979d9f58e99ffaf31159978fc5a6ed0914d45b81433411822b005549483fe0b70c0711001bfa402431085a8e71a0e1c51409bc9af6bf2de74efced4753 Ssdeep 48:aXOAPaMl7D+pyVjkTBi2k+tjEXGfrgo+ufW+Emz7jUprCntFar5TNc5FNSLHiFsW:a1l+s8BSWtW+Em5/GW5Fa0N Yara 无匹配 VirusTotal 搜索相关分析 index.dat 文件名 相关文件 index.dat C:\Users\test\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat 文件大小 32768 bytes 文件类型 Internet Explorer cache file version Ver 5.2 MD5 3dc09c7f23ad1ee21e9d8c41535fda6b SHA1 292e69464a917bf49cd26a20cf243a3029f68e79 SHA256 48a114a62b80c301f75048077f8ece89a8696ff1a27ef9ea5f03a125a6133c13 SHA512 1410ba6d5a1ee8b046553a37e2a3023b17dafce497d86f7784300ce796ceea96bedbbf2f013e0b15fe2b5cb718bfe3d5fc63bd0351c73d43fa97edc34046dbc4 Ssdeep 24:qjW3Qb0iodwgX8P6CEDz4jOzwBhzGG2I6JjmfO4:qC3M/K Yara 无匹配 VirusTotal 搜索相关分析 36-15112019493X13[1].jpg 文件名 相关文件 36-15112019493X13[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-15112019493X13[1].jpg 文件大小 8453 bytes 文件类型 JPEG image data, EXIF standard MD5 2d1c3a7f936694151138c9a53befc433 SHA1 0d2af37fc132c936d4091cd8fe4ccd67dc919a1f SHA256 ec6a35611d7e95f1ac85013a0b88115faa963c4b34add9ff34cd1e7a9afbead9 SHA512 37198aee6ad170562ee48cccf39df9972b5059137fffd7ff38e350fdacb7466c5b59c8e2ab4c42463ded36eb4310fbd0b8b8cf12f3bcf246c483fcc4a7efba0f Ssdeep 192:+wPGLjVNvmPlJtOUFPB86OL0rbcHPkp88s2:+w4jH+5OR6OL036V6 Yara 无匹配 VirusTotal 搜索相关分析 36-151120192K5F6[1].jpg 文件名 相关文件 36-151120192K5F6[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-151120192K5F6[1].jpg 文件大小 7780 bytes 文件类型 JPEG image data, EXIF standard MD5 cf6e5ded0ae05ba8f7a9528534c2add5 SHA1 e4ae64c96522a650ca0732369de31bd14b97a70d SHA256 8b3b9c08653d8e220e80ff6c4a00c25addb829937dc4c61de3fc9c5002b6893c SHA512 a3bf2f4bedf4d1400956d34051b251062aea23a63e7282a3b2d125759797d947b0922f3b1e0d004efaf15e181a0cc72c8bb82336f92457bce677d2dc598e2357 Ssdeep 192:+OSMxG3FqwUkpJiVPpW69d0Z+he6B6LkvpXRzYrGP:+RVqWuriHk6OXRz6GP Yara 无匹配 VirusTotal 搜索相关分析 cov_50[1].png 文件名 相关文件 cov_50[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\cov_50[1].png 文件大小 1013 bytes 文件类型 PNG image data, 2 x 2, 8-bit/color RGBA, non-interlaced MD5 d1d07f97d321c487c05fd8b43e08fb04 SHA1 844fd723de85a73e03181d8c2e129e1c8c7dd924 SHA256 286fc5cfd22c4456320b5fd5a2da382b618a2cde8b8615057bd1e36f1240ed11 SHA512 489df7af9126b915fcc57a5acb367d6b5fede08dafdcddb55b208a325263c9ccb368cd10c3e5f745338887f55e047f37781060c4d302eff3e95fcbb05f98f9c2 Ssdeep 24:TBJ1hiyWwh82lYSKw7DcaKcV+T3LyJ3VvP7D4Gc7:VuvnL8c4gSJ3d4X Yara 无匹配 VirusTotal 搜索相关分析 bg_info_hero_01[1].png 文件名 相关文件 bg_info_hero_01[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\bg_info_hero_01[1].png 文件大小 218 bytes 文件类型 PNG image data, 70 x 70, 2-bit colormap, non-interlaced MD5 d064962582a2ed1fc9dd1340f46f87a3 SHA1 f81f6b468d1f4a0a65c5fa053663d412eea1f090 SHA256 c843b210bbb07f780064b20084cb6daec05e468d372905ee83ab85f264c6f1e6 SHA512 33a69097a8061aba198dcc155de7e3d0af3a01e9376fb5fcd86a9dc8dac2dc518d6a2bb02a4ccedfe3d2797e8391e81565902090077225e694c6ce61d1bc78c0 Ssdeep 3:yionv//thPlb5nmbol7CX9/iy3/P6HHUfgodzl/oWhl/OuiWc3gR3fN1N1Nf/vjy:6v/lhPOkMUyKUflj/oWhAuiC0/Vp Yara 无匹配 VirusTotal 搜索相关分析 36-151120200029251[1].jpg 文件名 相关文件 36-151120200029251[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-151120200029251[1].jpg 文件大小 8490 bytes 文件类型 JPEG image data, EXIF standard MD5 11016814e368be158f423a6d1dd1b892 SHA1 73400476bdcf8d15477189872d5be70ebc0e4711 SHA256 fa56b5530f9fe199580d66533279ca0de7dd19d9edb6f59e72e264db2b955291 SHA512 320691dd5f1fede28336d8b5b10554e4d0280ecd49c1c9f35fd3cf9353b3e36e9356e85437cbc3126ae7e04bf7e7e8f941a551115de480dc358ef40b8235bdd7 Ssdeep 192:+ErzseTApYeivVXJbm483zmFjvuNoADgtp8f5fNlnV1:+77ivVZbp83zgjvueLtpW5zV1 Yara 无匹配 VirusTotal 搜索相关分析 36-15112020032R46[1].jpg 文件名 相关文件 36-15112020032R46[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-15112020032R46[1].jpg 文件大小 8520 bytes 文件类型 JPEG image data, EXIF standard MD5 0a75fd47b7d1f57e852de7ac9f8b3bc5 SHA1 72f4df880a7e5d9378aa4ee125fca94ac050bc51 SHA256 04eba219eff6cf9eb69c7c96f37e816173ff329dbac865f0c041a82d64060b5e SHA512 4f96dfb03bd0a74a5a0ee9639a27ce899738f6ce4c6983de2f68d0938dcb1a33c1300bc3b408a7559e13c809cb3c31cde5e598f7b8487d475ee805d1fbcc7e11 Ssdeep 192:+jCL1bLNJcdLbeW8b7zoHT5nnioZoEv3MGcfbyNF:+WL1bR2dn8XGioKaMGDF Yara 无匹配 VirusTotal 搜索相关分析 36-160413111950[1].jpg 文件名 相关文件 36-160413111950[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-160413111950[1].jpg 文件大小 6462 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 0c026b45639374bc1feff893795963ed SHA1 4a6569f190aaef6e94e751c48fa237f5daf18946 SHA256 1dd50d5c175b55d775751e6c6b2abb4891e7f57ff4b68943214b7e7b4b02eaf9 SHA512 e0e6b720cd32bd7d5a682c0a659a3ec01cdfc83432e4e72629227762f0893453e6fc8c9484dcbc744d47415d089c6fcbe99bfe359b40c4c427a8a35c2830a6fe Ssdeep 192:yOYgIHgnPlntGhzQJR64vP/8Lguphutcic:y/HloxXEppEmic Yara 无匹配 VirusTotal 搜索相关分析 arc[1].css 文件名 相关文件 文件大小 arc[1].css C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\arc[1].css 23080 bytes 文件类型 UTF-8 Unicode text, with CRLF line terminators MD5 21de20d8a4ca530974a07f457ffe1c09 SHA1 74dc52270ae7fe81e2731d349a98a15fd0a81124 SHA256 83631081177df247fc3f3cbb9afc1ef8f2311fce81cc8761ed00c0c6309ea4fe SHA512 5539138c81999bd04ce719952ee882c9798ad946ca7ca8b2f64e255b0bc564bf98743b5db1184afbc0c30674613a707587daf9512e6230abec011b3e665c16ef Ssdeep 384:bd+nV6gfzwpjtz3uPIh6lNTjqnQ2BxsdG+qi/:bQnV6gojV3uPIh6lNTjqnQ2Bxsdnp Yara 无匹配 VirusTotal 搜索相关分析 www.18183[1].xml 文件名 相关文件 www.18183[1].xml C:\Users\test\AppData\Local\Microsoft\Internet Explorer\DOMStore\YEE0B1V8\www.18183[1].xml 文件大小 137 bytes 文件类型 ASCII text, with no line terminators MD5 a194fe76094fccf0a0f933ff0004f357 SHA1 ed2f04801c647107b3dc1d83934e22ef7c36fcb6 SHA256 a673becd3a7f8c2c66c70f55531814b770d1c0ce1ed68978d5d4ba00c0580326 SHA512 d593091264cbf5a203c486134a0dc566432b5a1ad9379dbb5673e19aaeacd2b0d61a04e6dd41f4d3424d598c2b8a8e62a8c620aef3988964380fc0277ce1fff4 Ssdeep 3:D9yRtFwslotjGwPI0GVAqUNToRTQLW/uE/sqdSfsLKb:JUFJ2Q0qAqgk1QSuE/SDb Yara 无匹配 VirusTotal 搜索相关分析 bg_header_xz[1].png 文件名 相关文件 bg_header_xz[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\bg_header_xz[1].png 文件大小 23479 bytes 文件类型 PNG image data, 211 x 97, 8-bit/color RGBA, non-interlaced MD5 e90564686049eacba979bb2442d6f364 SHA1 3ed8c229d9425733b69d337b8f9e8e3c1ea4fe8d SHA256 01e363b7050f34eca5d1127780dd9b5b985c65187fb53f7e9aff800893d518c6 SHA512 9dd96128570c91c82a0dcc1f4e9edec1ecdd9c7bad83aa403c019f1b8d7be9a38893413537a3888222103c500a790d6745a1747502b188d6067ba0b6d64a1f56 Ssdeep 384:MTvfl68SGxOWSOvjDGnMQo37k0m4gaRK3bNwLJRn7nc4LcDeTe3m+GBUw7:MzslGzjioLksgAyN4z7c6T8lfw7 Yara 无匹配 VirusTotal 搜索相关分析 bg_body[1].jpg 文件名 相关文件 bg_body[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\bg_body[1].jpg 文件大小 142116 bytes 文件类型 JPEG image data, JFIF standard 1.01 MD5 4b9beae5892e81fec768f789a6e5e9f8 SHA1 53e73590f66c46a86afb72f07e98f6f030768eff SHA256 b4829d7f055a639c7102a43350df63b49d15289fbc3afeb7ff59228aee85b9a3 SHA512 194843908c7a156374f967e187e370d400d8e10b91b6e62109d923b35ce92ef1c4f49286f38b774d2174d6413a572dbcf63bd5415b8e0115683c221d798fd167 Ssdeep 3072:k4wZ7f+AnCTi6i/Zp++kFYey01/8NaqtkpyOlSP1P:kf96TIjQTkNaqmyOlSNP Yara 无匹配 VirusTotal 搜索相关分析 36-151120201150Z9[1].jpg 文件名 相关文件 36-151120201150Z9[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151120201150Z9[1].jpg 文件大小 8155 bytes 文件类型 JPEG image data, EXIF standard MD5 4ac58444831ee0747a7631a05babe0b7 SHA1 f82f6b196ee0a86a52ba4dfe7e71acadf3da8ca3 SHA256 31b80f3e79250648e3eac8e7c38a2a21fc3159cb609116a35f0a1727f8bb7b68 SHA512 74ed236a9caf8fb256d9c00a94a0b86ee4c268d3fe0f4b7a599e7a33dbe5d69595462b0f5c84228cfed871a5dd0340c461fa79cf6625117c43ad325cacd8b54d Ssdeep 192:+6kf2+s9t9odD232AiODVPwZHIz/QSl+wkXfbpP561WW:+9zs9t9odL76bQKmlMp Yara 无匹配 VirusTotal 搜索相关分析 index.dat 文件名 相关文件 index.dat C:\Users\test\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat 文件大小 262144 bytes 文件类型 Internet Explorer cache file version Ver 5.2 MD5 fbe6ba880d1f6cadfd771536120f2c73 SHA1 34b1a30160c6c7675a5c69b62d98661ab7a494bb SHA256 a2cdabb3fc43f2e94ca47fac764eea7819768bdf094690a6369be41fc4a5fd01 SHA512 6a28d50bc6feeee26b35f014de7c8462d584bea98e9d6c97ebcedd2f22af71c4006cac55583161f4b6e25ad6e7f44f067b3f983113e078104f27ec02b1a4d0ab Ssdeep 768:pFFwZHojCtOlWNw3nsiMsieuugxdKOri:rFwZIjCtkWm3siMbeuugxdKoi Yara 无匹配 VirusTotal 搜索相关分析 index.dat 文件名 相关文件 index.dat C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat 文件大小 294912 bytes 文件类型 Internet Explorer cache file version Ver 5.2 MD5 f8098117db9c10673fea3149019057bb SHA1 fdce822e50f5c496efdddaaed1dc699b900a6eb4 SHA256 3818998471801a9cc9bec8970acd3f4f50ad7d9eab01a39031833cdb3035c510 SHA512 c14ee479399d5f929d1ca843577f6dc17ff869f999dae60a7cf6abf348153fe2ec6b1f6bea18e497568e212f691a855e08fd72e3da040a4c3c4eb0feea39abb7 Ssdeep 1536:w+r+fN/Qn+iTVHQPjZ1JFE/qO9JCsRb1BLrErwzj3T08ND6lz97gYtB4ljEwxohH:5rwm23wzjagYtB46wxohV34k0I4SPhV Yara VirusTotal memory_shylock () NET () 搜索相关分析 bg_header_02[1].jpg 文件名 相关文件 bg_header_02[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\bg_header_02[1].jpg 文件大小 19134 bytes 文件类型 JPEG image data, JFIF standard 1.01 MD5 91632d80b4cd9f140eff1fd0a17ff3d7 SHA1 99b4b44a5da4baf37406673f3c9a8d4147c73144 SHA256 02b84695071d04faefa8bd788a8943f9f5a6cb834db6415ab7829eee29559fc4 SHA512 b2d769ba58e0bc7b062a47cfe776ab8a4aeaa03540845df82707c43d41d1dccdc9bf35dbe781704504b2186458c13f41cde3a0685f19674068ee525e722c7494 Ssdeep 384:HS/STBasB8McAO1XIPaV+8jtlQN7loezEOuRESnEkrabWHekuT:H+wzOA2YI+8Blc7l1iRESEk+bWXuT Yara 无匹配 VirusTotal 搜索相关分析 maruko[1].js 文件名 相关文件 maruko[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\maruko[1].js 文件大小 43792 bytes 文件类型 HTML document, UTF-8 Unicode text, with very long lines, with CRLF line terminators MD5 ef6e06a731ade254d1ff8e8af256e85b SHA1 cfe960b5c0b675cbad004f0dd45d263657370694 SHA256 57e58cd1cd36363e59e5d158c63af594f256b106899d21883ce7fa4c9c5cf6f4 SHA512 9d1d986488c5544489fa6ae98e0f69cada67e29de0fcd2d7cc06b32ab2d1c51615e0ad70ee24233df5f25e6e71cc060db3426840af282b3fde836fcc330f2217 Ssdeep 768:pvgoP2WzWk8V9nid96ONCrYlogyHdXwIu/5NBC+:pvgwZM+96ONCrYloTmIv+ Yara 无匹配 VirusTotal 搜索相关分析 36-160114113125[1].jpg 文件名 相关文件 36-160114113125[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-160114113125[1].jpg 文件大小 4502 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 6a339d44cc47d1eb71262685cff0e444 SHA1 c66c798a06ea0a72cc68046e9ba5a07a8bca65e6 SHA256 9af66aa54fb253f4453ece80d44c57e4690a7ea549951dfbfffa3e9753de0fc3 SHA512 6290682278c948f16e03bad7d09e664f3bd53494b0eb69bbf459809fc485dfd678551b48e5b1d7fa9b3b4da55961023fc606c0429a1c8223ae560d8f2028308f Ssdeep 96:i40xUl5KF2YZHlimJx1dnusL/YfRhU3gtHhvgRPjiXNH4JAUcQC:zl5KzZ8mJZuu/G7U3gLIPGXNH4hcF Yara 无匹配 VirusTotal 搜索相关分析 RecoveryStore.{B75A4AC3-5660-11DA-8A10-52540043F29A}.dat 文件名 相关文件 RecoveryStore.{B75A4AC3-5660-11DA-8A10-52540043F29A}.dat C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{B75A4AC3-5660-11DA-8A10-52540043F29A}.dat 文件大小 3584 bytes 文件类型 Composite Document File V2 Document, No summary info MD5 4789a8a58fecb1717113daa29ca830aa SHA1 05dbe27af7f4b78331b8c61ce308c0ac52c3e219 SHA256 6c37b6caeeb65a383f9537f90ee9a878227abcbfc5aa5dddf07c46a41692520e SHA512 f5977a03370ea40ef25f9a8b94a108dbcb34f2a6689ae269fb48ba5ddd8f1fb564a07f51511ef5bf262017f3663ccb0c11b04d7d661d03571f2c22e5339686c3 Ssdeep 12:rl0YmGF2sorEg5+IaCrI017+F3ADrEgmf+IaCy8qgQNlTqoCMgtFggMg:rIso5/gUGv/TQNlWoZgnggMg Yara 无匹配 VirusTotal 搜索相关分析 cov_v[1].png 文件名 相关文件 cov_v[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\cov_v[1].png 文件大小 1517 bytes 文件类型 PNG image data, 49 x 48, 8-bit colormap, non-interlaced MD5 f49c3a223281de64f88c7079808a3862 SHA1 b900f1b05addb409efb6b7ec51951607a941908f SHA256 de271a971e9b07f4dc4708b1a573e0a76f5acf857172145bfdafe31dfae9ac56 SHA512 362807fe8bfd8c8ef6fb62dc5508f4cee79d9f5200fc4e0535dfb0bb01fa6dfc0b3e9de33c96dcf0d14e2b4abd49703c731271832dbe616a4bdaa5144c46b851 Ssdeep 24:oHl3y3/k0OumUFq5JhKvCmyiFd8HZVzvZRtKbQ7t:iO/DOK47WDqVbUM7t Yara 无匹配 VirusTotal 搜索相关分析 36-160413111951[1].jpg 文件名 相关文件 36-160413111951[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-160413111951[1].jpg 文件大小 5961 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 6e08ab63bc7f09ceeab8df3be882a125 SHA1 06750f44cff53e01ab1102f1dcb2125c8d661a9b SHA256 5d491be0861fa91ca8d917390a867d8c7afc9911119c253b87c6b4f95ce6b7a6 SHA512 243f03d4bd651672b5d15be04df2d381eccbf3d780177e929db236a29a31b23214d09d0cf2a1b5ec41f6398c0cf3b6cd34245c31b00247fcf70727a8d81e013c Ssdeep 96:4lfftkID4p14XZ+WsTaaNuLv/A3mJNrdwZyBFsLHBCjOX3tet5505QiCz1lvUIvY:EfdD3Xo/bN2v4+DwZSMB0OX3YP+5WvUF Yara 无匹配 VirusTotal 搜索相关分析 [email protected][1].txt 文件名 相关文件 [email protected][1].txt C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt 文件大小 114 bytes 文件类型 ASCII text MD5 3cbe2c28a3ae787ba29e3516acddc202 SHA1 5d5fae7b89fe49d94c55cacb27a3da82cba7c409 SHA256 6abaafa02e455ebb87e6660efb12f2d59c874e31297d11c0eaba771ac11a34b1 SHA512 09f856862d9a5a333d9d9bc3d6de1e143f858f4494de24cc137362f2648497486a5053aa44c505d6a2493bf7221107def21b02a617048e154150f1595923ae41 Ssdeep 3:4VW5AZDUWhd+RyebQRFc3oYdIKPv7YcKb+W1u5l:4tQWLPtRFQfKKADel Yara 无匹配 VirusTotal 搜索相关分析 36-15112019553I60[1].jpg 文件名 相关文件 36-15112019553I60[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-15112019553I60[1].jpg 文件大小 7256 bytes 文件类型 JPEG image data, EXIF standard MD5 87722bf8e67133b76864746b59c739a9 SHA1 398c2b1608335138fa78684b8304506f7818d443 SHA256 f436debe6fcc19dd630daaa254584c3e9847e682e079c9ee7ecf84a5e52bc840 SHA512 77a4a1c436fcea5f89b28f8f453d7e1c33ad4cac3ae47353732cf5ee13647c97e58e3c01f0dcc1b13e0663fdc23f679906be51ba8290eb979aa50d19aa5eab3a Ssdeep 192:+9yqrb+meZ1w24jln8K0C8YCJLFiu3QNovqWL2FdHUdog:+9yq/4adjB8DYIwGQqvqEcdk Yara 无匹配 VirusTotal 搜索相关分析 B912B2C6928A18B8CD7D50CF08BEA95B_7F0B9652162FC5018915AD9167E5C64E 文件名 B912B2C6928A18B8CD7D50CF08BEA95B_7F0B9652162FC5018915AD9167E5C64E 相关文件 C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B912B2C6928A18B8CD7D50CF08BEA95B_7F0B9652162FC5018915AD9167E5C64E 文件大小 486 bytes 文件类型 data MD5 f0c3e36923e00a88c86c95f252c7f8de SHA1 2fcdb6a36bcdb9d753eea296ae48ddc3112d7759 SHA256 aaf2713e3ec25b9929fc4338ce7fd7b3af3cb1469335257e017ddaf51fc3e506 SHA512 fe658e5840b36d92b31db26bd9406923888b7281cc874c50c1ab68aee2cc666a0568a9e3de3c48a334cfb9cafc5c6a74bd07d1633ad5520b2f5cf9557370cc24 Ssdeep 12:pIPYMulX9ysFFSebMRPQMl2H+FVy6jyFRac:pIPrulX9VPSegRPL2H+Fg6jyFF Yara 无匹配 VirusTotal 搜索相关分析 bg_info_line_01[1].png 文件名 相关文件 bg_info_line_01[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\bg_info_line_01[1].png 文件大小 1382 bytes 文件类型 PNG image data, 1151 x 1, 8-bit colormap, non-interlaced MD5 4994400c6ef7dc808de90192e7c97d68 SHA1 655f980748536c83c2236c692841680b30fe288e SHA256 86ba5ab64740c2d58e884262548be2247494325d43392db7c22a1550bac5cebf SHA512 6576158c5b1a5e3291c6f92cad5ac20e8738c714f72cbcac3ff0c38c63bbca8505ea6d4915f4dbde9ce18600f43d55f35bfac1c4600962d89c4ee6abb1b3e39d Ssdeep 24:lekB2LcKuFBv+7ym2+kRj9O5atucnxTu0F04eKVyxvO2:wkB7DF47fzWOcNxTu0reKUs2 Yara 无匹配 VirusTotal 搜索相关分析 36-1605061121090-L[1].jpg 文件名 相关文件 36-1605061121090-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-1605061121090-L[1].jpg 文件大小 4918 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 5d3c4d235b36dc88bd26c21895d58a1a SHA1 24b101e1d691b6486889c5af7cb8b8f956be2d69 SHA256 c0aa67c3c873a7f9701ee1ca4f909be6dc60d7332172de200a20d14ae9611613 SHA512 f85233b7d7450c8fc7f337a7b45dde095cb41510697cc3bcfa464979cc34873001fdbbfc2a32cef4f381d67fcdb00c4f5609d768c4a648df971c9322a02a4595 Ssdeep 96:oc0VehJ1tRbXH6ox/tFjKG9sjfVqz/21JK4rneryCCjkHM1RywUJVhUsqEvW:oGJxxPDuVr1JvDuqjksvXQgsq2W Yara 无匹配 VirusTotal 搜索相关分析 36-15112020143OT[1].jpg 文件名 相关文件 36-15112020143OT[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-15112020143OT[1].jpg 文件大小 8041 bytes 文件类型 JPEG image data, EXIF standard MD5 25422915195771c31c2ae21f00ee67fc SHA1 4b1841afd2a3eb321121a0eb2f220c36f89582a0 SHA256 2325b26cb4947a7560cd8b796632f586d26eaf446f07fc17154af4e0e531f0c9 SHA512 35de3cd0e4cd64a5ea71dba246f5d0513751e2984b428a6183208f8d973172f2d278eb90be3ae22943cd43907b8718036f04c877c6e7d8138b9eabebcd3cdaa8 Ssdeep 192:+V7MzzmUdIRMfALKngHBahVIrvtLGaG3VK9rBlg:+5Mzc6fAGgHByVYvtLGe9c Yara 无匹配 VirusTotal 搜索相关分析 cov_60[1].png 文件名 相关文件 cov_60[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\cov_60[1].png 文件大小 933 bytes 文件类型 PNG image data, 2 x 2, 8-bit/color RGBA, non-interlaced MD5 35ec97ea6ae590de4dea531cd8a890bb SHA1 0b9beea82a00229e98d71cc044ba57b7e6ba333c SHA256 45e076594f543f02002626188ff723ceb8a152c8db96793d89bad4ae0c6c7558 SHA512 0dac459b3536f31e9f5de6a5100704c425424c33a45d3a8ead9f94967574f988e6060da316eb1cf28cc873710bfad8bcb168f489f39b131e703f87bc0456a132 Ssdeep 24:TBZ1hiyWwjx82lY2T37Vc+GQyJ3VyDwhGVes:luNn2vynzJ3c0h0N Yara 无匹配 VirusTotal 搜索相关分析 top_toolbar[1].js 文件名 top_toolbar[1].js 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\top_toolbar[1].js 文件大小 21327 bytes 文件类型 HTML document, UTF-8 Unicode text, with very long lines, with CRLF line terminators MD5 79d0161d6807daffec14c47bda57476e SHA1 a8499d9cdadf3c7dcfa6eec1fe6cac9ed5eaabbb SHA256 aaae47fe04517c39b504f72284d9a284fd8e0548de84997c0947f8d34ac65b86 SHA512 5504d8b54e259e16e4ab6c1b0f23656b2d4f73ab30593e458de859e133cd29b584df6047b380e5e238a4bf4b08333fe07c1ee2030133440aa594785b1db04827 Ssdeep 384:YZEHRzGNc3L2Dn3tJWL4tqivYkTY1vuKke8UymSwRI6G0X6b8wyvnoiy69BjksFE:YZEHJx7273tJe4tqfWP Yara 无匹配 VirusTotal 搜索相关分析 [email protected][2].txt 文件名 [email protected][2].txt 相关文件 C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt 文件大小 462 bytes 文件类型 ASCII text MD5 8129c9dfd84250a9e4813a8fe209b318 SHA1 0c40b869b89dae3fa24d2e576b39a73dcbff7c3a SHA256 c2b895f89aac0c3afb7d8c4b6d2fbd04c463d3074edd6d8f9b4aeea55c833a5c SHA512 c4fda9f2e591f7545704fd46b2c590225e3478ddd1992f8d314698864a994e6c98de5e922f27dc2edb79735145627f2757e9ea627a535e802f151058a6e4f773 Ssdeep 12:ZSlB0R4ScgDjdR84zbvrnKcPKV4HObvMgFguwtLJa4HObv2m:ZoQc6jlZOvIJxdm Yara 无匹配 VirusTotal 搜索相关分析 36-151120195156428[1].jpg 文件名 36-151120195156428[1].jpg 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-151120195156428[1].jpg 文件大小 8914 bytes 文件类型 JPEG image data, EXIF standard MD5 4cd3e5dd0653b061f3e0ed6b4c08d9db SHA1 d2cf18ae9b669df797b1b47cdee9b88242a8a012 SHA256 345dee5fd263e8867b31540eb20888e829c76b05f2c9aca6fc49086a48d4abb6 SHA512 53c0f33102d93a8e4dcc81614d76d29db36fd84a8304c42bf8ab8a6a37a6dae0484cce561bab94bb221bec3d509f95124bdc949a2388d5318bf8bc74b24c2f22 Ssdeep 192:+GOw9FdqdeSkErFYm22q1l9uOCc3CDeXGHV4IicE:+D3dfbYaYQMAes48E Yara 无匹配 VirusTotal 搜索相关分析 14629365731420[1].jpg 文件名 相关文件 14629365731420[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\14629365731420[1].jpg 文件大小 23966 bytes 文件类型 JPEG image data, EXIF standard MD5 5f8705d7c6bac9c3824b2aa832aac6af SHA1 334f390ddd7f504a03c860b35eec5b84e84279da SHA256 b1ab6b1cea07cfdca9ca18eaa430ee79ab68f5a5f6080204eb7769b1eb5c72e5 SHA512 1b0ede6f6afb8cda3b7401a58f067caccceb1478b042d0c835353c8bc80431184b469f53730afd368bf84c0f385682e9a78e769461f472ede3d06fd60d86c93e Ssdeep 384:hXxkSLEdkpZkuAyDEsCuLwKp44x0Gs/AOcQ96xqulSFf2Y3eyL/1iwq2Qk:hCjkpZbDEsC1Enx0R/ziquU2ueyL/rqE Yara 无匹配 VirusTotal 搜索相关分析 36-1601131916294W[1].jpg 文件名 相关文件 36-1601131916294W[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-1601131916294W[1].jpg 文件大小 4295 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 84399c619e3d21d78658f29c312899a2 SHA1 80d2d89eb2e0ff9b2dc2726a87acbb2395e7a730 SHA256 b652c8710f3b152c798dae0c291fefea8c62416cde325d00a68f930ec8b799a5 SHA512 e2d28b32d0f8a89def7dbba06f65144abc9f40cfdb87e04387854782f804183c8f876313811564fdb3854f2012b88c828227e0ca7e315ac443ab1cbfeff58a49 Ssdeep 96:ArvUlJRXuDDvhtaZnM9mdzIYLUcYAN7g/X:y0+fvh0M9QzIiUczA Yara 无匹配 VirusTotal 搜索相关分析 bottom_toolbar[1].js 文件名 相关文件 bottom_toolbar[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\bottom_toolbar[1].js 文件大小 3259 bytes 文件类型 HTML document, UTF-8 Unicode text, with very long lines, with CRLF line terminators MD5 7f43d131eaa161082fcf98ad7eb4a5e3 SHA1 4b0cd0706222229b51c97461348caa00ed1a4689 SHA256 85c06fe3c7211a5c5d37ffc52e0aa623ea5fcfd510a10afab21c2dbdcccfecbd SHA512 290d04d4b3a1b3fc74c247423334856df243a3b630a7f25b37f9247ebeebdf31d8c579f510ebeaf4d326fdb980b2a2b56b2e926b9a1e89f934e4aea05859ad69 Ssdeep 48:Sa0SfRyeZQdr6BO/Dj73WloCAToW2qq9pPC0JaMIg6:FfgLdr6BO3B5KbaMA Yara 无匹配 VirusTotal 搜索相关分析 bg_info_tab[1].png 文件名 相关文件 bg_info_tab[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\bg_info_tab[1].png 文件大小 5393 bytes 文件类型 PNG image data, 95 x 70, 8-bit/color RGBA, non-interlaced MD5 58a2d9cf09737b4aee5f13ffb0d13b00 SHA1 de6a5dad61e8aa37ea2ca71340b75172531eb987 SHA256 8b1bed9f5c66c810f6a8ea1e4a4b59f809f6d9651201f3853be89db63ebca7f6 SHA512 7c14aaeaa872da4fb7855fb0bfbe219b6899e88af1c8ceaa5d45c4a4697b3d14b39114d80ab29595a5a4ccad1552ae56d6e1d376c9202bf2213728e7e8d78769 Ssdeep 96:MKBQJYN4kAvJho9ngFWeUVkWoG+kZTPAyplsoztrJVni5ox/MR3rhbN:MKBcv1vJhoVeW4Gbv7zlJc5e0Jj Yara 无匹配 VirusTotal 搜索相关分析 index.dat 文件名 相关文件 index.dat C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\index.dat 文件大小 32768 bytes 文件类型 Internet Explorer cache file version Ver 5.2 MD5 a07fe7c79a65300fae883860cca5aedf SHA1 51a8b17031e1fbf8ba4833c52bf22f9c8354f652 SHA256 d9074243a7624fe16c937b11c54acd3b38b860d6c98d2aef70a201b53f32f94e SHA512 17795df123035c38f1b0343506dc9b4e9bec85fd0c778112896594e701a48aeea962f868264a89bbaed94761036cd71a7221604b016adf25db260e2254c23e2d Ssdeep 48:qbuYpr/jGiBtgx8Xpvdlr8jllJ7MfvFNzoyb10YH1iYnVnChXpu0sCmDdZn/4Syd:qyfkQQvWJwvHo2+YH1N4544x1F9 Yara 无匹配 VirusTotal 搜索相关分析 base[1].css 文件名 相关文件 base[1].css C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\base[1].css 文件大小 838 bytes 文件类型 UTF-8 Unicode text, with very long lines, with CRLF line terminators MD5 a0786bf8942f38ed6a75e561fae5defa SHA1 4dbd737317c1ada8d6a9749e31b835641917911b SHA256 50dc036a1a560ea2d8f371958b8b16b27f5e31169fb560dcce0f566d35c18f25 SHA512 5ed0254860181cca8aa3969c2955d89cc8736c9839f93e71cfb160ee38023d0b2440bec87e04d5e7b76d803b0ab5f769cbc54092f66974063dd32c54f644a537 Ssdeep 12:kHfvSsPXeiT+McvcF6MwGboyUChpFMQxgDTVTQMANgLFd0W3p4JxtWyJJ:i4SWuwshLMQxukMANgLFdv3p4PtXJ Yara 无匹配 VirusTotal 搜索相关分析 36-16042GR033[1].jpg 文件名 相关文件 36-16042GR033[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-16042GR033[1].jpg 文件大小 3408 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 64e83b7f44a49f7030ec387effc7b3d5 SHA1 59162096a1561b04b711af7d12975625b66cbc1f SHA256 93f8a6eb009406caa5f153f6f2a1372ed769ad13658f8671084a47935bd8b524 SHA512 7f1e4ceb4ee9009e7239e6f7105b48cafa7ea3226c2e203827ff640888e0669f2ef13e5af78ea4f68c35094fab83dda626a53363a6bfb270fb57694537831054 Ssdeep 96:o59lfyz16H9QX3wPr4G0pkeU1L0DeiBSZT1Szp2l+n:o/lf+1yQU4kXd0DeiBSZ60l+n Yara 无匹配 VirusTotal 搜索相关分析 70-1604051055461D[1].png 文件名 相关文件 70-1604051055461D[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\70-1604051055461D[1].png 文件大小 17093 bytes 文件类型 PNG image data, 150 x 150, 8-bit colormap, non-interlaced MD5 0740db895149f4dc95f49eb70a67624b SHA1 0ad54e113d3199a37627ee4c26d241efaab39aa2 SHA256 294e5b3bd03bf312fe3b82038154339e07cb75112b754b17324ef47115237ed9 SHA512 8edb4e485bae17280d6b266277706b8857be369346b912017bc07e2e339c57161ddd9d492878ed4a9c6252042c98364c6bc4ef088f024af3ed1e39fc9e3fd346 Ssdeep 384:CXWosANrDhZylAJmFJ2Hjs774+VN6ls8ggvELZcpfDt6FKYtw0:WW2NJZylAJ4Y477fVN/QWofpvZ0 Yara 无匹配 VirusTotal 搜索相关分析 36-15112020104Q94[1].jpg 文件名 相关文件 36-15112020104Q94[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-15112020104Q94[1].jpg 文件大小 8236 bytes 文件类型 JPEG image data, EXIF standard MD5 a0d1fdb31e1ede8f2b7ad0641aa829a1 SHA1 6468f222202326b4313d8580d5e2a708819e67b2 SHA256 e467016091683682d6fcc0b80ad62524a3107a2bcbf2124bb66c67433bdff81e SHA512 018d3d1dab09ae1d03a45b130959324e0f85b16f13cc03ffac287b1fde357047ef10f53a2dbf8968c62ab7f9556b521bad099ee5f39894449df1a472265ae018 Ssdeep 192:+/xDI5QoddEA1tPsWJfjqLXeoD5nZth7bUT/i:+/xDQdjfXPtqLeoD5Ztp Yara 无匹配 VirusTotal 搜索相关分析 bg_bzrd_links[1].png 文件名 相关文件 bg_bzrd_links[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\bg_bzrd_links[1].png 文件大小 14612 bytes 文件类型 PNG image data, 347 x 47, 8-bit/color RGBA, non-interlaced MD5 bd7e0bafb5e33342a447a9fffcfe31fc SHA1 1479d0520509d4323b0ac284f84577baac6ea92f SHA256 f730a4a1d8831b503806090af3c7d554cfd536a73b215ffa4cd6a08781db323c SHA512 390069fe5bec76ae52cae0609d6e958ead872fd8f92b7b82649436f8f36934e4c3594b590913db6ea0fa4342fd7a9ccbe3740d011e75c035d8dd033891733650 Ssdeep 384:t4vX5NFpNX3ncs87L30pZDBp+t4uC0sRvmjRThuJ:tgrNX3qH0pZDL+fC0sgjZhc Yara 无匹配 VirusTotal 搜索相关分析 2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat 文件名 相关文件 2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat 文件大小 294804 bytes 文件类型 data MD5 89c8569b15a2695c9005ce41204ace9c SHA1 64e3d469b65004c2a216bb2cbe7b374e83604c1f SHA256 e8ad3220054647c0f90fd7a63d278f18efcd5e292ebeab3553803def2e8ccfa5 SHA512 8f4418cf764100e2e40dd5a4200849838c67ecaa678d9e8fcea1b150dab60103a49cd97e14bb1abb8e28b1088d6e70b2c24be23dbb9c9f9bbce109e13fcdd753 Ssdeep 24:aXB5QeNlrIXsjkyEdd5A3RWHYytLxziT3iui//W6F0azKxXavPn:wOeDn/u5A3R+dtLp0ST//Wa0azKhmP Yara 无匹配 VirusTotal 搜索相关分析 36-160413112314[1].jpg 文件名 相关文件 36-160413112314[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-160413112314[1].jpg 文件大小 5782 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 f0ebf728c040cae9b3589850230ee3f6 SHA1 e3fae3b1b1c5c7fa20dd375df445afd12e0bd480 SHA256 ea4b6fc9fc17f5f7230523da6017a818eb8236a512a8b6557bf4fdbd849b249c SHA512 103a1b2e33fbca005ab82b59e0887f35f653f6c8cb10c5ff80a4984cb1e016c7b595b4cecc75c441df2277ad49e0360c27154a10a15ed2049479cc8df80f73c3 Ssdeep 96:HnExxiKxeXOuVlDkl6xPwb3z9vOLUWv8ANqo/4weMvXW5o6AxBdjsmEZcnXIhF2n:HyjxuVlD46hw7zwz8A1DebqDx7Y+Irhy Yara 无匹配 VirusTotal 搜索相关分析 94308059B57B3142E455B38A6EB92015 文件名 相关文件 94308059B57B3142E455B38A6EB92015 C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 文件大小 342 bytes 文件类型 data MD5 94dadc92e1735f3bf4792d5db0bae12b SHA1 1b42022ab14bc6a5c1bff3dc81a4252d331640ef SHA256 020ba0f3cc788191f97971f637b771fda8431ba550355986d7358b0db6b17c17 SHA512 3ba8d7f4c01a2935e79089a1968b04533911f8207e304ab27143d8a06181705db5b80da37fbb06f736e3decbd31892e6cb51b139c45d382bbeece36f2ea39861 Ssdeep 6:kKjLWyytNdSFCmas1W4Y+SkQlPlEGYRMY9z+4KlDA3RUeKl7pUmDt:2XNlsWokPlE99SNxAhUe4UW Yara 无匹配 VirusTotal 搜索相关分析 bg_close[1].png 文件名 相关文件 bg_close[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\bg_close[1].png 文件大小 1448 bytes 文件类型 PNG image data, 30 x 30, 8-bit/color RGBA, non-interlaced MD5 45d21086ddd3ebbe5fd3abd81d93c488 SHA1 ad3fc90683a9268605967b2ca67a360c95ee2b15 SHA256 3b7e7b728ae33389d6be75484a5b99eceb1dfcd2a0ef33fd4294635cec450a1d SHA512 04fbde08e326956f4698fc8408640710ccd279267029f8f456a9a77ac346648865adba0f5283dd21c8e132c3f77577eff7be2e9e586445fa8c2bfcefe5cad863 Ssdeep 24:Oy1he91Wwjx82lY2T3ouVS4jviyJ3V6vBofGzetbb9ygVj18doY2HZcxJ5EIOu:OwqQNn2xbJJ3sG5pygRS725253 Yara 无匹配 VirusTotal 搜索相关分析 blank[1].gif 文件名 相关文件 blank[1].gif C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\blank[1].gif 文件大小 148 bytes 文件类型 GIF image data, version 87a, 100 x 100 MD5 544f7bd6122f951996dd92da003610a6 SHA1 fd7ca06368d849fca9e687ec0dada79ef253158f SHA256 988d0aecb9f8050fd358725f605ca6164865231b0cc2cbbb25e71cd6fc2aff14 SHA512 4bbe4894c5da2b53c2e0a02498dee89bc56790dc6588a868b342a6b12044922948b90cc173dd7b059617d3fee3d87db6ba5176cacffe8f7c722b9334dde37d2b Ssdeep 3:MMP3vJ+881C9cr3pv9byYlS0ZYlSfGqOqd1VvUk:XQ881HXdIHlSEqdkk Yara 无匹配 VirusTotal 搜索相关分析 36-1511201ZI43Q[1].jpg 文件名 36-1511201ZI43Q[1].jpg 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-1511201ZI43Q[1].jpg 文件大小 7880 bytes 文件类型 JPEG image data, EXIF standard MD5 09b04bd121bc07af1d8b992e234e2b00 SHA1 b0eb1fb59117b680ceec2116936abff43d118978 SHA256 06d1cb8b21df95bf56d1af0919f123c4cbdc9f6a6138f9bab1e5ba689dcb7c1e SHA512 27aa495cd42e488fd9ee0ef99d33759fc8f2181e11665d6b23da92cb84c2f6f3f34f4233b939e0aae0d17819247416354f9c5919f7213d3c17e5fbbd32e11d77 Ssdeep 192:+WJ3Fd3YfFoes2L+onHpvt7OADZSfN5IjJ8PVj0vlY:+4VBtes2nHpvtvuIt8PVYNY Yara 无匹配 VirusTotal 搜索相关分析 36-1511301159450-L[1].jpg 文件名 36-1511301159450-L[1].jpg 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-1511301159450-L[1].jpg 文件大小 5123 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 303a51daac41d7e2363ac62d790031db SHA1 88cc31eb63c6a3d947ab10ac1137b729e062ce23 SHA256 98c7c7f8765cc0944464732b162b067527c87f96266e6c2d618f3e2ccea7058d SHA512 c69f5b900ea5fedb6e62260f29867bce345537a2cc4ce232feb70ba5ee6d7756b98d8c45ff783c5639e4353bea1665eb09dd5e72dbd0b5c94fdc963c78197f00 Ssdeep 96:RTC/R34tN4bvuEavmyCdAq+vIulAfjbMtyVQYsiykGwan82b3k5eKILn29V1N0kx:pCh4tNGQ/ZPvIuWMRhbzVlKOC1N0kCs Yara 无匹配 VirusTotal 搜索相关分析 index.dat 文件名 index.dat 相关文件 C:\Users\test\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat 文件大小 114688 bytes 文件类型 Internet Explorer cache file version Ver 5.2 MD5 a2011ad164c31ffee163c69a4a3e41fd SHA1 a3b8160506a03dff1cce5cd6e83d9381e9e1a7a1 SHA256 944258221f6d0327633a1d12d6b0f127a8526d2b37cb8c1db468cc0e0541b0d1 SHA512 52323c08deae320a47c772e63ac8e57f870011d2d75fa3017e81fed134b7de6c9850686aed84b023cd346fa3962dea8e2e7601953a878aba9d290e002513a21c Ssdeep 384:VOkZGEBP0DpH9maYm2e+0B9ZLHL61fuv:VOksGP0dBYVu Yara 无匹配 VirusTotal 搜索相关分析 [email protected][1].txt 文件名 相关文件 [email protected][1].txt C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt 文件大小 345 bytes 文件类型 ASCII text MD5 e3e6d9d61ae7852b82a04f601a1aa596 SHA1 35d90205a0d406aa4d0f35c23288e10fee96fc9e SHA256 853d49e3454040e9ce5fbe0f3960d21cffc00802aec3090eae74712088242fe1 SHA512 75e39927fceb827039263c324caa0062bf04d2c3615db08ccdc3a8b43cd251e97b78b1984af404daf10f053fc36461a6dde6fdf4cdd9154bf3d11b3d37acb36f Ssdeep 6:ZQ3sDWVdRiXcYRpJSScK9DjdRtWVdIbXvhRvVCFg2SnKcPD+KWVdIS0OvhRvMol:ZSlB0R4ScgDjdR84zbvrnKcPKV4HObvl Yara 无匹配 VirusTotal 搜索相关分析 36-151120192621D6[1].jpg 文件名 相关文件 36-151120192621D6[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-151120192621D6[1].jpg 文件大小 8482 bytes 文件类型 JPEG image data, EXIF standard MD5 8379ffeff0b442761c2fd5315881a086 SHA1 c0c2d2f037197181634af79776f3824983d66408 SHA256 e362ac7dbd0c8d214314ff24ab1ae90cb49ebd417c80fa7a3dd4970d5c358f83 SHA512 84a84b6604b8b29d60d2e6cde05d5795d127590e65578b16a533184f8b525f18b423df0fda2a4b60216100816e8f5aab575955e722ea09db330655efbbe7f409 Ssdeep 192:+dAPRZ3CwwZvYEz4w/yEWyuRrOs7sQF0JCf8OscSSwVv:+dAPqZvYEjJuRjffpZMv Yara 无匹配 VirusTotal 搜索相关分析 ico-toptoolbar[1].png 文件名 相关文件 ico-toptoolbar[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\ico-toptoolbar[1].png 文件大小 3446 bytes 文件类型 PNG image data, 16 x 64, 8-bit/color RGB, non-interlaced MD5 65e83fe01973749621ab547c23119d2e SHA1 14ac159b3c56ebceadcf458a033cd36dd984981d SHA256 41927fb5af1c229545c3a7f47e0a10e1f913b15ff00228c47f6469f9f124aa55 SHA512 01c5755c7af5dee672691547b10908a17d8c2b6ae8c8aa183053fee4b2fb5eecb2a1f72f4b18b077c344bc9c41089a718d8d8d694444f6edfbfa640cebdeb464 Ssdeep 96:/Y2V9WuSiptjD1+a04uhP7TnbY4/V2g95HnZJEiIRi:/hptv1t+vbRtJ9tE7Ri Yara 无匹配 VirusTotal 搜索相关分析 core[1].php 文件名 相关文件 core[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\core[1].php 文件大小 760 bytes 文件类型 HTML document, ASCII text, with very long lines, with no line terminators MD5 5b28276f0c1fb69562981106c6e00b7d SHA1 9af5d4e007f95d7e8a01ef66147399a3d17d969c SHA256 e08fbec388f2948905fd5022f1c3bd6e6d3c5a5ca980a95aa999c9c45a5da132 SHA512 354bd2446db2ba5b671702ae3705f2d5fa6a87551a053011170e05fa8c3c35c086924e6663914d22644fdc2b5781514d40c4c76f4bb4b0a599cd94076431da36 Ssdeep 12:cRnGsYAaTso/ihQOJRGweLa5+yIx7Gu2LB2o1wNJ/lgzVjuXiVcELnPXerTWz0i1:cRGXAYsoahqw3lCp2LBZ18pyBVNjPcTW Yara 无匹配 VirusTotal 搜索相关分析 c[1].php 文件名 相关文件 c[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\c[1].php 文件大小 9939 bytes 文件类型 ASCII text, with very long lines MD5 1fc3b1ea3fadc1e25625b349e7813f23 SHA1 9014924f8fa5a62ade49dd95062a0609fa95da77 SHA256 89dadf434bbdd8fc2cb77cdf9f7451fe625295bea82debe60a9a93456ea2ef9b SHA512 a64cff2f2894aa4cc56b4f1d68b2f5c188bedfc2e3b76c84cd155a8adee4de1c1af9a85318f534c93e90de47880291347f0f20f66518dbcdcea4fadea3b6a64d Ssdeep 192:ZIFxhYUCO5emuSsxf5m1mbi4s5pHx8ooBDeaJXg8lEkWwB9rP1VkCAt:SFxhYUCO1uphs1kxOahA8CUn7kCAt Yara 无匹配 VirusTotal 搜索相关分析 index.dat 文件名 相关文件 index.dat C:\Users\test\AppData\Roaming\Microsoft\Windows\IECompatCache\index.dat 文件大小 65536 bytes 文件类型 Internet Explorer cache file version Ver 5.2 MD5 6c2c329e6710f9a90b96c44f2a1c939f SHA1 15164457a4b2d11c1de4ed491d835252a41d84a0 SHA256 1f39e06613178b5bacf683a5d689937173af06c69140919ca111ac1ef65f4890 SHA512 3b740468d7a97562e8b92cac7ae8b3797da175c6186122688055b88c19fc223621c2b0e24f6177ef72e812aee1280895ccdaf4d09ad49839ec5b646c62b2a4ae Ssdeep 384:wEEG/+o0FpqcSmlB/+1cjltMfU/NgPKQzdGwcHQ6NneKC85XmhKvA1gIaVX+mPRF:wEEG/+BK Yara 无匹配 VirusTotal 搜索相关分析 CAEDF689AA6DC9642B833051B2B77D1A 文件名 相关文件 CAEDF689AA6DC9642B833051B2B77D1A C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAEDF689AA6DC9642B833051B2B77D1A 文件大小 266 bytes 文件类型 data MD5 f0b72c4a3bc52911de8b7e3f99edf002 SHA1 0000b9d5b73d91019215f579e66869d685ef2944 SHA256 8c7d949b003003ec93d943ddd8f2470896d0b84ffb047c9bf0ea78bd3c69578a SHA512 d0c35fdbefbdcd55a3fdd1fa06aead8cb5596373884bbfa271619c409de4bcfe3c0b6a2a64ef0866fa8429bdf743398311eb9a9ef7c8553c59210d427283b7e3 Ssdeep 6:kKahNtn48/HkPWe1+brB7WHiZlElQ12eCl0:ipng1S9pZ6mil0 Yara 无匹配 VirusTotal 搜索相关分析 [email protected][2].txt 文件名 [email protected][2].txt 相关文件 C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt 文件大小 212 bytes 文件类型 ASCII text MD5 e0b4ca063e5246c36409c3e692caf9e8 SHA1 3ae1ba9d1e5858110e7de5f5a8a809a9cab7364c SHA256 662977f84fa4de87f211fb62f6f9161d68c5481a1b04745c6f7ead053425b0c2 SHA512 1b19ad177127152be0fa61fd3841138ff38db2ee5906404a0f39b7616c653efadb1b4be4a6b76c6f36124c1811299aedb780c913e4d04a1676248871ba021d8e Ssdeep 6:ZQ3sDWVdRiXcYRpJSScK9DjdRtWVdIbXvhRvVCFgl:ZSlB0R4ScgDjdR84zbvN Yara 无匹配 VirusTotal 搜索相关分析 CAEDF689AA6DC9642B833051B2B77D1A 文件名 CAEDF689AA6DC9642B833051B2B77D1A 相关文件 C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAEDF689AA6DC9642B833051B2B77D1A 文件大小 185019 bytes 文件类型 data MD5 a95b8ab4fd2e8c2575f7f0d1b858da3c SHA1 08017547ed35dd83cf4df5e06af4ac81a54e5a04 SHA256 19bcd6cc9a16055ca0d19df6f92088d1c8c89631c389bd60a23d5182f013da18 SHA512 8271dca7cd75e30db3bf163c9b33587407236a9c17ca24583f611ea8143575774f0a4f72ccdba6e977aa2f062726f5a87a304f1772ea50d38600afe70208ad06 Ssdeep 1536:MwGpGrF0e7/nwmHjnv3lN9RdXWVTDyrbk9IhNPFTxht+4Lge4+/nQLnSEvlJpfLD:MwGpIdTr1mxyU9I11E+4LnplTfP Yara 无匹配 VirusTotal 搜索相关分析 14628768855622[1].jpg 文件名 相关文件 14628768855622[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\14628768855622[1].jpg 文件大小 44484 bytes 文件类型 JPEG image data, EXIF standard MD5 7eb82f06341d8b1dca1033037f95391b SHA1 92f6afbc1edf3e1d19f0cfe95943e655bdc7f9c2 SHA256 68708c8a9914bbc76a57e168d5238e26ebed36cd2f61c2937ae3b98c43e3aa48 SHA512 0b00fe0ef305f0b8d625b4ef6da5bfd4f4287ceb2ddf1a32924aa34b12ae8c183fda52ba96e605bfe4f3b11fc092f8d9d76b48326c5884b228442f05f4975b58 Ssdeep 768:98hd8qwuocVXv83CwMgwmg+YzNF2ktdBNlW9rJch7DvARrTd2Wx3S+E7jwEoLYug:9c2+ocZyCJnmXYzN0ktdBNg9M7DIRrkJ Yara 无匹配 VirusTotal 搜索相关分析 bg_header_01[1].jpg 文件名 相关文件 bg_header_01[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\bg_header_01[1].jpg 文件大小 19775 bytes 文件类型 JPEG image data, JFIF standard 1.01 MD5 b6ef72452b91a52e654243e8ab479ddc SHA1 b22ed742c370c7e89bd1ea3dea35305f0bcd2ecb SHA256 24d55eab958188949dd60ab94c361ea65bcf39f583902305eeca3edbc4f3cded SHA512 6e3a0a9ac56650437acbd6a9f06834208a926fab1623b1f17becff9a1111477ea11b9a65ad2dbab993a4c8d53018b5f6ff1e341a5c9b1615f9169a763daed356 Ssdeep 384:aIXY/I+QyQnZ/SPMb7kmwD+BkJ3q9UvmL1OK:rXYQyoBSEndwyiJ3qAmpOK Yara 无匹配 VirusTotal 搜索相关分析 36-1511202033120-L[1].jpg 文件名 相关文件 文件大小 36-1511202033120-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-1511202033120-L[1].jpg 8359 bytes 文件类型 JPEG image data, EXIF standard MD5 aeb76b054b209b4ea06cf859383139b3 SHA1 11652539f146d7b71e06e274726ca11fc6ea69c7 SHA256 76bd948e212a5f13d9d2720abb3a998fa34889242c83915a17bb6d42734ccd6b SHA512 f51504fcaaeaa8e1e296d2341fe79393ccc47946bb0a165e6c16711e853973708c2ed65470f8aa315a9d7466b61a1fa1e6d665d3a4b9edd03f6bba622ae9d440 Ssdeep 192:+DpkJSfKPLG0+2nHwThafyUHKKoQSPdz+PU6UVagcDSJB0:+DVKPLwafyUHKjQSwUpVsST0 Yara 无匹配 VirusTotal 搜索相关分析 c[1].php 文件名 相关文件 c[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\c[1].php 文件大小 9942 bytes 文件类型 ASCII text, with very long lines MD5 8f6b61346a8513da3791059ee847a34d SHA1 1d0b9c52bd3229c3d85a73689f910f16c08cff0a SHA256 879b3ea577069f2d0bb963ed2ecbc084cbf1ca09f7d12f4f7941f8f29d65a222 SHA512 1916b9794ac67c4e4f9a216a609a3fc7f4edd72539efa6cb4c5289d41d962747cf778e6898f4679b54aac8f651abe17b145e15811be57cb57fa9eac2db8fa540 Ssdeep 192:zFxhY+CO5emuSsxf5m1mbi4s5pHx8ooBDeaJXg8lEkWwB9rP1VkCAt:zFxhY+CO1uphs1kxOahA8CUn7kCAt Yara 无匹配 VirusTotal 搜索相关分析 36-151124143I80-L[1].jpg 文件名 相关文件 36-151124143I80-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151124143I80-L[1].jpg 文件大小 4612 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 1c760c53575b0a6c29156ae83ea72589 SHA1 1177accf943216e4aadb5fbd5db286cd4ae4606e SHA256 c050730ad05de4493236548041f71d2fc9dd806abf4c9288e01898deb03e2b59 SHA512 f3a68cab3621185e393fef0fe8ba9a6d287cd67a1da1e2e47614277f7b6a937f7eccac5a56827b67725452652c0aab2bc2fe985118ecb41f22ea216ac35f2d47 Ssdeep 96:DhwHVhhzrPIaFlgP3kmYygIr2WD1B4oq3dB3ZpDk6zi8wC7ilaS:W1hRrPPgM1ygqBxqBpDk6zi8l7qaS Yara 无匹配 VirusTotal 搜索相关分析 jquery-1.8.3.min[1].js 文件名 相关文件 jquery-1.8.3.min[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\jquery-1.8.3.min[1].js 文件大小 94147 bytes 文件类型 ASCII text, with very long lines, with CRLF line terminators MD5 a7c844a55e3b0cc9dd60c6b8a06f9ba9 SHA1 3b901beae2ec2b8c71ecca1c41f0b69ef2459599 SHA256 637f7abb8fd2d169db59efe14f77af6936ff88739d3b888933b8d296de21f680 SHA512 969e9d867a2f87caa4649eaf9de98c21674dde1977be98e92f9651c981d6a5655fa761a4e9599e46a6bd8bb206691add83401413140f4208615d7d9d19aefcaa Ssdeep 1536:96IzxETpavYSGaW4snuHEk/yosnSFngC/VEEG0vd0KO4emAp2LSEMBoviR+I1z5W:v+vIklosn/BLXjx0MhsSQ Yara 无匹配 VirusTotal 搜索相关分析 bg_header_03[1].jpg 文件名 相关文件 bg_header_03[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\bg_header_03[1].jpg 文件大小 19166 bytes 文件类型 JPEG image data, JFIF standard 1.01 MD5 8ee389ec490f6aa48d728e75e0aef932 SHA1 e8c1dcae1a3d05efc845f485af2539baf6569306 SHA256 a5aa3bcb8f7b39a377d0f49e31ab74b30f1a99f12a5e3460a973b72a6571c1fb SHA512 ea8c096748d0dbbd0df97df79c9485d9e7899e8bad3a6deaa26f6c9ecc919b44f5f6020bc77ab8fc5b12f3ee3f2e585ad85fd40294fd23cf5bbf4a380906fc92 Ssdeep 384:MkUGnBtzLEfwx6a71yTG6OOokR0WYRGUi/vWg13e6Th8Nqy/HbzUfdH:Flnv8xGyLRvlOg55cqy/7zM1 Yara 无匹配 VirusTotal 搜索相关分析 36-151120195921355[1].jpg 文件名 36-151120195921355[1].jpg 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151120195921355[1].jpg 文件大小 8824 bytes 文件类型 JPEG image data, EXIF standard MD5 e1ddfb31248d413144e3dd22316635a0 SHA1 e94fc695dce8ede9e162a197917cafc5209fb11e SHA256 39d688f509ee8bad512af24a8aa08a3847b6e7fa2374be2a9fbe0942ea6582ad SHA512 805b635fd2f9234173fba0c8f3fad12f7d5de11becdcec2d717bb001dfad16b89a73777c3c26a0b8b6366433b31e505f00d8fbe9da3996d4a12045b6ecf0667d Ssdeep 192:+rdBpMezAwasGa3CoiYMe89I4PzsW15XjHtmwY4vCpFvKKRrten:+rZTasv3sYMtI4PTXTtmwY4vC/Mn Yara 无匹配 VirusTotal 搜索相关分析 36-15120G55434631[1].jpg 文件名 36-15120G55434631[1].jpg 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-15120G55434631[1].jpg 文件大小 4323 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 c36d3992e15504e0688aa8507f3fa671 SHA1 addd718b0d3d7862e1fd8e85df9e84d6ffb26c4c SHA256 fd9735d10b1638a7309a7f471b7cef8620aae48e868578b48950d190256e01eb SHA512 f4bb8854d5109dc26d5f32791616673a227f447aead2a548e1d23043ddbfe8bf99cf61498019eab2c9af2f0da6f7bfdd0eada30bfaddcbd058e8cdbe715c672e Ssdeep 96:DXrO0beNXYOeaDUYro2ithMFF0lh5aq5HAHEwx3mI9n8RnXVe:jShNXfnjMlthMFKlh5a8HAkwhmnXM Yara 无匹配 VirusTotal 搜索相关分析 70-1605101IZ1C2[1].jpg 文件名 70-1605101IZ1C2[1].jpg 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\70-1605101IZ1C2[1].jpg 文件大小 8227 bytes 文件类型 JPEG image data, EXIF standard MD5 dc0258dae113b7e5a7177500e0e0b74f SHA1 aebf33148dc96588f3be393dcf7d715830f1c50e SHA256 826293bd6f6fb5261144d838a724cda118b7c3d3e13a25f4b5740a4daefd7e4f SHA512 3ff9284b1c180e735a9b1aa0421866e73443b129f3a84e3d9f7a924e74d1d2819c7d335fa056b473f026aa162490c2a911cb5f53c7c2d5d62074863fc4cfa07c Ssdeep 96:l2fQIJat5YxsznZzc223A7HmwsZlLyRa8zEeo7TKIAIkWFOhjKRwrbpM5y2yOMZp:Ztn5GwO2Q8W7TRaZwSbuDKZjz+BG7h Yara 无匹配 VirusTotal 搜索相关分析 36-1512101636260-L[1].jpg 文件名 36-1512101636260-L[1].jpg 相关文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-1512101636260-L[1].jpg 文件大小 3344 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 750f0bd054d26748aec72c94f86e83ed SHA1 5c5826ee22226d38ac58955fabf8e412a9d13cea SHA256 75cb32a32e4e9bbe8dd2fad95b58ba1ace20c0cf7faac15f892f2c3f6ba52acf SHA512 b78779eaaec7978dbec98f1fb6bef91151e2c83a2ef8dc32b4a9281e5a28cb4c1bd8fbb1c7b2dece2623b999de368f7e725502a1b3f6d1f3d4158f28105a34c6 Ssdeep 96:DtyRAnhipy0ADR6+JetVI3sy8QDnPTAre9xs:Rrn7h6ZgsyVDrAr4xs Yara 无匹配 VirusTotal 搜索相关分析 1445842259_324[1].jpg 文件名 相关文件 1445842259_324[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\1445842259_324[1].jpg 文件大小 8672 bytes 文件类型 JPEG image data, EXIF standard MD5 fdfd58531befc9d92cfc5c06c8f2530d SHA1 1bd89134a36b80062584669b87aeff299957d24e SHA256 01ddbb72a11c4a5e376fb9e9459799cfafd007945e3849e0cbfd489a76176ed2 SHA512 ff819ff6ed1be906a4299bbaa096c6caa3a9374f08aa362db84fe0fb26c0a18a005f3b5dfa5ea221fd03c9408bcf86c82a021c2ea2c98d48a61d14753fb8b4b5 Ssdeep 192:Bl+TNm0kPsVzMBh2G/ejTaKfztgloTj19Pua89mb8+J+j:36mIlqLQQoX1pnbp+j Yara 无匹配 VirusTotal 搜索相关分析 36-15112020062D41[1].jpg 文件名 相关文件 36-15112020062D41[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-15112020062D41[1].jpg 文件大小 8905 bytes 文件类型 JPEG image data, EXIF standard MD5 c88b3d6883f2b31b2edcf8e120159e8a SHA1 aca56cc29d9ca45aafe6c715d8ced521e39d9805 SHA256 fd93a3d95e7e23e22ea7bb26c008588d3974f4141a9a36fc6fee242c9004d99e SHA512 d82c65e009a275a28809ee92511c95aca0a7a0ef8d614f2f469aeb9454a4a5f431ef743d77b2942336cd830e0fdcb49b9acf1cd20d26619cfae1de67c615c9b5 Ssdeep 192:+rxTuNrg80JEjG7dFG+3gkn/F6XvAIaW0AdeUZW+Qt1YSNqkE:+rh780J7dFl3jn/F6XknUw+Qt1YSE3 Yara 无匹配 VirusTotal 搜索相关分析 36-151120192930A7[1].jpg 文件名 相关文件 36-151120192930A7[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-151120192930A7[1].jpg 文件大小 8584 bytes 文件类型 JPEG image data, EXIF standard MD5 e64a7de928317cb5439c6148b717a473 SHA1 d5ff3449673eee7fc13d0dc90ae86c855cf7729e SHA256 42f93efaf826556a1c21d27006cea0630644c846cf1adf6f1dadb75ba2772ced SHA512 c8d3560ad8dc51d65661d04e5024749c7dfa6e7eee77f4c6e4cf3aa727ed7dba2f66c3eaf9f139858bed052ec247eb3c7c168d8ec58ff3c7b1b54958a8c057e2 Ssdeep 192:+QdA7CUsvF1qDapv9ED1MdXlsvUPqZV8MROkn:+Rst0Opv9EEBPq7fROkn Yara 无匹配 VirusTotal 搜索相关分析 36-1602241G24W19[1].jpg 文件名 相关文件 36-1602241G24W19[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-1602241G24W19[1].jpg 文件大小 4372 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 0f772d9e189d88a01fb50dea4d41b919 SHA1 843e8be21a5e7cd55cc4f3d2e49a521ec84f1fca SHA256 e8a35588489dc3f71ac26b520aa5adcfa3e4122801f0c56767fb10237e7d718c SHA512 ca8af142a11811744d9a8dfd089e09a1a5acc75a6f566f5da1dded39110f8c63c752929c4e0b2d80015e4357081e7828013a1699530724e31b52206de1a37a36 Ssdeep 96:uUYpKMZVGzYW+MFkGrdymQioxg7+Q3d19br7TEe:hYwMvGz5+lA4mQC+Qn9brP Yara 无匹配 VirusTotal 搜索相关分析 c[1].php 文件名 相关文件 c[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\c[1].php 文件大小 9939 bytes 文件类型 ASCII text, with very long lines MD5 ad60be8443a86391c92ada38400e44fb SHA1 7cfd9c8be7373a77e3befa64b85206bf3355ceda SHA256 0c8d426de96c0561c11352e68ec8fd38b57163959b1796a8b4e5d780252f58c4 SHA512 b63e10ff35d52a202aca1c2d28ca95438963872df0f881ee274b53fc5ff0d0bda157ab4210d85fc5794df12c16c4957283aa13a73466dab365d9621fbb2d9b85 Ssdeep 192:wFxhYGCO5emuSsxf5m1mbi4s5pHx8ooBDeaJXg8lEkWwB9rP1VkCAt:wFxhYGCO1uphs1kxOahA8CUn7kCAt Yara 无匹配 VirusTotal 搜索相关分析 index.dat 文件名 相关文件 index.dat C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat 文件大小 32768 bytes 文件类型 Internet Explorer cache file version Ver 5.2 MD5 4ffea093c3af20dabbacf6161358baad SHA1 859253e2120d80ac3355a51ede74c85a98f8ecf3 SHA256 51088f8aaece09f902213b6b975678b82c69eb51fb55fdd6fde7bc0a0cc64d69 SHA512 d930f1cf81fc5fc606fe66aa40c054a828539804af1a507f6c6e002778df5fa598025db5998203599ee48dac71558c5247505255f7fba867f8f355b7404c199b Ssdeep 24:qjZ50goWHbIYFJaVLkjAW9H2czx2FskLYjaejMXVroNsR4DYxnU9I0dJaezLrMXO:qVaBggPyaEMXVt4D/IuasMXVGuasMXV Yara 无匹配 VirusTotal 搜索相关分析 36-160413111950-50[1].jpg 文件名 相关文件 36-160413111950-50[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-160413111950-50[1].jpg 文件大小 6350 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 a98010a61bdb4147011522e3e86ecc76 SHA1 7ca6cb3496c48ad796f78b2b07b30572d24659d5 SHA256 c3ca2e757b0c86e8b16ff08d688a51a1289308139cd8f13d906daca9e1ff62b6 SHA512 8cc422156a8ffdcc083e54af8b4b337b3aff05c65534afac0ad1409bca48f99d2c68c97c4b2f5ea1d88ce40cb9b2fdc80560806d1544148c628465aba81c8d2e Ssdeep 192:lOvGdvZ2x1GOiU7NP1dKqWGxRYDjqbsHo:lOvAvZ01IUB+qxwqAo Yara 无匹配 VirusTotal 搜索相关分析 36-151120200433543[1].jpg 文件名 相关文件 36-151120200433543[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-151120200433543[1].jpg 文件大小 7958 bytes 文件类型 JPEG image data, EXIF standard MD5 77ddf1743265fa5718cf5938c19dbf38 SHA1 781d0da89119ed2eae39020c266c1b387f994577 SHA256 8e93acd35f64a0938521e580881aba17314ed0f52da02a51ef2f2dcf36f42040 SHA512 44c6cb94483fdcc34fa41967330919bb189226ec0e13928da5241ca3042f6e447f20fe0a8ec048ee60b32add255d965b42977c89700cb5397db9336548e694eb Ssdeep 192:+0hcx0zOzKBGDTrVtk5InAOzf5G/FzlrNXPZ18OoluU8:+Ocx0zOzKkTr0LE5GJlrNT85luU8 Yara 无匹配 VirusTotal 搜索相关分析 70-1605091Q35cW[1].jpg 文件名 相关文件 70-1605091Q35cW[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\70-1605091Q35cW[1].jpg 文件大小 9573 bytes 文件类型 JPEG image data, EXIF standard MD5 e96b5fc99fb0d7634a72c415284be9c0 SHA1 f655ed284b013e3b2bab34fee91ebb523b31deeb SHA256 e9e9187b03fb0a0cb14677e219cf7e274d2c443b2d2aa900afdeaf39b383c6b7 SHA512 3b1864c24fd5fad4083091359f93b87c00f643dbbd5565e487cd1308623e9110366d4c15b67f1c96568e87a4011242b3deb460e9b662828f4091ac9b43244c13 Ssdeep 192:u9qPbg1p+e99cdOWM0onyLdxTef5mEGjFww2a7vZbMDv:Vbg1Ie9coyRpefwjSw2aUv Yara 无匹配 VirusTotal 搜索相关分析 36-151120194210628[1].jpg 文件名 相关文件 36-151120194210628[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-151120194210628[1].jpg 文件大小 8904 bytes 文件类型 JPEG image data, EXIF standard MD5 5c617458e8bdbba2c99caeb56e54ed8c SHA1 597b21b81781e6b60aef1f43127219f7e11a2a27 SHA256 4a1728eb3daaa52b94d2afd41197f6615d4e4939da4cd0a2a130a3ee7086797f SHA512 f2b9b84bbeda207400ddc3af0f571df1f11463135ddb267b2d2f9dbac9547b58abf2068cebca09529785255adc0c073cc214a6f8577f449165ef0342f0cd0cc1 Ssdeep 192:+PkcLgWrwoRKp4+RYSnBW34a5R+yeupNm0WfEtdBt3:+Pn8WMoR64+RYSBIOyeupNm0WfEtdBt3 Yara 无匹配 VirusTotal 搜索相关分析 d3j[1].gif 文件名 相关文件 d3j[1].gif C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\d3j[1].gif 文件大小 1099 bytes 文件类型 GIF image data, version 89a, 6 x 3 MD5 03ba9d8001fa4f196fe4874eaa8a7268 SHA1 34c27946455e97ea0489337d00a77db7e36dfa2d SHA256 0001e2cf90d0cd1332830fd562c5bdc8f69c9f2c5abfd81e66e934b9e68fd655 SHA512 a3097111b41146af06d90c23224c1a85c97fbafb570d207af6683fbacc15d25afe59a09a2aaa17e7465a9eb79df28a58d8c3e72b3b40423a0e73e9fbba744912 Ssdeep 24:cal1he91Wwjx82lY2T3ouV+ND7bgyJ3V+HObv+MGY8dE:NqQNn2xAdXjJ3Au2ML8dE Yara 无匹配 VirusTotal 搜索相关分析 cov_70[1].png 文件名 相关文件 cov_70[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\cov_70[1].png 文件大小 933 bytes 文件类型 PNG image data, 2 x 2, 8-bit/color RGBA, non-interlaced MD5 2e6898d6bc9cf210ae880e46230179d2 SHA1 32be01ad9f1fdbbad058231a3c0f31e41d84e56e SHA256 190ec773545215fb69dc0a4d01f48c575088858ca1df91dabf683ad9e7741584 SHA512 27dd5af5ac0dc9b5c4b767512ac24c20f4ca8418ffe680a5b6e20f4179b9a45d7b6f94ae2d88b8b0cfe3a7744c7223b72a5f0f3b4cf2457d74f23820202c7172 Ssdeep 24:TBZ1hiyWwjx82lY2T37VxLgohQoZyJ3Vx72oM+oWGAFc:luNn2vb9f4J3LjkW5Fc Yara 无匹配 VirusTotal 搜索相关分析 ico_search[1].png 文件名 相关文件 ico_search[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\ico_search[1].png 文件大小 786 bytes 文件类型 PNG image data, 38 x 20, 8-bit colormap, non-interlaced MD5 5c669f4921a272c211cdb15a8f6ee1a5 SHA1 ca5041084d037e5c957a2d7946820afdcad65214 SHA256 5c911e0761e3865c878e7d1eeb5cd8dc641a4a61128c43c3975aa5b5251d0bf3 SHA512 45cac6e1238f83e72db2d4016294226c67b0c5606ce5d614d3e50e6c0a0fa6ee74cacd702a866bd2e8446063ea21741ff7b5ac9b759d7fd759102cf788d6a0bc Ssdeep 12:6v/72tvWU5llJZq/W3DHIDsheLSyJWPLFbnrWndO8P9mOcF7:BhT7XZq/WTHIDCcJWPLFbrc167 Yara 无匹配 VirusTotal 搜索相关分析 test@18183[1].txt 文件名 相关文件 test@18183[1].txt C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\test@18183[1].txt 文件大小 109 bytes 文件类型 ASCII text MD5 1ae7b50c7dbcda053a6cb24ea51390dc SHA1 8d7522bb1e452e606a01d4c104e3c17cebba8c70 SHA256 f2e1dc3d1e665cbb474fc4640b35851066c05153e3ea67fd34f9b54dd73aaaec SHA512 d78a723f129705e3163ea84b8db920306b956a09778ecabd482b96df23c8598765d793f397264cdb93ebc804e7a744e1e97daccab7462d42841a37ba3e1913a7 Ssdeep 3:lotjGwPI0ZUQNc9UZItVdt8gVvmiWXUDWvM5l:l2Q0ZvGUWVd6QWEDWol Yara 无匹配 VirusTotal 搜索相关分析 70-1605091QI23D[1].jpg 文件名 相关文件 70-1605091QI23D[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\70-1605091QI23D[1].jpg 文件大小 8657 bytes 文件类型 JPEG image data, EXIF standard MD5 ff5f7efeb7c3d82e90d3b57e9bfa6e0f SHA1 6e1e3948844ac00667b334a368f8763c3f32f40a SHA256 2598fe02a115f6f0c6e352232852a9329c6bb2d3a7ff0b099ba3a68d113247d2 SHA512 e29dc43e391655a0d19c886318fe4eb2ccde2ae6987010c9fbecd3a3fcba73c5bf0d838acaddb029304d4f6fef4d57cfdccaec5c6713d8653c654ba046f3e6e1 Ssdeep 192:ZGE81MdH6IMybuU4EcSYzUYukUtnWVTvUhOV7Hd:E1IMTRLF6eUhu Yara 无匹配 VirusTotal 搜索相关分析 36-1511211552160-L[1].jpg 文件名 相关文件 36-1511211552160-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-1511211552160-L[1].jpg 文件大小 1692 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 8e2edb9a36442c3f67de2e158e480a35 SHA1 3a59b787d7dbb063f2b6f25e44bfa25265a7f6b5 SHA256 323e0d36cdf1d8c1cddc3daed6ad7e94f36e8a9a7276d07b9d2c0d442a4f7435 SHA512 966d5ec0134ff0d2e2b282db6bca70ffede7d285d8b6175bab1a45803102f66790880298757c12ab8343256286ee23fc4859cddefc43862b82086596c3a579ea Ssdeep 48:0Dc7fu24K3ZbbaMmobLMU7ipPJVqdgvnP:N7EQMU7O3qevnP Yara 无匹配 VirusTotal 搜索相关分析 main[1].js 文件名 相关文件 main[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\main[1].js 文件大小 19439 bytes 文件类型 UTF-8 Unicode text, with very long lines, with CRLF line terminators MD5 373bd656d7a0c65603c6f548aee7dfe0 SHA1 1d7891f5ebad18e7262fdd02eecc80831c2ca9e7 SHA256 7925770feb9f554f8090f302d5d84fe6f7e4653f1320d3fefedc63230bb9c4f8 SHA512 9936160f9e27d5560bac7b724c0c603e500983bdf4215d4bb15d7f49bb98f5f68d6af18f6aa6d6f5dfbe53d60d8af24fe9c9d5781c4c16049f7e557057274c72 Ssdeep 384:bP3ewTYUm1WTsyQU73mzBgl13NN+8MhPvuqEs78b8zwIeq5uEKCE1t:bP3O1WlQU73mzBgl13NN+HPoIePt Yara 无匹配 VirusTotal 搜索相关分析 MSIMGSIZ.DAT 文件名 相关文件 MSIMGSIZ.DAT C:\Users\test\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT 文件大小 16384 bytes 文件类型 FoxPro FPT, blocks size 0, next free block index 401590474 MD5 cfe540059abdf983fa3979eb2dd1f869 SHA1 2ccf7e469f22d62f9d16fbdcf53e0331c10944b6 SHA256 30ca66a282088d9de70a8499758d7e869ae1fd5fad110f8920ede58c86f7b580 SHA512 bcd98b9765250876964b91e487f286251cd100d0a3978138659849e3898a12057ea4ef3486f79545ebe567848738df425deec602d0bf2d33d5a3e5d6c2b7826c Ssdeep 12:qluRieZEt+4q01WtnDP/EWXSPUrtFRi6RsxaUPxtq3dHUS3/ZF2Et5G421j/14l7:qlUoL8+5E3BFcd++zXkMN1v+D Yara 无匹配 VirusTotal 搜索相关分析 36-1512151332240-L[1].jpg 文件名 相关文件 36-1512151332240-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-1512151332240-L[1].jpg 文件大小 4256 bytes 文件类型 JPEG image data, JFIF standard 1.02 MD5 b875c51c6691f4bdff66a631dd7ee6d5 SHA1 51946055189eaf1447c7878e663bacd73cd42cd4 SHA256 037d786982d4798f508ce5fdee1da86b65a247a336f5a7633705d88ae2f9556e SHA512 b1e34a57dc4679ee16d6c6949ce7994a7cd9d3a7148446118f4968cc04a6ef9a1f091febd572a64b094cecabdf11dc4950f47bad55fc14fbd97add87b850aa4d Ssdeep 96:DdWImQ9t6K8fQ7iaxCmTB802ZHgLFfpLLrj7XKURBHTbPag:SCk9fQ7PxRSxaFfpLH6oHT+g Yara 无匹配 VirusTotal 搜索相关分析 base[1].php 文件名 相关文件 base[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\base[1].php 文件大小 8209 bytes 文件类型 HTML document, UTF-8 Unicode text, with very long lines MD5 5916bc1a79c87fe9e1d6b626919f07f4 SHA1 9364d4afdc58e15f80c6d1755249389f44b77f7b SHA256 3026588406384478c0477c573a68199e1cfa3b32335b56e3e22a0aa8c51df19f SHA512 a930ab6a30830ed6ef4dbdd1cb992351451c03f096bbc7d32ab34e9b76c015b1cb287970cea321a9f9d4e62d1a1f46ea5c96fac6832a1660a508951e46176d08 Ssdeep 96:ZqlgSXs2ldXnlNXUl6XxvKJk0qy9ux7i/i5G1M1aXbAdNwHKylj4qslGXbyMTptK:Qdc2333kUBLf5Gml/yVWELHb+LmM Yara 无匹配 VirusTotal 搜索相关分析 36-15112020242M52[1].jpg 文件名 相关文件 36-15112020242M52[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-15112020242M52[1].jpg 文件大小 8994 bytes 文件类型 JPEG image data, EXIF standard MD5 38e87d0f787ecc3c5fcd57d3dd6fb07e SHA1 91001264733b0d0858dc0f17fd9bad389a1f115d SHA256 afb8b08dcabf1492454b5b802f16d0259227acc5934d757bfee5ea0c63e491fc SHA512 98ff1a063c3e694e7f71349da7ce09bf44a5ee8dea1d429856a0c04b5e001d0d362f7c79c87e97356253ad578c1d77e3a96add541bd98f8a606d7826e4ca9f9b Ssdeep 192:+Dem8PBODjLj7sQoFqc9+AsEddJXuxxrSisR5eBE:+amCODXY35ducjN Yara 无匹配 VirusTotal 搜索相关分析 3jj[1].gif 文件名 相关文件 3jj[1].gif C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\3jj[1].gif 文件大小 1099 bytes 文件类型 GIF image data, version 89a, 6 x 3 MD5 73aec5e7e287766087b39e82676890e7 SHA1 a9d148cb1d6adfdf19fe90499de97340f18228e3 SHA256 f013e6390288b8b6ea61091fd2d1a87fc1e4fcd255b2d30aacbe6212153b4973 SHA512 0458431c08b58e65e46022021a72c8b10e67d8e9c7c7ee005ef4edd852777c429c8dace76756fe21daed7b0ffaabf1815af6362e86c0878af854a7e5ced60638 Ssdeep 24:cal1he91Wwjx82lY2T3ouVAo4KyJ3VuRqRvPGY8V:NqQNn2xQJ3rL8V Yara 无匹配 VirusTotal 搜索相关分析 B912B2C6928A18B8CD7D50CF08BEA95B_7F0B9652162FC5018915AD9167E5C64E 文件名 相关文件 B912B2C6928A18B8CD7D50CF08BEA95B_7F0B9652162FC5018915AD9167E5C64E C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B912B2C6928A18B8CD7D50CF08BEA95B_7F0B9652162FC5018915AD9167E5C64E 文件大小 1757 bytes 文件类型 data MD5 80fcbb123ac46341fb355a1ac2944055 SHA1 74d8ac4f595eec239d0ebfac459c9c74c25853e9 SHA256 57967ad02d4114335a1c514e3710eaa1100c6f4fb2ae6dfde2e84e99bc71d100 SHA512 408e5f690172f15364b236803fa9fb9563d236838cafd46efe98078f6da36d73fc2fcc8881256841e5211c4816013f55c51dd91dc29a36677ad94757edd0a932 Ssdeep 48:RC0eowZlE1j1WnGmDuDeqQ/dMZhQ5R6AbVeOLdwLW:tJwZm1kG5DeqEdMZhahL4W Yara 无匹配 VirusTotal 搜索相关分析 appdwn[2].png 文件名 相关文件 appdwn[2].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\appdwn[2].png 文件大小 27275 bytes 文件类型 PNG image data, 284 x 563, 8-bit/color RGBA, non-interlaced MD5 1b1b47612e1a05fed86827b2b6ec7a16 SHA1 debd4c703a1d25e71eec0dbaf33011cbce31a0bb SHA256 5dbbff4d0125b342ad874f87bff563c11d74f467241dba1a5144fd4ce944c2a1 SHA512 d02b977acb65f20f702147fb15c44c848ae924f012e71552a7043a7ec747d2ebe1d8073e1b42bcd658b4621c054f948141cad8c47d5490ba02fa0d8c4a9191a3 Ssdeep 768:vqUrJ0ONZ+MtjoViXb+pRgIDX25G6+pO/yR7uH:v5fNZ7tjoVKb+Pg225GLpWg6 Yara 无匹配 VirusTotal 搜索相关分析 70-1605091Q034W6[1].jpg 文件名 相关文件 70-1605091Q034W6[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\70-1605091Q034W6[1].jpg 文件大小 9044 bytes 文件类型 JPEG image data, EXIF standard MD5 8a6b99d3d32be72aefe5575571a3226c SHA1 f098a355ee533066f832922ea72ad123b38e06be SHA256 2e16ab3800bc5bbedd66fc279c5b0aa397aa20b17aef7095e98e999d600e8704 SHA512 7a05dfecdae228bcbcfc289b2e4073ce765d624c13d57a2d8bafd8fd03d40d54915057e4cb1a12c488f8ef2780a2b22bcb8440106585881d1629c52be9b80bfd Ssdeep 192:k/E3oD2bsJebPMFHMDU2LsOapPYl/D2HNeaYPv1Uwyis+0xH:cSM1hpP0SN0Kb7 Yara 无匹配 VirusTotal 搜索相关分析 36-15112019112M25[1].jpg 文件名 相关文件 36-15112019112M25[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-15112019112M25[1].jpg 文件大小 8862 bytes 文件类型 JPEG image data, EXIF standard MD5 caae5fe3ea273b74d7b3110fff1b5a33 SHA1 b9a0d30b982251ed3d8f039b0b3e78a69fec85b2 SHA256 dea14b85fb3adcaca8bf9196ee3781737a62f57835656e1274faf2a88d0c5c90 SHA512 836e4f78fde0436f0823ec74136cd1c47abf6f544d463c7f8c5c2516bec54109dd1c900501079445c968b35b903b1f00cfcead2a46f1ba33b46c57c97df730bf Ssdeep 192:+WOYrJXHh7xUxkgQ2yED8wpBciRGsz0i6cRlgdRi488FqDU5jzwJW:+1YrNHh+kgQbMcirz0i6cRidw4Cg5jz7 Yara 无匹配 VirusTotal 搜索相关分析 行为分析 互斥量(Mutexes) IESQMMUTEX_0_208 Local\ZonesCounterMutex Local\MSCTF.Asm.MutexDefault1 Local\!IETld!Mutex Local\c:!users!test!appdata!local!microsoft!feeds cache! Local\ZoneAttributeCacheCounterMutex Local\ZonesCacheCounterMutex Local\ZonesLockedCacheCounterMutex Local\!BrowserEmulation!SharedMemory!Mutex Local\!IECompat!Mutex Local\c:!users!test!appdata!roaming!microsoft!windows!iecompatcache! ConnHashTable<2432>_HashTable_Mutex Local\WininetStartupMutex Global\ARM Update Mutex Global\Acro Update Mutex Groove:PathMutex:huJZ0a1oPtB4yGzDQW9lw0niEfg= Groove.Mutex.WebServices.Status Groove.Mutex.SystemServices.Lock Groove:PathMutex:v1n9odwmzLTGaaFW7PZysBRMqq8= SmartScreen_UrsCacheMutex_2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2High_S-1-5-21-2280033686-3172497658-3481507381-1000 SmartScreen_ClientId_Mutex Local\c:!users!test!appdata!roaming!microsoft!windows!privacie! Local\c:!users!test!appdata!roaming!microsoft!windows!ietldcache! Local\http://www.18183.com/ Local\c:!users!test!appdata!local!microsoft!internet explorer!domstore! MSIMGSIZECacheMutex Local\InternetExplorerDOMStoreQuota DBWinMutex {1B655094-FE2A-433c-A877-FF9793445069} _!SHMSFTHISTORY!_ Local\c:!users!test!appdata!local!microsoft!windows!history!history.ie5!mshist012005111620051117! 执行的命令 无信息 创建的服务 无信息 启动的服务 无信息 进程 iexplore.exe PID: 2432, 上一级进程 PID: 2368 iexplore.exe PID: 2708, 上一级进程 PID: 2432 访问的文件 C:\Program Files (x86)\Internet Explorer\ieproxy.dll C:\ProgramData\Microsoft\Network\Connections\Pbk\rasphone.pbk C:\ProgramData\Microsoft\Network\Connections\Pbk\*.pbk C:\Windows\System32\ras\*.pbk C:\Users\test\AppData\Roaming\Microsoft\Network\Connections\Pbk\rasphone.pbk C:\Users\test\AppData\Roaming\Microsoft\Network\Connections\Pbk\*.pbk C:\Windows\Fonts\staticcache.dat C:\Windows\System32\url.dll C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{B75A4AC3-5660-11DA-8A10-52540043F29A}.dat C:\Users\test\AppData\Local\Temp\~DFB9EEE8EFE4719041.TMP C:\Windows\SysWOW64\ieframe.dll C:\Windows\SysWOW64\stdole2.tlb C:\ C:\Users C:\Users\test\AppData\Local\Microsoft\Windows\Caches C:\Users\test\AppData\Local\Microsoft\Windows\Caches\cversions.1.db C:\Users\test\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000003.db C:\Users\desktop.ini C:\Users\test C:\Users\test\Favorites C:\Users\test\Favorites\desktop.ini C:\Users\test\Desktop\desktop.ini C:\Windows\SysWOW64\propsys.dll C:\Windows\sysnative\propsys.dll C:\Users\test\AppData\Local\Microsoft\Internet Explorer\frameiconcache.dat C:\Users\test\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico C:\Program Files (x86)\Internet Explorer\url.dll C:\Users\test\Desktop\url.dll C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{B75A4AC4-5660-11DA-8A10-52540043F29A}.dat C:\Users\test\AppData\Local\Temp\~DF81B375A814B4210B.TMP \??\MountPointManager C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016012420160125\desktop.ini C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016012420160125\*.* C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\favicon[2].ico \Device\KsecDD C:\Windows\Globalization\Sorting\sortdefault.nls C:\Program Files (x86)\Internet Explorer\IEShims.dll C:\Windows\SysWOW64\shell32.dll C:\Program Files (x86)\Internet Explorer\sqmapi.dll C:\Users\test\AppData\Local\Microsoft\Feeds Cache\ C:\Users\test\AppData\Local\Microsoft\Feeds Cache\index.dat C:\Users\test\AppData\Local\Microsoft\Feeds Cache\desktop.ini \??\Nsi C:\Users\test\AppData\Roaming\Microsoft\Windows\IECompatCache\ C:\Users\test\AppData\Roaming\Microsoft\Windows\IECompatCache\index.dat C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL C:\Windows\AppPatch\sysmain.sdb C:\Program Files (x86)\Microsoft Office\Office14\ C:\Program Files (x86) C:\Program Files (x86)\Microsoft Office C:\Program Files (x86)\Microsoft Office\Office14 C:\Program Files (x86)\Microsoft Office\Office14\*.* C:\ProgramData C:\Users\test\AppData\Local C:\Users\test\AppData\Local\microsoft\Office\Groove\User\GFSConfig.xml C:\Users\test\AppData\Local\microsoft\Office\Groove\User\UnreadMarks.xml C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\566007[1].htm C:\Windows\WindowsShell.manifest C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\ C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat C:\Windows\sysnative\C_1256.NLS C:\Windows\sysnative\C_864.NLS C:\Windows\sysnative\C_708.NLS C:\Windows\sysnative\C_720.NLS C:\Windows\sysnative\C_28596.NLS C:\Windows\sysnative\C_10004.NLS C:\Windows\sysnative\C_1257.NLS C:\Windows\sysnative\C_775.NLS C:\Windows\sysnative\C_28594.NLS C:\Windows\sysnative\C_1250.NLS C:\Windows\sysnative\C_852.NLS C:\Windows\sysnative\C_28592.NLS C:\Windows\sysnative\C_10029.NLS C:\Windows\sysnative\C_G18030.DLL C:\Windows\sysnative\C_20936.NLS C:\Windows\sysnative\C_IS2022.DLL C:\Windows\sysnative\C_10008.NLS C:\Windows\sysnative\C_950.NLS C:\Windows\sysnative\C_20000.NLS C:\Windows\sysnative\C_20002.NLS C:\Windows\sysnative\C_10002.NLS C:\Windows\sysnative\C_10082.NLS C:\Windows\sysnative\C_1251.NLS C:\Windows\sysnative\C_866.NLS C:\Windows\sysnative\C_28595.NLS C:\Windows\sysnative\C_20866.NLS C:\Windows\sysnative\C_21866.NLS C:\Windows\sysnative\C_10007.NLS C:\Windows\sysnative\c_28603.nls C:\Windows\sysnative\C_21027.NLS C:\Windows\sysnative\C_863.NLS C:\Windows\sysnative\C_20106.NLS C:\Windows\sysnative\C_1253.NLS C:\Windows\sysnative\C_737.NLS C:\Windows\sysnative\C_28597.NLS C:\Windows\sysnative\C_10006.NLS C:\Windows\sysnative\C_869.NLS C:\Windows\sysnative\C_1255.NLS C:\Windows\sysnative\C_862.NLS C:\Windows\sysnative\C_28598.NLS C:\Windows\sysnative\C_10005.NLS C:\Windows\sysnative\C_20003.NLS C:\Windows\sysnative\C_20420.NLS C:\Windows\sysnative\C_20880.NLS C:\Windows\sysnative\C_21025.NLS C:\Windows\sysnative\C_20277.NLS C:\Windows\sysnative\C_1142.NLS C:\Windows\sysnative\C_20278.NLS C:\Windows\sysnative\C_1143.NLS C:\Windows\sysnative\C_20297.NLS C:\Windows\sysnative\C_1147.NLS C:\Windows\sysnative\C_20273.NLS C:\Windows\sysnative\C_1141.NLS C:\Windows\sysnative\C_20423.NLS C:\Windows\sysnative\C_875.NLS C:\Windows\sysnative\C_20424.NLS C:\Windows\sysnative\C_20871.NLS C:\Windows\sysnative\C_1149.NLS C:\Windows\sysnative\C_500.NLS C:\Windows\sysnative\C_1148.NLS C:\Windows\sysnative\C_20280.NLS C:\Windows\sysnative\C_1144.NLS C:\Windows\sysnative\C_932.NLS C:\Windows\sysnative\C_20290.NLS C:\Windows\sysnative\C_949.NLS C:\Windows\sysnative\C_20833.NLS C:\Windows\sysnative\C_870.NLS C:\Windows\sysnative\C_20284.NLS C:\Windows\sysnative\C_1145.NLS C:\Windows\sysnative\C_874.NLS C:\Windows\sysnative\C_20838.NLS C:\Windows\sysnative\C_1254.NLS C:\Windows\sysnative\C_20905.NLS C:\Windows\sysnative\C_1026.NLS C:\Windows\sysnative\C_20285.NLS C:\Windows\sysnative\C_1146.NLS C:\Windows\sysnative\C_037.NLS C:\Windows\sysnative\C_1140.NLS C:\Windows\sysnative\C_1047.NLS C:\Windows\sysnative\C_20924.NLS C:\Windows\sysnative\C_861.NLS C:\Windows\sysnative\C_10079.NLS C:\Windows\sysnative\C_ISCII.DLL C:\Windows\sysnative\C_20269.NLS C:\Windows\sysnative\C_20932.NLS C:\Windows\sysnative\C_10001.NLS C:\Windows\sysnative\C_20949.NLS C:\Windows\sysnative\C_1361.NLS C:\Windows\sysnative\C_10003.NLS C:\Windows\sysnative\C_28593.NLS C:\Windows\sysnative\C_28605.NLS C:\Windows\sysnative\C_865.NLS C:\Windows\sysnative\C_20108.NLS C:\Windows\sysnative\C_855.NLS C:\Windows\sysnative\C_437.NLS C:\Windows\sysnative\C_858.NLS C:\Windows\sysnative\C_860.NLS C:\Windows\sysnative\C_10010.NLS C:\Windows\sysnative\C_20107.NLS C:\Windows\sysnative\C_20261.NLS C:\Windows\sysnative\C_20001.NLS C:\Windows\sysnative\C_20004.NLS C:\Windows\sysnative\C_10021.NLS C:\Windows\sysnative\C_857.NLS C:\Windows\sysnative\C_28599.NLS C:\Windows\sysnative\C_10081.NLS C:\Windows\sysnative\C_10017.NLS C:\Windows\sysnative\C_1258.NLS C:\Windows\sysnative\C_20005.NLS C:\Windows\sysnative\C_850.NLS C:\Windows\sysnative\C_20105.NLS C:\Windows\sysnative\C_28591.NLS C:\Windows\sysnative\C_10000.NLS C:\Windows\System32\en-US\MLANG.dll.mui C:\Windows\System32\ieapfltr.dat \Device\RasAcd C:\Users\test\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\* C:\Users\test\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\* C:\Users\test\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\* C:\Windows\System32\p2pcollab.dll C:\Windows\System32\qagentrt.dll C:\Windows\System32\dnsapi.dll C:\Users\test\AppData\LocalLow C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40E450F7CE13419A2CCC2A5445035A0A_* C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B912B2C6928A18B8CD7D50CF08BEA95B_* C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B912B2C6928A18B8CD7D50CF08BEA95B_7F0B9652162FC5018915AD9167E5C64E C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\jquery-1.8.3.min[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\base[1].css C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\arc[1].css C:\Users\test\AppData\Roaming\Microsoft\Windows\PrivacIE C:\Users\test\AppData\Roaming\Microsoft\Windows\PrivacIE\ C:\Users\test\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\top_toolbar[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\bg_body[1].jpg C:\Users\test\AppData\Roaming\Microsoft\Windows\IETldCache\ C:\Users\test\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\maruko[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\3jj[1].gif C:\Users\test\AppData\Local\Microsoft\Internet Explorer\DOMStore\ C:\Users\test\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat C:\Users\test\AppData\Local\Microsoft\Internet Explorer\DOMStore\YEE0B1V8\www.18183[1].xml C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\appdwn[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\appdwn[2].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\ico-toptoolbar[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\js[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\base[1].php C:\Users\test\AppData\Local\Microsoft C:\Users\test\AppData\Local\Microsoft\Internet Explorer C:\Users\test\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\bg_close[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-1602241G24W19[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\14628768855622[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\14544096519373[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\all_tl_bg[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\X[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\70-1604051055461D[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-1605061121090-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\bg_header_02[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-16042GR033[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\bg_header_xz[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-15112020242M52[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151120195921355[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151120194JVJ[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\14629365731420[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\cov_70[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\cov_v[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\ico_search[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\bg_info_line_01[1].png C:\Program Files (x86)\Internet Explorer\iexplore.exe.Local\ C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80 C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\bg_info_tab[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-151120195233R1[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\14448186091968[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\bottom_toolbar[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-160114113125[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-1511301159450-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-151210163I00-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-15112020062D41[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\1445842259_324[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\cov_60[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\bg_bzrd_links[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\bg_info_hero_01[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-15112019493X13[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\blank[1].gif C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\ico_arc[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-160413111H5[1].jpg C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\test@baidu[2].txt C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-1512101636260-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\icons[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-160413111950[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-1511211552160-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\bg_header_01[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\bg_header_bbs[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\cov_50[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-151120192621D6[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\gt[1].gif C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-15112019202XQ[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-1512151332240-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-15112020104Q94[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\70-1605101IZ1C2[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-151120200433543[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-151120194210628[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-15112019242YD[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\70-1605091Q034W6[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\70-16040510545QP[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-151120195156428[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-1511202033120-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-160413111951[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-151120194430346[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-160413111950-50[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-15112019553I60[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-15120G55434631[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-1511201ZI43Q[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-151120192K5F6[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-15112020143OT[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-151120201334B1[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-15112020032R46[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-151120195T5292[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\70-1605091QI23D[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-151120200029251[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-151120192120620[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151120201150Z9[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-160510155JK05[1].jpg C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B912B2C6928A18B8CD7D50CF08BEA95B_7F0B9652162FC5018915AD9167E5C64E C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-15112020021X28[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151120200ST33[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151124143I80-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151120202200192[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-1601131916294W[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\70-1605091Q35cW[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-151120192930A7[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-160413112314[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-15112019112M25[1].jpg C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAEDF689AA6DC9642B833051B2B77D1A C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\h[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\c[1].php C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\test@18183[1].txt C:\Windows\SysWOW64\mshtml.tlb C:\Windows\SysWOW64\Macromed\Flash\ss.sgn C:\Windows\SysWOW64\Macromed\Flash\ss.cfg C:\Windows\SysWOW64\Macromed\Flash\mms.cfg C:\Windows\SysWOW64\Macromed\Flash\oem.cfg C:\Windows\SysWOW64\oem.cfg C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache C:\Users\test\AppData\Local\Temp\ C:\Users\test\AppData C:\Users\test\AppData\Local\Temp C:\Users\test\AppData\Roaming\Adobe\FLASH PLAYER\NATIVECACHE\ C:\Users\test\AppData\Roaming\Adobe\FLASH PLAYER\ C:\Users\test\AppData\Roaming\Adobe\ C:\Users\test\AppData\Roaming\ C:\Users\test\AppData\ C:\Users\test\ C:\Users\ C:\Users\test\AppData\Roaming C:\Users\test\AppData\Roaming\Adobe C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\NativeCache.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\94D901CE4AD8BABEF1A9F51A72BF8CE8.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\D19A124A63BC3E484EE0CC12F63FFE86\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\14FE212574D1C626E7D9F8D9E261A62B\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\58D75590E211D1B0C26C176059D52D75\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\DE89D1447AB1E99DD87F51CA87C52655\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\9DCB33E1CFD76DD078ED1898ECBAEFEE\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\668D0A067F2436E1D58EA37A2D7DAF2E\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\396B667C011CF74AFE66D655E875014B\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\7FCDFC8C65295F95F1B2B94C4B4AC6BF\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\BF4BB2C7EE96F73EC15D03471A3C7190\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\24FB7F8BF29F9D5B1BA5F5BD986D6BDB\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\27B164FB036E31553875E83C0CEADD7C\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\E5617A3A2E52B334393316C9AF28E65D\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\74C6CC968D46AD77ED26CD2279AFAD4A\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\5E1695CF661F2AC6997BB8E3D81DF826\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\53C2449AF5289A3021851A926C9292AE\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\2B9A81C6A66630E584CDC25504552597\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\46ED9160074E9FE80B68B8F4635E1E1F\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\7624407C79FD148BD154961B5C878D06\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\52A424DE7FAAAC541C1DDDCE9E5AB317\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\915E84FE7E8929AA0AF1E491D8AA8669\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\A0B83912A1953D21B712724637B8789A\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\824E0FF07F7744CEBFDAF4FF92BE9E8F\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\63241689DE8DD5590FBBFA84AD7D116C\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\5F01BA1496F8B8F767931AACBF93267B\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\340EE80BB6C2BDC03A237663EA24C806\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\B8A777454276EE030F7A5FF3F6E693DC\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\AssetCache C:\Users\test\AppData\Roaming\Adobe\Flash Player\AssetCache\* C:\Users\test\.telemetry.cfg C:\Users\test\telemetry.cfg C:\Windows\SysWOW64\Macromed\Flash\activex.vch C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAEDF689AA6DC9642B833051B2B77D1A C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 C:\Users\test\AppData\Local\Temp\Cab4049.tmp C:\Users\test\AppData\Local\Temp\Tar404A.tmp C:\Users\test\Desktop\Cab4049.tmp C:\Windows\inf\ C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Windows\System32\mshtml.tlb C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\core[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\main[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\stat[1].gif C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\c[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\c[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\core[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\stat[1].gif C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\test@mmstat[1].txt C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\core[1].php C:\Users\test\AppData\Local\Microsoft\Windows\History\desktop.ini C:\Users\test\AppData\Local\Microsoft\Windows C:\Users\test\AppData\Local\Microsoft\Windows\History C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016012420160125\index.dat C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016012420160125\ C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012005111620051117\ C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012005111620051117\index.dat C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\stat[1].gif C:\Windows\System32\shell32.dll C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\favicon[1].ico C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Program Files (x86)\Internet Explorer\imageres.dll C:\Windows\System32\imageres.dll C:\Windows\System32\zh-CN\imageres.dll.mui C:\Windows\sysnative\zh-CN\imageres.dll.mui C:\Windows\System32\zh-Hans\imageres.dll.mui C:\Windows\System32\zh\imageres.dll.mui C:\Windows\System32\en-US\imageres.dll.mui C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_zh-cn_b7a33d2d3f47b7fb C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_zh-cn_b7a33d2d3f47b7fb\comctl32.dll.mui C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\test@cnzz[1].txt C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\bg_header_03[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\bg_info_hero_02[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\d3j[1].gif 读取的文件 C:\Program Files (x86)\Internet Explorer\ieproxy.dll C:\Windows\Fonts\staticcache.dat C:\Windows\System32\url.dll C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{B75A4AC3-5660-11DA-8A10-52540043F29A}.dat C:\Users\test\AppData\Local\Temp\~DFB9EEE8EFE4719041.TMP C:\Windows\SysWOW64\ieframe.dll C:\Windows\SysWOW64\stdole2.tlb C:\ C:\Users\test\AppData\Local\Microsoft\Windows\Caches\cversions.1.db C:\Users\test\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000003.db C:\Users\desktop.ini C:\Users C:\Users\test C:\Users\test\Favorites\desktop.ini C:\Users\test\Desktop\desktop.ini C:\Users\test\AppData\Local\Microsoft\Internet Explorer\frameiconcache.dat C:\Users\test\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{B75A4AC4-5660-11DA-8A10-52540043F29A}.dat C:\Users\test\AppData\Local\Temp\~DF81B375A814B4210B.TMP C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\favicon[2].ico \Device\KsecDD C:\Windows\Globalization\Sorting\sortdefault.nls C:\Program Files (x86)\Internet Explorer\IEShims.dll C:\Windows\SysWOW64\shell32.dll C:\Program Files (x86)\Internet Explorer\sqmapi.dll C:\Users\test\AppData\Local\Microsoft\Feeds Cache\index.dat C:\Users\test\AppData\Roaming\Microsoft\Windows\IECompatCache\index.dat C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL C:\Windows\AppPatch\sysmain.sdb C:\Program Files (x86)\Microsoft Office\Office14\ C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL C:\Windows\WindowsShell.manifest C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat C:\Windows\System32\en-US\MLANG.dll.mui C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\566007[1].htm C:\Windows\System32\ieapfltr.dat \Device\RasAcd C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B912B2C6928A18B8CD7D50CF08BEA95B_7F0B9652162FC5018915AD9167E5C64E C:\Users\test\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\arc[1].css C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\base[1].css C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\jquery-1.8.3.min[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\top_toolbar[1].js C:\Users\test\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\maruko[1].js C:\Users\test\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat C:\Users\test\AppData\Local\Microsoft\Internet Explorer\DOMStore\YEE0B1V8\www.18183[1].xml C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\js[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\base[1].php C:\Users\test\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\bottom_toolbar[1].js C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\test@baidu[2].txt C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B912B2C6928A18B8CD7D50CF08BEA95B_7F0B9652162FC5018915AD9167E5C64E C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAEDF689AA6DC9642B833051B2B77D1A C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\h[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\c[1].php C:\Windows\SysWOW64\mshtml.tlb C:\Windows\SysWOW64\Macromed\Flash\mms.cfg C:\Windows\SysWOW64\Macromed\Flash\oem.cfg C:\Windows\SysWOW64\oem.cfg C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\94D901CE4AD8BABEF1A9F51A72BF8CE8.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\NativeCache.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\D19A124A63BC3E484EE0CC12F63FFE86\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\14FE212574D1C626E7D9F8D9E261A62B\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\58D75590E211D1B0C26C176059D52D75\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\DE89D1447AB1E99DD87F51CA87C52655\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\9DCB33E1CFD76DD078ED1898ECBAEFEE\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\668D0A067F2436E1D58EA37A2D7DAF2E\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\396B667C011CF74AFE66D655E875014B\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\7FCDFC8C65295F95F1B2B94C4B4AC6BF\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\BF4BB2C7EE96F73EC15D03471A3C7190\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\24FB7F8BF29F9D5B1BA5F5BD986D6BDB\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\27B164FB036E31553875E83C0CEADD7C\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\E5617A3A2E52B334393316C9AF28E65D\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\74C6CC968D46AD77ED26CD2279AFAD4A\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\5E1695CF661F2AC6997BB8E3D81DF826\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\53C2449AF5289A3021851A926C9292AE\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\2B9A81C6A66630E584CDC25504552597\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\46ED9160074E9FE80B68B8F4635E1E1F\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\7624407C79FD148BD154961B5C878D06\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\52A424DE7FAAAC541C1DDDCE9E5AB317\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\915E84FE7E8929AA0AF1E491D8AA8669\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\A0B83912A1953D21B712724637B8789A\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\824E0FF07F7744CEBFDAF4FF92BE9E8F\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\63241689DE8DD5590FBBFA84AD7D116C\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\5F01BA1496F8B8F767931AACBF93267B\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\340EE80BB6C2BDC03A237663EA24C806\Info.directory C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\B8A777454276EE030F7A5FF3F6E693DC\Info.directory C:\Users\test\.telemetry.cfg C:\Users\test\telemetry.cfg C:\Windows\SysWOW64\Macromed\Flash\activex.vch C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAEDF689AA6DC9642B833051B2B77D1A C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 C:\Users\test\AppData\Local\Temp\Cab4049.tmp C:\Users\test\AppData\Local\Temp\Tar404A.tmp C:\Windows\System32\mshtml.tlb C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\core[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\main[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\c[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\c[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\core[1].php C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\test@mmstat[1].txt C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\core[1].php C:\Users\test\AppData C:\Users\test\AppData\Local C:\Users\test\AppData\Local\Microsoft C:\Users\test\AppData\Local\Microsoft\Windows C:\Users\test\AppData\Local\Microsoft\Windows\History\desktop.ini C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012005111620051117\index.dat C:\Windows\System32\shell32.dll C:\Windows\System32\imageres.dll C:\Windows\System32\zh-CN\imageres.dll.mui C:\Windows\sysnative\zh-CN\imageres.dll.mui C:\Windows\System32\zh-Hans\imageres.dll.mui C:\Windows\System32\zh\imageres.dll.mui C:\Windows\System32\en-US\imageres.dll.mui C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_zh-cn_b7a33d2d3f47b7fb\comctl32.dll.mui 修改的文件 C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{B75A4AC3-5660-11DA-8A10-52540043F29A}.dat C:\Users\test\AppData\Local\Temp\~DFB9EEE8EFE4719041.TMP C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{B75A4AC4-5660-11DA-8A10-52540043F29A}.dat C:\Users\test\AppData\Local\Temp\~DF81B375A814B4210B.TMP C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\test\AppData\Local\Microsoft\Feeds Cache\index.dat C:\Users\test\AppData\Roaming\Microsoft\Windows\IECompatCache\index.dat C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\566007[1].htm C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat \Device\RasAcd C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\jquery-1.8.3.min[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\base[1].css C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\arc[1].css C:\Users\test\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\top_toolbar[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\bg_body[1].jpg C:\Users\test\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\maruko[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\3jj[1].gif C:\Users\test\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat C:\Users\test\AppData\Local\Microsoft\Internet Explorer\DOMStore\YEE0B1V8\www.18183[1].xml C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\appdwn[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\appdwn[2].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\ico-toptoolbar[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\js[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\base[1].php C:\Users\test\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\bg_close[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-1602241G24W19[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\14628768855622[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\14544096519373[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\all_tl_bg[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\X[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\70-1604051055461D[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-1605061121090-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\bg_header_02[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-16042GR033[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\bg_header_xz[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-15112020242M52[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151120195921355[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151120194JVJ[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\14629365731420[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\cov_70[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\cov_v[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\ico_search[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\bg_info_line_01[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\bg_info_tab[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-151120195233R1[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\14448186091968[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\bottom_toolbar[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-160114113125[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-1511301159450-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-151210163I00-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-15112020062D41[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\1445842259_324[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\cov_60[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\bg_bzrd_links[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\bg_info_hero_01[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-15112019493X13[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\blank[1].gif C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\ico_arc[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-160413111H5[1].jpg C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-1512101636260-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\icons[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-160413111950[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-1511211552160-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\bg_header_01[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\bg_header_bbs[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\cov_50[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-151120192621D6[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\gt[1].gif C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-15112019202XQ[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-1512151332240-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-15112020104Q94[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\70-1605101IZ1C2[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-151120200433543[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-151120194210628[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-15112019242YD[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\70-1605091Q034W6[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\70-16040510545QP[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-151120195156428[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-1511202033120-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-160413111951[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-151120194430346[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-160413111950-50[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-15112019553I60[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-15120G55434631[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-1511201ZI43Q[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-151120192K5F6[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-15112020143OT[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-151120201334B1[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-15112020032R46[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-151120195T5292[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\70-1605091QI23D[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-151120200029251[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\36-151120192120620[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151120201150Z9[1].jpg C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B912B2C6928A18B8CD7D50CF08BEA95B_7F0B9652162FC5018915AD9167E5C64E C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B912B2C6928A18B8CD7D50CF08BEA95B_7F0B9652162FC5018915AD9167E5C64E C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-160510155JK05[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-15112020021X28[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151120200ST33[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151124143I80-L[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-151120202200192[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-1601131916294W[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\70-1605091Q35cW[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\36-151120192930A7[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\36-160413112314[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\36-15112019112M25[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\h[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\c[1].php C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\test@18183[1].txt C:\Users\test\AppData\Roaming\Adobe\Flash Player\NativeCache\NativeCache.directory C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAEDF689AA6DC9642B833051B2B77D1A C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAEDF689AA6DC9642B833051B2B77D1A C:\Users\test\AppData\Local\Temp\Cab4049.tmp C:\Users\test\AppData\Local\Temp\Tar404A.tmp C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\test\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\core[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\main[1].js C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\stat[1].gif C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\c[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\c[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\core[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ADSMJH\stat[1].gif C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\core[1].php C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012005111620051117\index.dat C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\stat[1].gif C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\favicon[1].ico C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\favicon[2].ico C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\test@cnzz[1].txt C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TAGI4AC\bg_header_03[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGQJCUPQ\bg_info_hero_02[1].png C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\d3j[1].gif 删除的文件 C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\js[1].php C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\base[1].php C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\test\AppData\Local\Temp\Cab4049.tmp C:\Users\test\AppData\Local\Temp\Tar404A.tmp C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016012420160125\index.dat C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016012420160125\ 注册表键 HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname HKEY_CURRENT_USER\Software\Classes HKEY_CURRENT_USER\Software\Classes\Interface\{1AC7516E-E6BB-4A69-B63F-E841904DC5A6} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1AC7516E-E6BB-4A69-B63F-E841904DC5A6}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1AC7516E-E6BB-4A69-B63F-E841904DC5A6}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InProcServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InprocHandler HKEY_CURRENT_USER\Software\Classes\Interface\{26656EAA-54EB-4E6F-8F85-4F0EF901A406} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{55272A00-42CB-11CE-8135-00AA004BB851} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{55272A00-42CB-11CE-8135-00AA004BB851}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{55272A00-42CB-11CE-8135-00AA004BB851}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocHandler HKEY_CURRENT_USER\Software\Classes\Interface\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{2A1C9EB2-DF62-4154-B800-63278FCB8037} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5B678A52-EAE8-4CE7-983B-7984CC409A1F} HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5B678A52-EAE8-4CE7-983B-7984CC409A1F}\WpadDecision HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5B678A52-EAE8-4CE7-983B-7984CC409A1F}\WpadDecisionTime HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5B678A52-EAE8-4CE7-983B-7984CC409A1F}\WpadDecisionReason HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5B678A52-EAE8-4CE7-983B-7984CC409A1F}\fe-54-00-43-f2-9a HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\fe-54-00-43-f2-9a HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\WpadLastNetwork HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000\ProfileImagePath HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings HKEY_CURRENT_USER\Software\Classes\Interface\{7673B35E-907A-449D-A49F-E5CE47F0B0B2} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{7673B35E-907A-449D-A49F-E5CE47F0B0B2}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{7673B35E-907A-449D-A49F-E5CE47F0B0B2}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\Groups HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\TabbedBrowsing HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch\EnabledScopes HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Feeds HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Feeds HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Search HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Search\CurrentVersion HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\\xe5\xbe\xae\xe8\xbd\xaf\xe9\x9b\x85\xe9\xbb\x91 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Security HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Security\DisableSecuritySettingsCheck HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0 HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0 HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\DisableFixSecuritySettings HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Security\DisableFixSecuritySettings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1000 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1000 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\1000 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\1000 HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Zones HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\SecuritySafe HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Placement HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ITBar7Position HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FullScreen HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\IE8RunOnceLastShown HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\IEAK HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\IEAK HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CommandBar HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CommandBar\SmallIcons HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\CommandBar HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CommandBar\ShowLeftAddressToolbar HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CommandBar\ShowCompatibilityViewButton HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\UseIE7AutoComplete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001 HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\alipay.com HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\alisoft.com HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\taobao.com HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\\xe5\xbe\xae\xe8\xbd\xaf\xe9\x9b\x85\xe9\xbb\x91 HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SearchControlWidth HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SearchMigrated HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SearchMigratedInstalled HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SearchMigratedDefaultName HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\provider HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\DefaultScope HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\Deleted HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\URL HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\DisplayName HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ShowSearchSuggestions HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ShowSearchSuggestions HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\ShowSearchSuggestionsGlobal HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\ShowSearchSuggestionsGlobal HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURL_JSON HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURL_JSON HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURL_JSONFallback HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURL_JSONFallback HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURL HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURLFallback HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\PreviewURL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\PreviewURL HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\PreviewURLFallback HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\PreviewURLFallback HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\FaviconURL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\FaviconURL HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\FaviconURLFallback HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\FaviconPath HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\Codepage HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\Codepage HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SortIndex HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\Enabled HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Locked HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CommandBar\TextOption HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CommandBar\CommandBarEnabled HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\Enabled HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CommandBar\FavBandRow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\ActivityMeterTimerInterval HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\ActivityMeterDisable HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\QuickTabsThreshold HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksExplorer HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\LinksExplorer HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\ThumbnailBehavior HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ITBar7Height HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\iexplore.exe HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3FC47A08-E5C9-4BCA-A2C7-BC9A282AED14}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_CURRENT_USER HKEY_CURRENT_USER\Keyboard Layout\Toggle HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Min_Width HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Min_Height HKEY_CURRENT_USER\Software\Classes\CLSID\{0002DF01-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0002DF01-0000-0000-C000-000000000046}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0002DF01-0000-0000-C000-000000000046}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0002DF01-0000-0000-C000-000000000046}\ProgID\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0002DF01-0000-0000-C000-000000000046}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0002DF01-0000-0000-C000-000000000046}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0002DF01-0000-0000-C000-000000000046}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0002DF01-0000-0000-C000-000000000046}\InprocHandler HKEY_CURRENT_USER\Software\Classes\CLSID\{D5E8041D-920F-45E9-B8FB-B1DEB82C6E5E} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D5E8041D-920F-45E9-B8FB-B1DEB82C6E5E}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D5E8041D-920F-45E9-B8FB-B1DEB82C6E5E}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D5E8041D-920F-45E9-B8FB-B1DEB82C6E5E}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D5E8041D-920F-45E9-B8FB-B1DEB82C6E5E}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D5E8041D-920F-45E9-B8FB-B1DEB82C6E5E}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D5E8041D-920F-45E9-B8FB-B1DEB82C6E5E}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D5E8041D-920F-45E9-B8FB-B1DEB82C6E5E}\InprocHandler HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\IEDevTools HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameTabWindow HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FrameTabWindow HKEY_CURRENT_USER\Software\Classes\Interface\{9EC704BA-E1D4-45C5-9B59-BFAE07D9F04E} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9EC704BA-E1D4-45C5-9B59-BFAE07D9F04E}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9EC704BA-E1D4-45C5-9B59-BFAE07D9F04E}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{B40C43F1-F039-44D2-AEB7-87F5AF8ABC3D} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B40C43F1-F039-44D2-AEB7-87F5AF8ABC3D}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B40C43F1-F039-44D2-AEB7-87F5AF8ABC3D}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{D358F4E1-0465-4965-9DD5-CAE303D2C345} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D358F4E1-0465-4965-9DD5-CAE303D2C345}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D358F4E1-0465-4965-9DD5-CAE303D2C345}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{F704B7E0-4760-46FF-BBDB-7439E0A2A814} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F704B7E0-4760-46FF-BBDB-7439E0A2A814}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F704B7E0-4760-46FF-BBDB-7439E0A2A814}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\DefaultAuthLevel HKEY_CURRENT_USER\Software\Classes\Interface\{00020400-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00020400-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00020400-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\CLSID\{00020420-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020420-0000-0000-C000-000000000046}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020420-0000-0000-C000-000000000046}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020420-0000-0000-C000-000000000046}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020420-0000-0000-C000-000000000046}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020420-0000-0000-C000-000000000046}\InprocHandler HKEY_CURRENT_USER\Software\Classes\Interface\{D30C1661-CDAF-11D0-8A3E-00C04FC9E26E} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D30C1661-CDAF-11D0-8A3E-00C04FC9E26E}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D30C1661-CDAF-11D0-8A3E-00C04FC9E26E}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020424-0000-0000-C000-000000000046}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020424-0000-0000-C000-000000000046}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020424-0000-0000-C000-000000000046}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020424-0000-0000-C000-000000000046}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020424-0000-0000-C000-000000000046}\InprocHandler HKEY_CURRENT_USER\Software\Classes\Interface\{D30C1661-CDAF-11D0-8A3E-00C04FC9E26E}\ProxyStubClsid32 HKEY_CURRENT_USER\Software\Classes\Interface\{D30C1661-CDAF-11D0-8A3E-00C04FC9E26E}\Forward HKEY_CURRENT_USER\Software\Classes\Interface\{D30C1661-CDAF-11D0-8A3E-00C04FC9E26E}\TypeLib HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D30C1661-CDAF-11D0-8A3E-00C04FC9E26E}\TypeLib\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D30C1661-CDAF-11D0-8A3E-00C04FC9E26E}\TypeLib\Version HKEY_CURRENT_USER\Software\Classes\TypeLib\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\1.1 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\1.1\0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\1.1\0\win32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\1.1\0\win32\(Default) HKEY_CURRENT_USER\Software\Classes\TypeLib HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\UDTAlignmentPolicy HKEY_CURRENT_USER\Software\Classes\Interface\{48A98A1F-5CDD-47EE-9286-DB04A3EB7CE1} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{48A98A1F-5CDD-47EE-9286-DB04A3EB7CE1}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{48A98A1F-5CDD-47EE-9286-DB04A3EB7CE1}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{6D5140C1-7436-11CE-8034-00AA006009FA} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6D5140C1-7436-11CE-8034-00AA006009FA}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6D5140C1-7436-11CE-8034-00AA006009FA}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{B722BCCB-4E68-101B-A2BC-00AA00404770} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B722BCCB-4E68-101B-A2BC-00AA00404770}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B722BCCB-4E68-101B-A2BC-00AA00404770}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Explorer HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Directory\OpenWithProgids HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory HKEY_CLASSES_ROOT\Directory HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\CurVer HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ShellEx\IconHandler HKEY_CLASSES_ROOT\Folder HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\IconHandler HKEY_CLASSES_ROOT\AllFilesystemObjects HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\IconHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\Clsid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\Clsid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\Clsid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PropertyBag HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\InitFolderHandler HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PropertyBag HKEY_CLASSES_ROOT\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\CallForAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\RestrictedAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsFORDISPLAY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HideFolderVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\UseDropHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsFORPARSING HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsParseDisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\QueryForOverlay HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\MapNetDriveVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\QueryForInfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HideInWebView HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HideOnDesktopPerUser HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsAliasedNotifications HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsUniversalDelegate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\NoFileFolderJunction HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\PinToNameSpaceTree HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HasNavigationEnum HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{59031A47-3F72-44A7-89C5-5595FE6B30EE} HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Use FormSuggest HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\Use FormSuggest HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\QuickTabsLastUsed HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore\Type HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CaretBrowsing HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CaretBrowsing\EnableOnStartup HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\CaretBrowsing HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Suggested Sites HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Suggested Sites\MigrationTime HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Migration HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Migration\IE Installed Date HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\IE8RunOncePerInstallCompleted HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\IE8RunOnceCompletionTime HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Check_Associations HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\Check_Associations HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo\ShowIconsCommand HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo\IconsVisible HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Capabilities\FileAssociations HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications\Internet Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Capabilities HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\FileAssociations HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\FileAssociations\.mht HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\FileAssociations\.html HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\FileAssociations\.htm HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\FileAssociations\.url HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\FileAssociations\.mhtml HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice\Progid HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Capabilities\UrlAssociations HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\URLAssociations HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\UrlAssociations\https HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\UrlAssociations\ftp HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\UrlAssociations\http HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice\Progid HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Capabilities\MIMEAssociations HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\MIMEAssociations HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\MIMEAssociations\message/rfc822 HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\message/rfc822\UserChoice HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\message/rfc822\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\MIMEAssociations\text/html HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\text/html\UserChoice HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\text/html\UserChoice\Progid HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Suggested Sites\Enabled HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Suggested Sites\ObjectsCreated HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Suggested Sites\SlicePath HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch\Version HKEY_CURRENT_USER\Software\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF50} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF50}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF50}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch\ConfiguredScopes HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch\User Favorites Path HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch\UpgradeTime HKEY_CURRENT_USER\Software\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF55} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF55}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF55}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF52} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF52}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF52}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{04C18CCF-1F57-4CBD-88CC-3900F5195CE3} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{04C18CCF-1F57-4CBD-88CC-3900F5195CE3}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{04C18CCF-1F57-4CBD-88CC-3900F5195CE3}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{B5702E61-E75C-4B64-82A1-6CB4F832FCCF} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B5702E61-E75C-4B64-82A1-6CB4F832FCCF}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B5702E61-E75C-4B64-82A1-6CB4F832FCCF}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF58} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF58}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF58}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\Version HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\UpgradeTime HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences\2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences\88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977 HKEY_CURRENT_USER\Control Panel\Desktop HKEY_CURRENT_USER\Control Panel\Desktop\SmoothScroll HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewAlphaSelect HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewShadow HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\DEPOff HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLESAFESEARCHPATH_KB963027 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ENABLESAFESEARCHPATH_KB963027 HKEY_LOCAL_MACHINE\Software\Policies HKEY_CURRENT_USER\Software\Policies HKEY_CURRENT_USER\Software HKEY_LOCAL_MACHINE\Software HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Low Rights\ProtectedModeOffForAllZones HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\TabProcGrowth HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\TabProcGrowth HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Low Rights\LuaOffLoRIEOn HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameMerging HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FrameMerging HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SessionMerging HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\SessionMerging HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\AdminTabProcs HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\AdminTabProcs HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\CompatibilityFlags HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\DetourDialogs HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\New Windows HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\AcRedir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\iexplore.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\TabShutdownDelay HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\TabShutdownDelay HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SQM HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SQM\ServerFreezeOnUpload HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SQM HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InitFolderHandler HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PropertyBag HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Favorites HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D} HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InitFolderHandler HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InitFolderHandler HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PropertyBag HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InitFolderHandler HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PropertyBag HKEY_CURRENT_USER\Software\Classes\AppID\iexplore.exe HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\74DD1FC8 HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\iexplore.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE\DontUseDesktopChangeRouter HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\EnablePreBinding HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\CallForAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\RestrictedAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsFORDISPLAY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideFolderVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\UseDropHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsFORPARSING HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsParseDisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\QueryForOverlay HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\MapNetDriveVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\QueryForInfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideInWebView HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideOnDesktopPerUser HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsAliasedNotifications HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsUniversalDelegate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\NoFileFolderJunction HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\PinToNameSpaceTree HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HasNavigationEnum HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{871C5380-42A0-1069-A2EA-08002B30309D} HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32\LoadWithoutCOM HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\AppCompat HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{871c5380-42a0-1069-a2ea-08002b30309d}\InProcServer32 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{871C5380-42A0-1069-A2EA-08002B30309D} {000214E6-0000-0000-C000-000000000046} 0xFFFF HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{871C5380-42A0-1069-A2EA-08002B30309D} HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionHigh HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionHigh HKEY_LOCAL_MACHINE\Software\Microsoft\Feeds HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Feeds\UrlCacheVersion HKEY_CURRENT_USER\Software\Classes\PROTOCOLS\Name-Space Handler\ HKEY_LOCAL_MACHINE\Software\Classes\PROTOCOLS\Name-Space Handler HKEY_CURRENT_USER\Software\Classes\PROTOCOLS\Name-Space Handler HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_FAILED_CONNECT_CONTENT_KB942615 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_SHOW_FAILED_CONNECT_CONTENT_KB942615 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\UrlEncoding HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MIME_HANDLING HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MIME_HANDLING\iexplore.exe HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\ HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\http\ HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\*\ HKEY_LOCAL_MACHINE\Software\Microsoft\Ole HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\Feature_Enable_Compat_Logging HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\Feature_Enable_Compat_Logging HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Compatible HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Compatible HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Version HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Version HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\UA Tokens HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Pre Platform HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Pre Platform HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Pre Platform HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Platform HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Platform HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iexplore_RASMANCS HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASMANCS\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASMANCS\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASMANCS\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASMANCS\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASMANCS\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASMANCS\FileDirectory HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASAPI32\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASAPI32\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASAPI32\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASAPI32\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASAPI32\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASAPI32\FileDirectory HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER\* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER\* HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\UrlMon Settings HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915 HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_UNC_SAVEDFILECHECK HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_UNC_SAVEDFILECHECK\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_UNC_SAVEDFILECHECK\* HKEY_LOCAL_MACHINE\System\Setup HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\iexplore.exe HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\* HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\iexplore.exe HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\ HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0 HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0 HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1 HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1 HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2 HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2 HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3 HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3 HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4 HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4 HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\Location Awareness HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSock2\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\WinSock_Registry_Version HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\AutodialDLL HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableUTF8 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\AcceptLanguage HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\AllSitesCompatibilityMode HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\BrowserEmulation HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\IntranetCompatibilityMode HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\MSCompatibilityMode HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\IECompatVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\IECompatVersionHigh HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\WpadExpirationDays HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\ClearableListData HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\UnattendLoaded HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION\* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFileMenu HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window Title HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\StatusBarWeb HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Enable Browser Extensions HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A10 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoBandCustomize HKEY_CURRENT_USER\Software\AppDataLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\DontShowMeThisDialogAgain HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PageSetup HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Passport\LowDAMap HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\LowRegistry HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Zoom HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\LowMic HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\LowMic HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ITBar7Layout HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\AlwaysShowMenus HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\AlwaysShowMenus HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Marlett HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ADDON_MANAGEMENT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ADDON_MANAGEMENT\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ADDON_MANAGEMENT\* HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Ext HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Ext HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{18DF081C-E8AD-4283-A596-FA578C2EBDC3} HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\Flags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{18DF081C-E8AD-4283-A596-FA578C2EBDC3} HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{18df081c-e8ad-4283-a596-fa578c2ebdc3}\InProcServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\InprocServer32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\AcroIEHelperShim.dll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{18DF081C-E8AD-4283-A596-FA578C2EBDC3} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Type HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Count HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Time HKEY_CLASSES_ROOT\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\InprocServer32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\LoadTime HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\Flags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{72853161-30c5-4d22-b7f9-0bbc1d38a37e}\InProcServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\InprocServer32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\GROOVEEX.DLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\Type HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\Count HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\Time HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Groove HKEY_CURRENT_USER\SOFTWARE\Groove Networks, Inc.\Groove HKEY_LOCAL_MACHINE\SOFTWARE\Groove Networks, Inc.\Groove HKEY_LOCAL_MACHINE\SOFTWARE\Groove.OldData HKEY_CURRENT_USER\SOFTWARE\Groove.OldData HKEY_LOCAL_MACHINE\Software\Microsoft\Office\14.0\Groove\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InitFolderHandler HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PropertyBag HKEY_LOCAL_MACHINE\Software\Microsoft\Office\14.0\Groove HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 001 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Offload HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\LoadTime HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{B4F3A835-0E21-4959-BA22-42B3008E02FF} HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\Flags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{B4F3A835-0E21-4959-BA22-42B3008E02FF} HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{b4f3a835-0e21-4959-ba22-42b3008e02ff}\InProcServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\URLREDIR.DLL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\14.0\Groove\InstallRoot\Path HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{B4F3A835-0E21-4959-BA22-42B3008E02FF} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore\Type HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore\Count HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore\Time HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore\LoadTime HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5F226421-415D-408D-9A09-0DCD94E25B48} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5F226421-415D-408D-9A09-0DCD94E25B48}\1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5F226421-415D-408D-9A09-0DCD94E25B48}\1.0\0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5F226421-415D-408D-9A09-0DCD94E25B48}\1.0\0\win32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5F226421-415D-408D-9A09-0DCD94E25B48}\1.0\0\win32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B} HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\OpenDirectlyInApp HKEY_CURRENT_USER\Software\Policies\Microsoft\Security HKEY_CURRENT_USER\Software\Microsoft\Security HKEY_CLASSES_ROOT\CLSID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04fb6bfc4} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InsecureQI HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common HKEY_CURRENT_USER\Software\Microsoft\Office\Common\AllowConsecutiveSlashesInUrlPathComponent HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\OptimisticBHO HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\Server Cache\ HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IEDDE_REGISTER_PROTOCOL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_IEDDE_REGISTER_PROTOCOL HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Safety\PrivacIE HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Safety\PrivacIE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_READ_ZONE_STRINGS_FROM_REGISTRY HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_READ_ZONE_STRINGS_FROM_REGISTRY HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\MinLevel HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\RecommendedLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\CurrentLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\Flags HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\MinLevel HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\RecommendedLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\CurrentLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\MinLevel HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\RecommendedLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\CurrentLevel HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\MinLevel HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\RecommendedLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\CurrentLevel HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\MinLevel HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\RecommendedLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\CurrentLevel HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\MediaTypeClass HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Accepted Documents HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Ratings HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\No3DBorder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\No3DBorder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\UrlEncoding HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\UrlEncoding HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\TabbedBrowsing HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Main HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\MenuUserExpanded HKEY_CLASSES_ROOT\MIME\Database\Content Type\text/html HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\text/html\Extension HKEY_CURRENT_USER\SOFTWARE\Classes\PROTOCOLS\Filter\text/html HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MIME_SNIFFING HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MIME_SNIFFING\iexplore.exe HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\iexplore.exe HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2100 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\IsTextPlainHonored HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_FEEDS HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_FEEDS\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_FEEDS\* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_SAFE_BINDTOOBJECT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\iexplore.exe HKEY_CURRENT_USER\Software\Classes\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\ProgID\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\InProcServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\InprocHandler HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollInset HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollInterval HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MANAGE_SCRIPT_CIRCULAR_REFS HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MANAGE_SCRIPT_CIRCULAR_REFS HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\* HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Security\Floppy Access HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\Adv AddrBar Spoof Detection HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Security\Adv AddrBar Spoof Detection HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\about\ HKEY_CURRENT_USER\SOFTWARE\Classes\PROTOCOLS\Handler\about HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\about HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\about\CLSID HKEY_CURRENT_USER\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InprocHandler HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2106 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Zoom\ZoomDisabled HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Zoom HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Zoom\ResetTextSizeOnStartup HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Zoom\ResetTextSizeOnZoom HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Zoom\ResetZoomOnStartup2 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Zoom\ZoomFactor HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter\EnabledV8 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2\UserFile HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IPERSISTMONIKER_LOAD_REDIRECTED_URL_KB976425 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_IPERSISTMONIKER_LOAD_REDIRECTED_URL_KB976425 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SmartDithering HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SmartDithering HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\RtfConverterFlags HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\UseClearType HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Page_Transitions HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\Page_Transitions HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Use_DlgBox_Colors HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Anchor Underline HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\CSS_Compat HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Expand Alt Text HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Display Inline Images HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Display Inline Videos HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\Display Inline Videos HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Play_Background_Sounds HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Play_Animations HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Print_Background HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\Print_Background HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Use Stylesheets HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SmoothScroll HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\SmoothScroll HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\XMLHTTP HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Show image placeholders HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\Show image placeholders HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Disable Script Debugger HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\DisableScriptDebuggerIE HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Move System Caret HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Force Offscreen Composition HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Enable AutoImageResize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\Enable AutoImageResize HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\UseThemes HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\UseHR HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Q300829 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Cleanup HTCs HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\XDomainRequest HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\XDomainRequest HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\DOMStorage HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\DOMStorage HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Default_CodePage HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\AutoDetect HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\Default_IEFontSizePrivate HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\International\Scripts HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Anchor Color HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Anchor Color Visited HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Anchor Color Hover HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Settings HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Always Use My Colors HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Always Use My Font Size HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Always Use My Font Face HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Disable Visited Hyperlinks HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Use Anchor Hover Color HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\MiscFlags HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles\Use My Stylesheet HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles\MaxScriptStatements HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Allow Programmatic Cut_Copy_Paste HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PageSetup\Print_Background HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\x8f\x91\xe9\x80\x81\xe8\x87\xb3 OneNote(&N) HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\x8f\x91\xe9\x80\x81\xe8\x87\xb3 OneNote(&N)\(Default) HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\x8f\x91\xe9\x80\x81\xe8\x87\xb3 OneNote(&N)\Flags HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\x8f\x91\xe9\x80\x81\xe8\x87\xb3 OneNote(&N)\Contexts HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\xaf\xbc\xe5\x87\xba\xe5\x88\xb0 Microsoft Excel(&X) HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\xaf\xbc\xe5\x87\xba\xe5\x88\xb0 Microsoft Excel(&X)\(Default) HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\xaf\xbc\xe5\x87\xba\xe5\x88\xb0 Microsoft Excel(&X)\Flags HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\xaf\xbc\xe5\x87\xba\xe5\x88\xb0 Microsoft Excel(&X)\Contexts HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\CodePage HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\950 HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Codepage HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1256 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\864 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\708 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\51256 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\720 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28596 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10004 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50001 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1257 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\775 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28594 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1250 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\852 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28592 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10029 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50936 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\51936 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\54936 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20936 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\52936 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50227 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10008 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50950 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20000 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20002 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50229 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10002 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10082 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1251 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\51251 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\866 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28595 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20866 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\21866 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10007 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28603 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\29001 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\21027 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\863 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20106 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1253 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\51253 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\737 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28597 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10006 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\869 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1255 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\862 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\38598 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28598 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10005 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20003 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20420 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20880 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\21025 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20277 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1142 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20278 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1143 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20297 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1147 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20273 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1141 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20423 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\875 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20424 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20871 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1149 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\500 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1148 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20280 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1144 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\932 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50930 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50939 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50931 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20290 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\949 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50933 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20833 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\870 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50935 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20284 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1145 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\874 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20838 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50937 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1254 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20905 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1026 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20285 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1146 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\37 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1140 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1047 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20924 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\861 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10079 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57006 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57003 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57002 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57010 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57008 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57009 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57007 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57011 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57004 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57005 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20269 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50932 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\51932 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50220 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20932 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50221 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50222 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10001 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50949 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\51949 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50225 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1361 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10003 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20949 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28593 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28605 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\865 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20108 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\855 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\437 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\858 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\860 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10010 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20107 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20261 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20001 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20004 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10021 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\857 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28599 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10081 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10017 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1201 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1258 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20005 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\850 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20105 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28591 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10000 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEFontSize HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEFontSizePrivate HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEPropFontName HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEFixedFontName HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Version Vector HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Version Vector\VML HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Version Vector\IE HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Version Vector\WindowsEdition HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ZONE_ELEVATION\iexplore.exe HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2700 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_XSSFILTER HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_XSSFILTER\iexplore.exe HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1409 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\NoProtectedModeBanner HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME\* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CONVERT_A3A0INGB2312 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_CONVERT_A3A0INGB2312 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2301 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DxTrans HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\DxTrans HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSize HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSizePrivate HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEPropFontName HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFixedFontName HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN\* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDITIONAL_IE8_MEMORY_CLEANUP HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ADDITIONAL_IE8_MEMORY_CLEANUP HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SecurityIdIUriCacheSize HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SecurityIdIUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SecurityIdIUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\SecurityIdIUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BEHAVIORS HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BEHAVIORS\iexplore.exe HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2000 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Default Behaviors HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Default Behaviors\discovery HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BINARY_CALLER_SERVICE_PROVIDER HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BINARY_CALLER_SERVICE_PROVIDER HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_SSLUX HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_SSLUX\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_SSLUX\* HKEY_CURRENT_USER\Software\Microsoft\AntiPhishing HKEY_CURRENT_USER\Software\Microsoft\AntiPhishing\i HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ HKEY_CURRENT_USER\Software\Classes\Interface\{9D973E3B-F610-4F03-83D3-AED90C3237AC} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9D973E3B-F610-4F03-83D3-AED90C3237AC}\SynchronousInterface HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9D973E3B-F610-4F03-83D3-AED90C3237AC}\SynchronousInterface\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Safety\PrivacIE HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_STATUS_BAR_THROTTLING HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_STATUS_BAR_THROTTLING HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IEDDE_REGISTER_URLECHO HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_IEDDE_REGISTER_URLECHO HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\GipActivityBypass HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Version HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\Schannel HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\MY\Certificates HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\MY\CRLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\MY\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllDecodeObjectEx HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4 HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000 HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\PhysicalStores HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\MY\ HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\MY\Keys HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\PhysicalStores HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\ HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\CRLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\CTLs HKEY_CURRENT_USER\ HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\Certificates HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\CRLs HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\475BA6DA2AFD5AE3ADAE78A261CA0E3E548B9532 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\475BA6DA2AFD5AE3ADAE78A261CA0E3E548B9532\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\CA HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPublisher\Safer HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\ HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\Certificates HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CRLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CTLs HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Disallowed HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\PhysicalStores HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\Certificates HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\CRLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\CTLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A7217F919843199C958C128449DD52D2723B0A8A HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A7217F919843199C958C128449DD52D2723B0A8A\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D85213E038F309D02A40917B59E142368AE6B1C0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D85213E038F309D02A40917B59E142368AE6B1C0\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\DBB84423C928ABE889D0E368FC3191D151DDB1AB HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\DBB84423C928ABE889D0E368FC3191D151DDB1AB\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\SmartCardRoot HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\ HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\ HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPeople HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\PhysicalStores HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\ HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\Certificates HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\CRLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\CTLs HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\Certificates HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\CRLs HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\trust HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7 HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\1a\AAF68885 HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\1A\AAF68885\LanguageList HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\1A\AAF68885\@%SystemRoot%\system32\p2pcollab.dll,-8042 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7 HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7 HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\1A\AAF68885\@%SystemRoot%\system32\dnsapi.dll,-103 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllVerifyEncodedSignature HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllVerifyEncodedSignature HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx2 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx2 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllVerifyRevocation HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyRevocation HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyRevocation\DEFAULT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\TimeValidDllGetObject HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\TimeValidDllGetObject HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\UrlDllGetObjectUrl HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\UrlDllGetObjectUrl HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetCachedOcspSwitchToCrlCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetMaxCachedOcspPerCrlCount HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllEncodeObjectEx HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.4 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugFlags HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318} HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\fe-54-00-43-f2-9a\WpadDecision HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\fe-54-00-43-f2-9a\WpadDecisionTime HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\fe-54-00-43-f2-9a\WpadDecisionReason HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableInetUnknownAuth HKEY_CURRENT_USER\Software\Microsoft\CTF\LayoutIcon\0804\00000804 HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/javascript HKEY_CLASSES_ROOT\MIME\Database\Content Type\text/css HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\text/css\Extension HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CUSTOM_IMAGE_MIME_TYPES_KB910561 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_CUSTOM_IMAGE_MIME_TYPES_KB910561 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016012420160125 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016012420160125\CachePath HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_Cross_Domain_Redirect_Mitigation HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_Cross_Domain_Redirect_Mitigation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1400 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_SCRIPTURL_MITIGATION HKEY_CLASSES_ROOT\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT\* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1201 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESPECT_OBJECTSAFETY_POLICY_KB905547 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_RESPECT_OBJECTSAFETY_POLICY_KB905547 HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\ActiveX Compatibility\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58} HKEY_LOCAL_MACHINE\Software\Microsoft\COM3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\COM+Enabled HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_INACTIVATE_MODE_REMOVAL_REVERT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ACTIVEX_INACTIVATE_MODE_REMOVAL_REVERT HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL\* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Recovery HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\160A HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XMLHTTP HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_XMLHTTP HKEY_CLASSES_ROOT\MIME\Database\Content Type\image/jpeg HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\image/jpeg\Extension HKEY_CLASSES_ROOT\MIME\Database\Content Type\image/gif HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\image/gif\Extension HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOMSTORAGE HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_DOMSTORAGE HKEY_CLASSES_ROOT\MIME\Database\Content Type\image/png HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\image/png\Extension HKEY_CURRENT_USER\Software\Classes\MIME\Database\Content Type\application/javascript HKEY_CURRENT_USER\Software\Classes\CLSID\{3050F285-98B5-11CF-BB82-00AA00BDCE0B} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F285-98B5-11CF-BB82-00AA00BDCE0B}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F285-98B5-11CF-BB82-00AA00BDCE0B}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F285-98B5-11CF-BB82-00AA00BDCE0B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F285-98B5-11CF-BB82-00AA00BDCE0B}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F285-98B5-11CF-BB82-00AA00BDCE0B}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F285-98B5-11CF-BB82-00AA00BDCE0B}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F285-98B5-11CF-BB82-00AA00BDCE0B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F285-98B5-11CF-BB82-00AA00BDCE0B}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F285-98B5-11CF-BB82-00AA00BDCE0B}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F285-98B5-11CF-BB82-00AA00BDCE0B}\ProgID HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_IMG HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_IMG\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_IMG\* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\MS PGothic HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\MaxRenderLine HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots HKEY_CURRENT_USER\Software\Classes\MIME\Database\Content Type\image/gif HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\18183.com HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total\(Default) HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\18183.com\(Default) HKEY_CURRENT_USER\Software\Classes\ShockwaveFlash.ShockwaveFlash HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash\CLSID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash\CLSID\(Default) HKEY_CURRENT_USER\Software\Classes\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ProgID\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\ActiveX Compatibility\{D27CDB6E-AE6D-11CF-96B8-444553540000} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\ActiveX Compatibility\{D27CDB6E-AE6D-11CF-96B8-444553540000}\Compatibility Flags HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\ActiveX Compatibility\{D27CDB6E-AE6D-11CF-96B8-444553540000}\MiscStatus Flags HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{D27CDB6E-AE6D-11CF-96B8-444553540000} HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D27CDB6E-AE6D-11CF-96B8-444553540000}\Flags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{D27CDB6E-AE6D-11CF-96B8-444553540000} HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION\* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1207 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOWEDDOMAINLIST HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ALLOWEDDOMAINLIST HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\120B HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1208 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore\Count HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore\Time HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1200 HKEY_CURRENT_USER\Software\Classes\Interface\{00020404-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00020404-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00020404-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\CLSID\{00020421-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020421-0000-0000-C000-000000000046}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020421-0000-0000-C000-000000000046}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020421-0000-0000-C000-000000000046}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020421-0000-0000-C000-000000000046}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020421-0000-0000-C000-000000000046}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020421-0000-0000-C000-000000000046}\InprocHandler HKEY_LOCAL_MACHINE\Hardware\Description\System\CentralProcessor\0 HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\~MHz HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\{10200490-FA38-11D0-AC0E-00A0C90FFFC0} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\{10200490-FA38-11D0-AC0E-00A0C90FFFC0} HKEY_CURRENT_USER\Software\Classes\CLSID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4} {D27CDB6E-AE6D-11CF-96B8-444553540000}\Required Categories\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1405 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchMinMaxAgeSeconds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchMaxMaxAgeSeconds HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\AuthRoot HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogMaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllVerifyCertificateChainPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyCertificateChainPolicy HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Escalation HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\WMR HKEY_CURRENT_USER\Software\Classes\BDEXIE.BDExExtension.1 HKEY_CURRENT_USER\Software\Classes\Interface\{3ED72303-6FFC-4214-BA90-FAF1862DEC8A} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3ED72303-6FFC-4214-BA90-FAF1862DEC8A}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3ED72303-6FFC-4214-BA90-FAF1862DEC8A}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{3050F69A-98B5-11CF-BB82-00AA00BDCE0B} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3050F69A-98B5-11CF-BB82-00AA00BDCE0B}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3050F69A-98B5-11CF-BB82-00AA00BDCE0B}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{3050F69A-98B5-11CF-BB82-00AA00BDCE0B}\ProxyStubClsid32 HKEY_CURRENT_USER\Software\Classes\Interface\{3050F69A-98B5-11CF-BB82-00AA00BDCE0B}\Forward HKEY_CURRENT_USER\Software\Classes\Interface\{3050F69A-98B5-11CF-BB82-00AA00BDCE0B}\TypeLib HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3050F69A-98B5-11CF-BB82-00AA00BDCE0B}\TypeLib\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3050F69A-98B5-11CF-BB82-00AA00BDCE0B}\TypeLib\Version HKEY_CURRENT_USER\Software\Classes\TypeLib\{3050F1C5-98B5-11CF-BB82-00AA00BDCE0B} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3050F1C5-98B5-11CF-BB82-00AA00BDCE0B}\4.0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3050F1C5-98B5-11CF-BB82-00AA00BDCE0B}\4.0\0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3050F1C5-98B5-11CF-BB82-00AA00BDCE0B}\4.0\0\win32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3050F1C5-98B5-11CF-BB82-00AA00BDCE0B}\4.0\0\win32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\Forward HKEY_CURRENT_USER\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\TypeLib HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\TypeLib\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\TypeLib\Version HKEY_CURRENT_USER\Software\Classes\Interface\{332C4427-26CB-11D0-B483-00C04FD90119} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{332C4427-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{332C4427-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{332C4427-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32 HKEY_CURRENT_USER\Software\Classes\Interface\{332C4427-26CB-11D0-B483-00C04FD90119}\Forward HKEY_CURRENT_USER\Software\Classes\Interface\{332C4427-26CB-11D0-B483-00C04FD90119}\TypeLib HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{332C4427-26CB-11D0-B483-00C04FD90119}\TypeLib\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{332C4427-26CB-11D0-B483-00C04FD90119}\TypeLib\Version HKEY_CURRENT_USER\Software\Classes\Interface\{3050F32D-98B5-11CF-BB82-00AA00BDCE0B} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3050F32D-98B5-11CF-BB82-00AA00BDCE0B}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3050F32D-98B5-11CF-BB82-00AA00BDCE0B}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{3050F32D-98B5-11CF-BB82-00AA00BDCE0B}\ProxyStubClsid32 HKEY_CURRENT_USER\Software\Classes\Interface\{3050F32D-98B5-11CF-BB82-00AA00BDCE0B}\Forward HKEY_CURRENT_USER\Software\Classes\Interface\{3050F32D-98B5-11CF-BB82-00AA00BDCE0B}\TypeLib HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3050F32D-98B5-11CF-BB82-00AA00BDCE0B}\TypeLib\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3050F32D-98B5-11CF-BB82-00AA00BDCE0B}\TypeLib\Version HKEY_CURRENT_USER\Software\Classes\Interface\{30510478-98B5-11CF-BB82-00AA00BDCE0B} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{30510478-98B5-11CF-BB82-00AA00BDCE0B}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{30510478-98B5-11CF-BB82-00AA00BDCE0B}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{30510478-98B5-11CF-BB82-00AA00BDCE0B}\ProxyStubClsid32 HKEY_CURRENT_USER\Software\Classes\Interface\{30510478-98B5-11CF-BB82-00AA00BDCE0B}\Forward HKEY_CURRENT_USER\Software\Classes\Interface\{30510478-98B5-11CF-BB82-00AA00BDCE0B}\TypeLib HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{30510478-98B5-11CF-BB82-00AA00BDCE0B}\TypeLib\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{30510478-98B5-11CF-BB82-00AA00BDCE0B}\TypeLib\Version HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\KindMap HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\.htm HKEY_CLASSES_ROOT\.htm HKEY_CURRENT_USER\Software\Classes\.htm\(Default) HKEY_CLASSES_ROOT\.htm\OpenWithProgids HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithProgids HKEY_CLASSES_ROOT\htmlfile HKEY_CLASSES_ROOT\IE.AssocFile.HTM HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IE.AssocFile.HTM\CurVer HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IE.AssocFile.HTM\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IE.AssocFile.HTM\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IE.AssocFile.HTM\NoStaticDefaultVerb HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IE.AssocFile.HTM\shell HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IE.AssocFile.HTM\shell\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IE.AssocFile.HTM\shell\opennew HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IE.AssocFile.HTM\shell\opennew\NeverDefault HKEY_CURRENT_USER\Software\Classes\IE.AssocFile.HTM HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IE.AssocFile.HTM\shell\edit HKEY_CLASSES_ROOT\.htm\OpenWithList HKEY_CLASSES_ROOT\Applications\Excel.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Excel.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Excel.exe\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Excel.exe\shell\edit HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Excel.exe\shell\edit\command HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Excel.exe\shell\edit\command\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Default HTML Editor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Default HTML Editor\Stubs HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Excel.Sheet\OpenWithProgids HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Excel.Sheet HKEY_CLASSES_ROOT\Excel.Sheet HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Excel.Sheet\CurVer HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Excel.Sheet\CurVer\(Default) HKEY_CLASSES_ROOT\Excel.Sheet.12 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Excel.Sheet.12\shell HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Excel.Sheet.12\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Excel.Sheet.12\NoStaticDefaultVerb HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Excel.Sheet.12\shell\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Excel.Sheet.12\shell\Open HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Excel.Sheet.12\shell\Open\NeverDefault HKEY_CURRENT_USER\Software\Classes\Excel.Sheet.12 HKEY_CLASSES_ROOT\Applications\Microsoft Excel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Excel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Excel\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Excel\shell\edit HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Excel\shell\edit\command HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Excel\shell\edit\command\(Default) HKEY_CLASSES_ROOT\Applications\Microsoft Publisher HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Publisher HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Publisher\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Publisher\shell\edit HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Publisher\shell\edit\command HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Publisher\shell\edit\command\(Default) HKEY_CLASSES_ROOT\Applications\Microsoft Word HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Word HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Word\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Word\shell\edit HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Word\shell\edit\command HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Word\shell\edit\command\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Word.Document\OpenWithProgids HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Word.Document HKEY_CLASSES_ROOT\Word.Document HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Document\CurVer HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Document\CurVer\(Default) HKEY_CLASSES_ROOT\Word.Document.12 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Document.12\shell HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Document.12\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Document.12\NoStaticDefaultVerb HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Document.12\shell\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Document.12\shell\Open HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Document.12\shell\Open\NeverDefault HKEY_CURRENT_USER\Software\Classes\Word.Document.12 HKEY_CLASSES_ROOT\Applications\MSPub.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\MSPub.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\MSPub.exe\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\MSPub.exe\shell\edit HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\MSPub.exe\shell\edit\command HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\MSPub.exe\shell\edit\command\(Default) HKEY_CLASSES_ROOT\Applications\notepad.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\notepad.exe\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\notepad.exe\shell\edit HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\notepad.exe\shell\edit\command HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\notepad.exe\shell\edit\command\(Default) HKEY_CLASSES_ROOT\Applications\WinWord.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\Winword.exe\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\Winword.exe\shell\edit HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\Winword.exe\shell\edit\command HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\Winword.exe\shell\edit\command\(Default) HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\CheckDocumentForProgID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\CheckDocumentForProgID HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Feed Discovery HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Feed Discovery HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Feed Discovery\Sound HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Feed Discovery HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Feed Discovery\Enabled HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Feed Discovery\ HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Feed Discovery\ HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Feeds HKEY_CURRENT_USER\Software\Microsoft\Ftp HKEY_CURRENT_USER\Software\Microsoft\FTP\Use Web Based FTP HKEY_LOCAL_MACHINE\Software\Microsoft\Ftp HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Services HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Services\SelectionActivityButtonDisable HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Services HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Activities HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Activities HKEY_CLASSES_ROOT\CLSID\{FF393560-C2A7-11CF-BFF4-444553540000} HKEY_CLASSES_ROOT\CLSID\{FF393560-C2A7-11CF-BFF4-444553540000}\InProcServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FF393560-C2A7-11CF-BFF4-444553540000}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FF393560-C2A7-11CF-BFF4-444553540000}\InProcServer32\LoadWithoutCOM HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{ff393560-c2a7-11cf-bff4-444553540000}\InProcServer32 HKEY_CLASSES_ROOT\CLSID\{FF393560-C2A7-11CF-BFF4-444553540000}\ShellFolder HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{FF393560-C2A7-11CF-BFF4-444553540000} {000214E6-0000-0000-C000-000000000046} 0xFFFF HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{FF393560-C2A7-11CF-BFF4-444553540000} HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016012420160125\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016012420160125\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016012420160125\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016012420160125\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D} HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\Desktop\NameSpace\NameCustomizations HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\LocalizedString HKEY_CURRENT_USER\Software\Classes\MIME\Database\Content Type\image/x-icon HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\image/x-icon\Extension HKEY_CURRENT_USER\SOFTWARE\Classes\PROTOCOLS\Filter\image/x-icon HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\image/x-icon HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_TREAT_IMAGE_AS_AUTHORITATIVE HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MIME_TREAT_IMAGE_AS_AUTHORITATIVE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2101 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter\ShownServiceDownBalloon HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\PhishingFilter HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\PhishingFilter\ShownServiceDownBalloon HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchProviders\ HKEY_CURRENT_USER\Software\Classes\MIME\Database\Content Type\image/jpeg HKEY_CURRENT_USER\Software\Classes\MIME\Database\Content Type\image/png 读取的注册表键 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1AC7516E-E6BB-4A69-B63F-E841904DC5A6}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InProcServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{55272A00-42CB-11CE-8135-00AA004BB851}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5B678A52-EAE8-4CE7-983B-7984CC409A1F}\WpadDecision HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5B678A52-EAE8-4CE7-983B-7984CC409A1F}\WpadDecisionTime HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5B678A52-EAE8-4CE7-983B-7984CC409A1F}\WpadDecisionReason HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\WpadLastNetwork HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2280033686-3172497658-3481507381-1000\ProfileImagePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{7673B35E-907A-449D-A49F-E5CE47F0B0B2}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\Groups HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch\EnabledScopes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Search\CurrentVersion HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Security\DisableSecuritySettingsCheck HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\DisableFixSecuritySettings HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Security\DisableFixSecuritySettings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1000 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1000 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\1000 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\1000 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Placement HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ITBar7Position HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FullScreen HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\IE8RunOnceLastShown HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CommandBar\SmallIcons HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CommandBar\ShowLeftAddressToolbar HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CommandBar\ShowCompatibilityViewButton HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\UseIE7AutoComplete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\\xe5\xbe\xae\xe8\xbd\xaf\xe9\x9b\x85\xe9\xbb\x91 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SearchControlWidth HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SearchMigrated HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SearchMigratedInstalled HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SearchMigratedDefaultName HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\provider HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\DefaultScope HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\Deleted HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\URL HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\DisplayName HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ShowSearchSuggestions HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ShowSearchSuggestions HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\ShowSearchSuggestionsGlobal HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\ShowSearchSuggestionsGlobal HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURL_JSON HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURL_JSON HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURL_JSONFallback HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURL_JSONFallback HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURL HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURLFallback HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\PreviewURL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\PreviewURL HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\PreviewURLFallback HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\PreviewURLFallback HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\FaviconURL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\FaviconURL HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\FaviconURLFallback HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\FaviconPath HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\Codepage HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\Codepage HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SortIndex HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\Enabled HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Locked HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CommandBar\TextOption HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CommandBar\CommandBarEnabled HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\Enabled HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CommandBar\FavBandRow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\ActivityMeterTimerInterval HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\ActivityMeterDisable HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\QuickTabsThreshold HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\ThumbnailBehavior HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ITBar7Height HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Min_Width HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Min_Height HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0002DF01-0000-0000-C000-000000000046}\ProgID\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0002DF01-0000-0000-C000-000000000046}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D5E8041D-920F-45E9-B8FB-B1DEB82C6E5E}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameTabWindow HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FrameTabWindow HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9EC704BA-E1D4-45C5-9B59-BFAE07D9F04E}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B40C43F1-F039-44D2-AEB7-87F5AF8ABC3D}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D358F4E1-0465-4965-9DD5-CAE303D2C345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F704B7E0-4760-46FF-BBDB-7439E0A2A814}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\DefaultAuthLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00020400-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020420-0000-0000-C000-000000000046}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D30C1661-CDAF-11D0-8A3E-00C04FC9E26E}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020424-0000-0000-C000-000000000046}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D30C1661-CDAF-11D0-8A3E-00C04FC9E26E}\TypeLib\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D30C1661-CDAF-11D0-8A3E-00C04FC9E26E}\TypeLib\Version HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\1.1\0\win32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\UDTAlignmentPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{48A98A1F-5CDD-47EE-9286-DB04A3EB7CE1}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6D5140C1-7436-11CE-8034-00AA006009FA}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B722BCCB-4E68-101B-A2BC-00AA00404770}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\InitFolderHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\CallForAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\RestrictedAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsFORDISPLAY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HideFolderVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\UseDropHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsFORPARSING HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsParseDisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\QueryForOverlay HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\MapNetDriveVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\QueryForInfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HideInWebView HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HideOnDesktopPerUser HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsAliasedNotifications HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsUniversalDelegate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\NoFileFolderJunction HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\PinToNameSpaceTree HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HasNavigationEnum HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{59031A47-3F72-44A7-89C5-5595FE6B30EE} HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Use FormSuggest HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\Use FormSuggest HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\QuickTabsLastUsed HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore\Type HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CaretBrowsing\EnableOnStartup HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Suggested Sites\MigrationTime HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Migration\IE Installed Date HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\IE8RunOncePerInstallCompleted HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\IE8RunOnceCompletionTime HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Check_Associations HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\Check_Associations HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo\ShowIconsCommand HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo\IconsVisible HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications\Internet Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\FileAssociations\.mht HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\FileAssociations\.html HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\FileAssociations\.htm HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\FileAssociations\.url HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\FileAssociations\.mhtml HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\UrlAssociations\https HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\UrlAssociations\ftp HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\UrlAssociations\http HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\MIMEAssociations\message/rfc822 HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\message/rfc822\UserChoice\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Capabilities\MIMEAssociations\text/html HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\text/html\UserChoice\Progid HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Suggested Sites\Enabled HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Suggested Sites\ObjectsCreated HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Suggested Sites\SlicePath HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch\Version HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF50}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch\ConfiguredScopes HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch\User Favorites Path HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch\UpgradeTime HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF55}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF52}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{04C18CCF-1F57-4CBD-88CC-3900F5195CE3}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B5702E61-E75C-4B64-82A1-6CB4F832FCCF}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF58}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\Version HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\UpgradeTime HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences\2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences\88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977 HKEY_CURRENT_USER\Control Panel\Desktop\SmoothScroll HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewAlphaSelect HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewShadow HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\DEPOff HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Low Rights\ProtectedModeOffForAllZones HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\TabProcGrowth HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\TabProcGrowth HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Low Rights\LuaOffLoRIEOn HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameMerging HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FrameMerging HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SessionMerging HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\SessionMerging HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\AdminTabProcs HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\AdminTabProcs HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\CompatibilityFlags HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\DetourDialogs HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\AcRedir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\TabShutdownDelay HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\TabShutdownDelay HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SQM\ServerFreezeOnUpload HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InitFolderHandler HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Favorites HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InitFolderHandler HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InitFolderHandler HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InitFolderHandler HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\74DD1FC8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE\DontUseDesktopChangeRouter HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\EnablePreBinding HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\CallForAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\RestrictedAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsFORDISPLAY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideFolderVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\UseDropHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsFORPARSING HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsParseDisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\QueryForOverlay HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\MapNetDriveVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\QueryForInfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideInWebView HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideOnDesktopPerUser HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsAliasedNotifications HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsUniversalDelegate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\NoFileFolderJunction HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\PinToNameSpaceTree HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HasNavigationEnum HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{871C5380-42A0-1069-A2EA-08002B30309D} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32\LoadWithoutCOM HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{871C5380-42A0-1069-A2EA-08002B30309D} {000214E6-0000-0000-C000-000000000046} 0xFFFF HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionHigh HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionHigh HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Feeds\UrlCacheVersion HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\UrlEncoding HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MIME_HANDLING\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Compatible HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Compatible HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Version HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Version HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Platform HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Platform HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASMANCS\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASMANCS\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASMANCS\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASMANCS\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASMANCS\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASMANCS\FileDirectory HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASAPI32\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASAPI32\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASAPI32\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASAPI32\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASAPI32\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iexplore_RASAPI32\FileDirectory HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER\* HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER\* HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_UNC_SAVEDFILECHECK\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_UNC_SAVEDFILECHECK\* HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\iexplore.exe HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\* HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\iexplore.exe HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\WinSock_Registry_Version HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\AutodialDLL HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableUTF8 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\AcceptLanguage HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\AllSitesCompatibilityMode HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\IntranetCompatibilityMode HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\MSCompatibilityMode HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\IECompatVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\IECompatVersionHigh HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\WpadExpirationDays HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\UnattendLoaded HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION\* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFileMenu HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window Title HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\StatusBarWeb HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Enable Browser Extensions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A10 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoBandCustomize HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ITBar7Layout HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\AlwaysShowMenus HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\AlwaysShowMenus HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ADDON_MANAGEMENT\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ADDON_MANAGEMENT\* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\Flags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\InprocServer32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Count HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\InprocServer32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\LoadTime HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\Flags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\InprocServer32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\Count HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InitFolderHandler HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\LoadTime HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\Flags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\14.0\Groove\InstallRoot\Path HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore\Count HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore\LoadTime HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5F226421-415D-408D-9A09-0DCD94E25B48}\1.0\0\win32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\OpenDirectlyInApp HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InsecureQI HKEY_CURRENT_USER\Software\Microsoft\Office\Common\AllowConsecutiveSlashesInUrlPathComponent HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Internet\OptimisticBHO HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\MinLevel HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\RecommendedLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\CurrentLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\Flags HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\MinLevel HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\RecommendedLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\CurrentLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\MinLevel HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\RecommendedLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\CurrentLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\MinLevel HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\RecommendedLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\CurrentLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\MinLevel HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\RecommendedLevel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\CurrentLevel HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\No3DBorder HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\No3DBorder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\UrlEncoding HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\UrlEncoding HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\MenuUserExpanded HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\text/html\Extension HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MIME_SNIFFING\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\iexplore.exe HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2100 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\IsTextPlainHonored HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_FEEDS\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_FEEDS\* HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\ProgID\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\InProcServer32\ThreadingModel HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollInset HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollInterval HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\* HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\about\CLSID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32\ThreadingModel HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2106 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Zoom\ZoomDisabled HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Zoom\ResetTextSizeOnStartup HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Zoom\ResetTextSizeOnZoom HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Zoom\ResetZoomOnStartup2 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Zoom\ZoomFactor HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter\EnabledV8 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2\UserFile HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SmartDithering HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\SmartDithering HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\RtfConverterFlags HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\UseClearType HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Page_Transitions HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\Page_Transitions HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Use_DlgBox_Colors HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Anchor Underline HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\CSS_Compat HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Expand Alt Text HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Display Inline Images HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Display Inline Videos HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\Display Inline Videos HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Play_Background_Sounds HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Play_Animations HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Print_Background HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\Print_Background HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Use Stylesheets HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SmoothScroll HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\SmoothScroll HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\XMLHTTP HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Show image placeholders HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\Show image placeholders HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Disable Script Debugger HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\DisableScriptDebuggerIE HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Move System Caret HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Force Offscreen Composition HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Enable AutoImageResize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\Enable AutoImageResize HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\UseThemes HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\UseHR HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Q300829 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Cleanup HTCs HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\XDomainRequest HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\XDomainRequest HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\DOMStorage HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\DOMStorage HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Default_CodePage HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\AutoDetect HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\Default_IEFontSizePrivate HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Anchor Color HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Anchor Color Visited HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Anchor Color Hover HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Always Use My Colors HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Always Use My Font Size HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Always Use My Font Face HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Disable Visited Hyperlinks HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Use Anchor Hover Color HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\MiscFlags HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles\Use My Stylesheet HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles\MaxScriptStatements HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Allow Programmatic Cut_Copy_Paste HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PageSetup\Print_Background HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\x8f\x91\xe9\x80\x81\xe8\x87\xb3 OneNote(&N)\(Default) HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\x8f\x91\xe9\x80\x81\xe8\x87\xb3 OneNote(&N)\Flags HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\x8f\x91\xe9\x80\x81\xe8\x87\xb3 OneNote(&N)\Contexts HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\xaf\xbc\xe5\x87\xba\xe5\x88\xb0 Microsoft Excel(&X)\(Default) HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\xaf\xbc\xe5\x87\xba\xe5\x88\xb0 Microsoft Excel(&X)\Flags HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\xaf\xbc\xe5\x87\xba\xe5\x88\xb0 Microsoft Excel(&X)\Contexts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\950 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1256 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\864 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\708 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\51256 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\720 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28596 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10004 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50001 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1257 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\775 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28594 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1250 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\852 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28592 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10029 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50936 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\51936 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\54936 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20936 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\52936 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50227 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10008 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50950 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20000 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20002 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50229 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10002 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10082 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1251 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\51251 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\866 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28595 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20866 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\21866 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10007 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28603 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\29001 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\21027 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\863 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20106 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1253 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\51253 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\737 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28597 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10006 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\869 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1255 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\862 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\38598 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28598 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10005 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20003 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20420 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20880 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\21025 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20277 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1142 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20278 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1143 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20297 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1147 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20273 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1141 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20423 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\875 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20424 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20871 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1149 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\500 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1148 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20280 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1144 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\932 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50930 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50939 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50931 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20290 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\949 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50933 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20833 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\870 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50935 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20284 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1145 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\874 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20838 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50937 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1254 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20905 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1026 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20285 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1146 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\37 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1140 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1047 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20924 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\861 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10079 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57006 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57003 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57002 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57010 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57008 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57009 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57007 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57011 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57004 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\57005 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20269 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50932 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\51932 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50220 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20932 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50221 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50222 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10001 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50949 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\51949 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\50225 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1361 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10003 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20949 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28593 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28605 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\865 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20108 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\855 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\437 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\858 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\860 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10010 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20107 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20261 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20001 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20004 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10021 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\857 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28599 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10081 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10017 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1201 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1258 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20005 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\850 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\20105 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\28591 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\10000 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEFontSize HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEFontSizePrivate HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEPropFontName HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEFixedFontName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Version Vector\VML HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Version Vector\IE HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Version Vector\WindowsEdition HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ZONE_ELEVATION\iexplore.exe HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2700 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_XSSFILTER\iexplore.exe HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1409 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\SecuritySafe HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\NoProtectedModeBanner HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME\* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2301 HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSize HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSizePrivate HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEPropFontName HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFixedFontName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN\* HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SecurityIdIUriCacheSize HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SecurityIdIUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SecurityIdIUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\SecurityIdIUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BEHAVIORS\iexplore.exe HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2000 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Default Behaviors\discovery HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_SSLUX\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_SSLUX\* HKEY_CURRENT_USER\Software\Microsoft\AntiPhishing\i HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9D973E3B-F610-4F03-83D3-AED90C3237AC}\SynchronousInterface\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\GipActivityBypass HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Version HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\475BA6DA2AFD5AE3ADAE78A261CA0E3E548B9532\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A7217F919843199C958C128449DD52D2723B0A8A\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D85213E038F309D02A40917B59E142368AE6B1C0\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\DBB84423C928ABE889D0E368FC3191D151DDB1AB\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\1A\AAF68885\@%SystemRoot%\system32\p2pcollab.dll,-8042 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\1A\AAF68885\@%SystemRoot%\system32\dnsapi.dll,-103 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetCachedOcspSwitchToCrlCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetMaxCachedOcspPerCrlCount HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugFlags HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\fe-54-00-43-f2-9a\WpadDecision HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\fe-54-00-43-f2-9a\WpadDecisionTime HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\fe-54-00-43-f2-9a\WpadDecisionReason HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableInetUnknownAuth HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\text/css\Extension HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016012420160125\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1400 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT\* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1201 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\COM+Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL\* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\160A HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\image/jpeg\Extension HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\image/gif\Extension HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\image/png\Extension HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F285-98B5-11CF-BB82-00AA00BDCE0B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F285-98B5-11CF-BB82-00AA00BDCE0B}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F285-98B5-11CF-BB82-00AA00BDCE0B}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3050F285-98B5-11CF-BB82-00AA00BDCE0B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_IMG\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_IMG\* HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\MaxRenderLine HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash\CLSID\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ProgID\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\ActiveX Compatibility\{D27CDB6E-AE6D-11CF-96B8-444553540000}\Compatibility Flags HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\ActiveX Compatibility\{D27CDB6E-AE6D-11CF-96B8-444553540000}\MiscStatus Flags HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D27CDB6E-AE6D-11CF-96B8-444553540000}\Flags HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION\iexplore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION\* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1207 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\120B HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1208 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore\Count HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1200 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00020404-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020421-0000-0000-C000-000000000046}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\~MHz HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\{10200490-FA38-11D0-AC0E-00A0C90FFFC0} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\{10200490-FA38-11D0-AC0E-00A0C90FFFC0} HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1405 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchMinMaxAgeSeconds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchMaxMaxAgeSeconds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogMaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3ED72303-6FFC-4214-BA90-FAF1862DEC8A}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3050F69A-98B5-11CF-BB82-00AA00BDCE0B}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3050F69A-98B5-11CF-BB82-00AA00BDCE0B}\TypeLib\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3050F69A-98B5-11CF-BB82-00AA00BDCE0B}\TypeLib\Version HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3050F1C5-98B5-11CF-BB82-00AA00BDCE0B}\4.0\0\win32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\TypeLib\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\TypeLib\Version HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{332C4427-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{332C4427-26CB-11D0-B483-00C04FD90119}\TypeLib\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{332C4427-26CB-11D0-B483-00C04FD90119}\TypeLib\Version HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3050F32D-98B5-11CF-BB82-00AA00BDCE0B}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3050F32D-98B5-11CF-BB82-00AA00BDCE0B}\TypeLib\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3050F32D-98B5-11CF-BB82-00AA00BDCE0B}\TypeLib\Version HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{30510478-98B5-11CF-BB82-00AA00BDCE0B}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{30510478-98B5-11CF-BB82-00AA00BDCE0B}\TypeLib\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{30510478-98B5-11CF-BB82-00AA00BDCE0B}\TypeLib\Version HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\.htm HKEY_CURRENT_USER\Software\Classes\.htm\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IE.AssocFile.HTM\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IE.AssocFile.HTM\NoStaticDefaultVerb HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IE.AssocFile.HTM\shell\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IE.AssocFile.HTM\shell\opennew\NeverDefault HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Excel.exe\shell\edit\command\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Default HTML Editor\Stubs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Excel.Sheet\CurVer\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Excel.Sheet.12\NoStaticDefaultVerb HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Excel.Sheet.12\shell\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Excel.Sheet.12\shell\Open\NeverDefault HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Excel\shell\edit\command\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Publisher\shell\edit\command\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\Microsoft Word\shell\edit\command\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Document\CurVer\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Document.12\NoStaticDefaultVerb HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Document.12\shell\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Document.12\shell\Open\NeverDefault HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.htm\OpenWithList\MSPub.exe\shell\edit\command\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\notepad.exe\shell\edit\command\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\Winword.exe\shell\edit\command\(Default) HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\CheckDocumentForProgID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\MAIN\CheckDocumentForProgID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Feed Discovery\Sound HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\Feed Discovery\Enabled HKEY_CURRENT_USER\Software\Microsoft\FTP\Use Web Based FTP HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Services\SelectionActivityButtonDisable HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FF393560-C2A7-11CF-BFF4-444553540000}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FF393560-C2A7-11CF-BFF4-444553540000}\InProcServer32\LoadWithoutCOM HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{FF393560-C2A7-11CF-BFF4-444553540000} {000214E6-0000-0000-C000-000000000046} 0xFFFF HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016012420160125\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016012420160125\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016012420160125\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016012420160125\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\LocalizedString HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\image/x-icon\Extension HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2101 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter\ShownServiceDownBalloon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\INTERNET EXPLORER\PhishingFilter\ShownServiceDownBalloon 修改的注册表键 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\WpadLastNetwork HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\SecuritySafe HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FullScreen HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Placement HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch\UpgradeTime HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Type HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Count HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Time HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\LoadTime HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\Type HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\Count HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\Time HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\LoadTime HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore\Type HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore\Count HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore\Time HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore\LoadTime HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2\UserFile HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\1A\AAF68885\LanguageList HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total\(Default) HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\18183.com HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\18183.com\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore\Type HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore\Count HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore\Time HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005111620051117\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter\ShownServiceDownBalloon 删除的注册表键 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName API解析 ieproxy.dll.DllGetClassObject ieproxy.dll.DllCanUnloadNow oleaut32.dll.DllGetClassObject oleaut32.dll.DllCanUnloadNow gdi32.dll.GetLayout gdi32.dll.GdiRealizationInfo gdi32.dll.FontIsLinked advapi32.dll.RegOpenKeyExW advapi32.dll.RegQueryInfoKeyW gdi32.dll.GetTextFaceAliasW advapi32.dll.RegEnumValueW advapi32.dll.RegCloseKey advapi32.dll.RegQueryValueExW advapi32.dll.RegQueryValueExA advapi32.dll.RegEnumKeyExW gdi32.dll.GdiIsMetaPrintDC ole32.dll.CoInitializeEx user32.dll.MsgWaitForMultipleObjectsEx uxtheme.dll.OpenThemeData uxtheme.dll.GetThemeMargins uxtheme.dll.GetThemePartSize uxtheme.dll.GetThemeTextMetrics uxtheme.dll.GetThemeBool comctl32.dll.#410 comctl32.dll.#413 uxtheme.dll.IsAppThemed uxtheme.dll.GetThemeBackgroundExtent comctl32.dll.ImageList_LoadImageW comctl32.dll.ImageList_GetIconSize uxtheme.dll.GetThemeFont uxtheme.dll.IsCompositionActive uxtheme.dll.SetWindowTheme comctl32.dll.ImageList_Create comctl32.dll.ImageList_ReplaceIcon oleaut32.dll.#10 comctl32.dll.ImageList_AddMasked oleaut32.dll.#2 oleaut32.dll.#6 uxtheme.dll.IsThemePartDefined uxtheme.dll.GetThemeColor imm32.dll.ImmIsIME urlmon.dll.CoInternetCreateSecurityManager msctf.dll.SetInputScopes2 uxtheme.dll.CloseThemeData uxtheme.dll.GetThemeBackgroundContentRect uxtheme.dll.GetThemeTextExtent uxtheme.dll.EnableThemeDialogTexture urlmon.dll.#408 uxtheme.dll.IsThemeActive ieui.dll.CreateGadget ieui.dll.SetGadgetMessageFilter ieui.dll.SetGadgetStyle ieui.dll.SetGadgetRootInfo uxtheme.dll.GetThemeAppProperties xmllite.dll.CreateXmlReader xmllite.dll.CreateXmlReaderInputWithEncodingName ieui.dll.FindStdColor ieui.dll.InvalidateGadget ieui.dll.SetGadgetParent ieui.dll.GetGadgetTicket ieui.dll.SetGadgetRect uxtheme.dll.IsThemeBackgroundPartiallyTransparent uxtheme.dll.DrawThemeBackground uxtheme.dll.DrawThemeParentBackground comctl32.dll.ImageList_Draw uxtheme.dll.BufferedPaintInit uxtheme.dll.BufferedPaintRenderAnimation uxtheme.dll.GetThemeTransitionDuration uxtheme.dll.BeginBufferedAnimation uxtheme.dll.EndBufferedAnimation uxtheme.dll.BeginBufferedPaint uxtheme.dll.DrawThemeParentBackgroundEx uxtheme.dll.EndBufferedPaint ole32.dll.CoUninitialize ole32.dll.CoRegisterInitializeSpy ole32.dll.CoRevokeInitializeSpy shell32.dll.SHGetInstanceExplorer wininet.dll.InternetSetOptionW user32.dll.PostMessageW ole32.dll.CoMarshalInterface user32.dll.PeekMessageW user32.dll.TranslateMessage user32.dll.DispatchMessageW ieui.dll.PeekMessageExW ole32.dll.CoInitialize ole32.dll.RegisterDragDrop msimg32.dll.TransparentBlt rpcrt4.dll.RpcBindingToStringBindingW rpcrt4.dll.RpcStringBindingParseW rpcrt4.dll.RpcStringFreeW rpcrt4.dll.I_RpcBindingInqLocalClientPID rpcrt4.dll.RpcServerInqCallAttributesW rpcrt4.dll.RpcImpersonateClient rpcrt4.dll.RpcRevertToSelf rpcrt4.dll.NdrServerCall2 rpcrt4.dll.RpcBindingInqObject msimg32.dll.GradientFill uxtheme.dll.DrawThemeText ieui.dll.WaitMessageEx rpcrt4.dll.RpcStringBindingComposeW rpcrt4.dll.RpcBindingFromStringBindingW rpcrt4.dll.RpcBindingSetAuthInfoExW rpcrt4.dll.NdrClientCall2 user32.dll.GetWindowLongW user32.dll.IsWindow user32.dll.SendMessageW rpcrt4.dll.RpcBindingFree oleaut32.dll.#9 sxs.dll.SxsOleAut32MapIIDToProxyStubCLSID advapi32.dll.RegQueryValueW sxs.dll.SxsOleAut32MapIIDToTLBPath advapi32.dll.RegEnumKeyW sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid sxs.dll.SxsOleAut32RedirectTypeLibrary mlang.dll.#112 wininet.dll.GetUrlCacheEntryInfoA comctl32.dll.#328 comctl32.dll.#334 advapi32.dll.InitializeSecurityDescriptor advapi32.dll.SetEntriesInAclW advapi32.dll.SetSecurityDescriptorDacl advapi32.dll.IsTextUnicode comctl32.dll.#332 comctl32.dll.#338 comctl32.dll.#339 shell32.dll.#102 propsys.dll.PSCreateMemoryPropertyStore propsys.dll.PSPropertyBag_WriteStr ole32.dll.PropVariantClear propsys.dll.PSPropertyBag_WriteGUID propsys.dll.PSPropertyBag_ReadGUID propsys.dll.PSStringFromPropertyKey propsys.dll.PSGetPropertyDescription ole32.dll.CoTaskMemAlloc propsys.dll.PropVariantToString propsys.dll.InitPropVariantFromStringAsVector propsys.dll.PSCoerceToCanonicalValue usp10.dll.ScriptIsComplex urlmon.dll.#420 comctl32.dll.HIMAGELIST_QueryInterface comctl32.dll.ImageList_Remove urlmon.dll.#441 urlmon.dll.#395 urlmon.dll.#351 wininet.dll.GetUrlCacheEntryInfoExW normaliz.dll.IdnToAscii wininet.dll.GetUrlCacheEntryInfoExA uxtheme.dll.DrawThemeTextEx setupapi.dll.CM_Get_Device_Interface_List_Size_ExW setupapi.dll.CM_Get_Device_Interface_List_ExW comctl32.dll.#386 msimg32.dll.AlphaBlend oleaut32.dll.#15 oleaut32.dll.#23 oleaut32.dll.#22 urlmon.dll.#325 wininet.dll.CommitUrlCacheEntryA ole32.dll.CoTaskMemFree urlmon.dll.#403 propsys.dll.PSGetPropertyKeyFromName urlmon.dll.CoInternetQueryInfo comctl32.dll.ImageList_GetImageCount user32.dll.CharLowerW cryptsp.dll.CryptAcquireContextW cryptsp.dll.CryptCreateHash cryptsp.dll.CryptHashData cryptsp.dll.CryptGetHashParam cryptsp.dll.CryptDestroyHash cryptsp.dll.CryptReleaseContext crypt32.dll.CryptUnprotectData cryptbase.dll.SystemFunction041 ieui.dll.FindGadgetFromPoint ieui.dll.DUserSendEvent ieui.dll.GetGadgetRect uxtheme.dll.GetThemeBackgroundRegion advapi32.dll.EventWrite advapi32.dll.EventRegister advapi32.dll.EventUnregister kernel32.dll.InitializeSRWLock kernel32.dll.AcquireSRWLockExclusive kernel32.dll.AcquireSRWLockShared kernel32.dll.ReleaseSRWLockExclusive kernel32.dll.ReleaseSRWLockShared kernel32.dll.SetProcessDEPPolicy user32.dll.SetProcessDPIAware shell32.dll.SetCurrentProcessExplicitAppUserModelID user32.dll.GetShellWindow user32.dll.GetWindowThreadProcessId kernel32.dll.SortGetHandle kernel32.dll.SortCloseHandle ieframe.dll.#251 kernel32.dll.WerSetFlags comctl32.dll.PropertySheetW comctl32.dll.PropertySheetA comdlg32.dll.PageSetupDlgW comdlg32.dll.PrintDlgW ieshims.dll.IEShims_Initialize kernel32.dll.VirtualProtect user32.dll.SetWindowsHookExW user32.dll.FindWindowExA kernel32.dll.WaitForSingleObject kernel32.dll.CreateProcessW kernel32.dll.CreateProcessA advapi32.dll.RegQueryValueA ntdll.dll.LdrRegisterDllNotification ole32.dll.CoGetApartmentType comctl32.dll.#236 ole32.dll.CoGetMalloc cryptbase.dll.SystemFunction036 uxtheme.dll.ThemeInitApiHook user32.dll.IsProcessDPIAware kernel32.dll.WerRegisterMemoryBlock kernel32.dll.WerUnregisterMemoryBlock user32.dll.RegisterWindowMessageW rpcrt4.dll.RpcServerUseProtseqW rpcrt4.dll.RpcServerRegisterIfEx rpcrtremote.dll.I_RpcExtInitializeExtensionPoint rpcrt4.dll.RpcServerInqBindings rpcrt4.dll.RpcEpRegisterW rpcrt4.dll.RpcServerListen user32.dll.RegisterClassExW user32.dll.CreateWindowExW user32.dll.DefWindowProcW user32.dll.SetWindowLongW dwmapi.dll.DwmIsCompositionEnabled urlmon.dll.#400 shell32.dll.SHGetFolderPathW advapi32.dll.TraceMessage advapi32.dll.TraceMessageVa kernel32.dll.IsWow64Process sqmapi.dll.SqmGetSession sqmapi.dll.SqmEndSession sqmapi.dll.SqmStartSession sqmapi.dll.SqmStartUpload sqmapi.dll.SqmWaitForUploadComplete sqmapi.dll.SqmSet sqmapi.dll.SqmSetBool sqmapi.dll.SqmSetBits sqmapi.dll.SqmSetString sqmapi.dll.SqmIncrement sqmapi.dll.SqmSetIfMax sqmapi.dll.SqmSetIfMin sqmapi.dll.SqmAddToAverage sqmapi.dll.SqmAddToStreamDWord sqmapi.dll.SqmAddToStreamString sqmapi.dll.SqmSetAppId sqmapi.dll.SqmSetAppVersion sqmapi.dll.SqmSetMachineId sqmapi.dll.SqmSetUserId sqmapi.dll.SqmCreateNewId sqmapi.dll.SqmReadSharedMachineId sqmapi.dll.SqmReadSharedUserId sqmapi.dll.SqmWriteSharedMachineId sqmapi.dll.SqmWriteSharedUserId sqmapi.dll.SqmIsWindowsOptedIn advapi32.dll.OpenThreadToken ole32.dll.CreateBindCtx comctl32.dll.#320 comctl32.dll.#324 comctl32.dll.#323 ole32.dll.CoCreateInstance ntmarta.dll.GetMartaExtensionInterface sechost.dll.ConvertSidToStringSidW profapi.dll.#104 ole32.dll.CoUnmarshalInterface sechost.dll.LookupAccountNameLocalW advapi32.dll.LookupAccountSidW sechost.dll.LookupAccountSidLocalW cryptsp.dll.CryptGenRandom ole32.dll.NdrOleInitializeExtension ole32.dll.CoGetClassObject ole32.dll.CoGetMarshalSizeMax ole32.dll.StringFromIID ole32.dll.CoGetPSClsid ole32.dll.CoReleaseMarshalData ole32.dll.DcomChannelSetHResult shell32.dll.SHChangeNotifyRegisterThread comctl32.dll.#4 ieshims.dll.IEShims_SetRedirectRegistryForThread apphelp.dll.ApphelpCheckShellObject urlmon.dll.CreateUri advapi32.dll.AddMandatoryAce version.dll.GetFileVersionInfoSizeW version.dll.GetFileVersionInfoW version.dll.VerQueryValueW wininet.dll.GetUrlCacheEntryInfoW urlmon.dll.CreateURLMonikerEx urlmon.dll.CreateAsyncBindCtxEx urlmon.dll.RegisterBindStatusCallback urlmon.dll.UrlMkGetSessionOption rasapi32.dll.RasConnectionNotificationW rasman.dll.RasPortClearStatistics rasman.dll.RasBundleClearStatistics rasman.dll.RasBundleClearStatisticsEx rasman.dll.RasDeviceEnum rasman.dll.RasDeviceGetInfo rasman.dll.RasFreeBuffer rasman.dll.RasGetBuffer rasman.dll.RasGetInfo rasman.dll.RasGetDialMachineEventContext rasman.dll.RasSetDialMachineEventHandle rasman.dll.RasGetNdiswanDriverCaps rasman.dll.RasInitialize rasman.dll.RasInitializeNoWait rasman.dll.RasPortCancelReceive rasman.dll.RasPortEnum rasman.dll.RasPortGetInfo rasman.dll.RasPortGetFramingEx rasman.dll.RasPortGetStatistics rasman.dll.RasBundleGetStatistics rasman.dll.RasPortGetStatisticsEx rasman.dll.RasBundleGetStatisticsEx rasman.dll.RasPortReceive rasman.dll.RasPortReceiveEx rasman.dll.RasPortSend rasman.dll.RasPortGetBundle rasman.dll.RasGetDevConfig rasman.dll.RasGetDevConfigEx rasman.dll.RasSetDevConfig rasman.dll.RasPortClose rasman.dll.RasPortListen rasman.dll.RasPortConnectComplete rasman.dll.RasPortDisconnect rasman.dll.RasRequestNotification rasman.dll.RasPortEnumProtocols rasman.dll.RasPortSetFraming rasman.dll.RasPortSetFramingEx rasman.dll.RasSetCachedCredentials rasman.dll.RasGetDialParams rasman.dll.RasSetDialParams rasman.dll.RasCreateConnection rasman.dll.RasDestroyConnection rasman.dll.RasConnectionEnum rasman.dll.RasAddConnectionPort rasman.dll.RasEnumConnectionPorts rasman.dll.RasGetConnectionParams rasman.dll.RasSetConnectionParams rasman.dll.RasGetConnectionUserData rasman.dll.RasSetConnectionUserData rasman.dll.RasGetPortUserData rasman.dll.RasSetPortUserData rasman.dll.RasAddNotification rasman.dll.RasSignalNewConnection rasman.dll.RasApplyPostConnectActions rasman.dll.RasProtocolStop rasman.dll.RasProtocolCallback rasman.dll.RasProtocolChangePassword rasman.dll.RasProtocolGetInfo rasman.dll.RasProtocolRetry rasman.dll.RasProtocolStart rasman.dll.RasPortOpen rasman.dll.RasAllocateRoute rasman.dll.RasActivateRoute rasman.dll.RasActivateRouteEx rasman.dll.RasDeviceSetInfo rasman.dll.RasDeviceSetInfoSafe rasman.dll.RasDeviceConnect rasman.dll.RasPortSetInfo rasman.dll.RasSendProtocolResultToRasman rasman.dll.RasSetEapInfo rasman.dll.RasRpcConnect rasman.dll.RasRpcDisconnect rasman.dll.RasGetNumPortOpen rasman.dll.RasRefConnection rasman.dll.RasSetEapUIData rasman.dll.RasGetEapUIData rasman.dll.RasFindPrerequisiteEntry rasman.dll.RasPortOpenEx rasman.dll.RasLinkGetStatistics rasman.dll.RasConnectionGetStatistics rasman.dll.RasGetHportFromConnection rasman.dll.RasRPCBind rasman.dll.RasReferenceCustomCount rasman.dll.RasGetHConnFromEntry rasman.dll.RasGetDeviceName rasman.dll.RasEnableIpSec rasman.dll.RasSetTunnelEndPoints rasman.dll.RasStartRasAutoIfRequired rasman.dll.RasStartProtocolRenegotiation rasman.dll.RasSendNotification rasman.dll.RasGetDeviceNameW rasman.dll.RasGetUnicodeDeviceName rasman.dll.RasRpcGetVersion rasman.dll.RasRpcPortEnum rasman.dll.RasRpcDeviceEnum rasman.dll.RasRpcGetDevConfig rasman.dll.RasRpcPortGetInfo rasman.dll.RasRpcGetInstalledProtocols rasman.dll.RasRpcGetInstalledProtocolsEx rasman.dll.RasRpcGetSystemDirectory rasman.dll.RasRpcGetUserPreferences rasman.dll.RasRpcDeleteEntry rasman.dll.RasRpcEnumConnections rasman.dll.RasRpcGetCountryInfo rasman.dll.RasRpcGetErrorString rasman.dll.RasRpcSetUserPreferences rasman.dll.RasProtocolUpdateConnection rasman.dll.RasAddNotificationEx rasman.dll.RasRemoveNotificationEx rasman.dll.RasGetNotificationEntry rasman.dll.RasSignalMonitorThreadExit rasman.dll.RasmanUninitialize rtutils.dll.TraceRegisterExA rtutils.dll.TracePrintfExA sechost.dll.OpenSCManagerA sechost.dll.OpenServiceA sechost.dll.QueryServiceStatus sechost.dll.CloseServiceHandle sechost.dll.NotifyServiceStatusChangeA nlaapi.dll.NSPStartup iphlpapi.dll.GetAdapterIndex rasadhlp.dll.WSAttemptAutodialAddr rasadhlp.dll.WSAttemptAutodialName rasadhlp.dll.WSNoteSuccessfulHostentLookup advapi32.dll.RegDeleteTreeA advapi32.dll.RegDeleteTreeW mlang.dll.#121 urlmon.dll.#444 oleaut32.dll.#8 advapi32.dll.RegOpenKeyW napinsp.dll.NSPStartup sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW pnrpnsp.dll.NSPStartup mswsock.dll.NSPStartup winrnr.dll.NSPStartup ws2_32.dll.#112 ws2_32.dll.#111 dnsapi.dll.DnsApiAlloc dnsapi.dll.DnsApiFree urlmon.dll.#445 comctl32.dll.ImageList_Destroy comctl32.dll.ImageList_Add urlmon.dll.CoInternetCreateZoneManager urlmon.dll.CoInternetIsFeatureEnabledForUrl wininet.dll.InternetQueryOptionA gdi32.dll.GetFontAssocStatus gdi32.dll.GetTextExtentExPointWPri urlmon.dll.#104 acroiehelper.dll.DllMain acroiehelper.dll.StubInit acroiehelper.dll.StubSetSite acroiehelper.dll.StubOnQuit kernel32.dll.QueryActCtxW kernel32.dll.ActivateActCtx kernel32.dll.FindActCtxSectionStringW kernel32.dll.DeactivateActCtx kernel32.dll.InterlockedPushEntrySList kernel32.dll.InterlockedPopEntrySList user32.dll.MsgWaitForMultipleObjects user32.dll.IsWindowUnicode user32.dll.GetMessageW comctl32.dll.#8 comctl32.dll.LoadIconWithScaleDown uxtheme.dll.GetThemeInt urlmon.dll.RevokeBindStatusCallback urlmon.dll.CreateFormatEnumerator urlmon.dll.CreateIUriBuilder urlmon.dll.IntlPercentEncodeNormalize user32.dll.ChangeWindowMessageFilter dwmapi.dll.DwmSetWindowAttribute oleaut32.dll.#500 imm32.dll.ImmGetContext mshtml.dll.DllGetClassObject mshtml.dll.DllCanUnloadNow iertutil.dll.#35 kernel32.dll.GetThreadUILanguage oleaut32.dll.#7 ieframe.dll.#302 urlmon.dll.RegisterFormatEnumerator urlmon.dll.#101 oleaut32.dll.VariantClear ieframe.dll.#234 wininet.dll.InternetUnlockRequestFile oleaut32.dll.#4 urlmon.dll.CoInternetIsFeatureEnabled urlmon.dll.#335 oleaut32.dll.#19 oleaut32.dll.#17 oleaut32.dll.#20 cryptbase.dll.SystemFunction040 oleaut32.dll.BSTR_UserSize oleaut32.dll.BSTR_UserMarshal oleaut32.dll.BSTR_UserUnmarshal oleaut32.dll.BSTR_UserFree oleaut32.dll.VARIANT_UserSize oleaut32.dll.VARIANT_UserMarshal oleaut32.dll.VARIANT_UserUnmarshal oleaut32.dll.VARIANT_UserFree oleaut32.dll.LPSAFEARRAY_UserSize oleaut32.dll.LPSAFEARRAY_UserMarshal oleaut32.dll.LPSAFEARRAY_UserUnmarshal oleaut32.dll.LPSAFEARRAY_UserFree urlmon.dll.#330 wininet.dll.InternetCloseHandle wininet.dll.InternetOpenW wininet.dll.InternetConnectW wininet.dll.HttpOpenRequestW wininet.dll.HttpSendRequestW secur32.dll.FreeContextBuffer ncrypt.dll.SslOpenProvider ncrypt.dll.GetSChannelInterface bcryptprimitives.dll.GetHashInterface ncrypt.dll.SslIncrementProviderReferenceCount ncrypt.dll.SslImportKey bcryptprimitives.dll.GetCipherInterface sechost.dll.ConvertStringSidToSidW userenv.dll.RegisterGPNotification gpapi.dll.RegisterGPNotificationInternal sechost.dll.OpenSCManagerW sechost.dll.OpenServiceW sechost.dll.QueryServiceConfigW user32.dll.LoadStringW ncrypt.dll.BCryptOpenAlgorithmProvider ncrypt.dll.BCryptGetProperty ncrypt.dll.BCryptCreateHash ncrypt.dll.BCryptHashData ncrypt.dll.BCryptFinishHash ncrypt.dll.BCryptDestroyHash cryptsp.dll.CryptAcquireContextA cryptsp.dll.CryptVerifySignatureA cryptsp.dll.CryptDestroyKey bcryptprimitives.dll.GetAsymmetricEncryptionInterface ncrypt.dll.BCryptImportKeyPair ncrypt.dll.BCryptVerifySignature ncrypt.dll.BCryptDestroyKey cryptnet.dll.CertDllVerifyRevocation sensapi.dll.IsNetworkAlive winhttp.dll.WinHttpOpen winhttp.dll.WinHttpSetTimeouts winhttp.dll.WinHttpSetOption winhttp.dll.WinHttpCrackUrl shlwapi.dll.StrCmpNW winhttp.dll.WinHttpConnect winhttp.dll.WinHttpOpenRequest winhttp.dll.WinHttpGetDefaultProxyConfiguration winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser nsi.dll.NsiAllocateAndGetTable cfgmgr32.dll.CM_Open_Class_Key_ExW iphlpapi.dll.ConvertInterfaceGuidToLuid iphlpapi.dll.GetIfEntry2 iphlpapi.dll.GetIpForwardTable2 iphlpapi.dll.GetIpNetEntry2 iphlpapi.dll.FreeMibTable nsi.dll.NsiFreeTable winhttp.dll.WinHttpSendRequest ws2_32.dll.GetAddrInfoW msimtf.dll.MsimtfIsWindowFiltered imm32.dll.ImmGetCompositionWindow imm32.dll.ImmGetCandidateWindow oleaut32.dll.SysAllocString oleaut32.dll.SysStringLen oleaut32.dll.SysFreeString shell32.dll.#165 wininet.dll.CreateUrlCacheContainerW oleacc.dll.LresultFromObject user32.dll.GetGUIThreadInfo user32.dll.GetCursorInfo user32.dll.GetWindowInfo user32.dll.GetTitleBarInfo user32.dll.GetScrollBarInfo user32.dll.GetComboBoxInfo user32.dll.GetAncestor user32.dll.RealChildWindowFromPoint user32.dll.RealGetWindowClassW user32.dll.GetAltTabInfoW user32.dll.GetListBoxInfo user32.dll.GetMenuBarInfo user32.dll.SendInput user32.dll.BlockInput user32.dll.LogicalToPhysicalPoint user32.dll.PhysicalToLogicalPoint user32.dll.WindowFromPhysicalPoint user32.dll.GetPhysicalCursorPos kernel32.dll.GetModuleFileNameW kernel32.dll.VirtualAllocEx kernel32.dll.VirtualFreeEx ntdll.dll.NtQueryInformationProcess ntdll.dll.NtAllocateVirtualMemory ntdll.dll.NtFreeVirtualMemory oleacc.dll.ObjectFromLresult ole32.dll.CoGetObjectContext oleaut32.dll.#201 oleaut32.dll.#200 wininet.dll.CreateUrlCacheEntryW xmllite.dll.CreateXmlWriter wininet.dll.CommitUrlCacheEntryW imgutil.dll.DecodeImage gdiplus.dll.GdiplusStartup kernel32.dll.IsProcessorFeaturePresent user32.dll.GetMonitorInfoA user32.dll.EnumDisplayMonitors user32.dll.EnumDisplayDevicesA gdi32.dll.ExtTextOutW gdiplus.dll.GdipAlloc gdiplus.dll.GdipCreateBitmapFromHBITMAP gdiplus.dll.GdipCreateImageAttributes gdiplus.dll.GdipSetImageAttributesWrapMode gdiplus.dll.GdipCreateFromHDC gdiplus.dll.GdipSetPageUnit gdiplus.dll.GdipSetPixelOffsetMode gdiplus.dll.GdipSetCompositingMode gdiplus.dll.GdipSetCompositingQuality gdiplus.dll.GdipSetInterpolationMode gdiplus.dll.GdipSetClipRectI gdiplus.dll.GdipDrawImageRectRect gdiplus.dll.GdipDeleteGraphics gdiplus.dll.GdipDisposeImageAttributes gdiplus.dll.GdipCreateBitmapFromScan0 gdiplus.dll.GdipImageRotateFlip gdiplus.dll.GdipDisposeImage gdiplus.dll.GdipFree ws2_32.dll.WSASocketW ws2_32.dll.#2 ws2_32.dll.#21 ws2_32.dll.#9 ws2_32.dll.WSAIoctl ws2_32.dll.FreeAddrInfoW ws2_32.dll.#6 ws2_32.dll.#5 ws2_32.dll.WSARecv ws2_32.dll.WSASend winhttp.dll.WinHttpReceiveResponse winhttp.dll.WinHttpQueryHeaders shlwapi.dll.StrStrIW winhttp.dll.WinHttpQueryDataAvailable winhttp.dll.WinHttpReadData winhttp.dll.WinHttpCloseHandle wininet.dll.InternetGetCookieExW mshtml.dll.MatchExactGetIDsOfNames oleaut32.dll.#161 ieframe.dll.#243 ole32.dll.CLSIDFromProgIDEx ole32.dll.CLSIDFromProgID ieframe.dll.#231 advapi32.dll.CryptAcquireContextA advapi32.dll.CryptGenRandom advapi32.dll.CryptReleaseContext flash32_20_0_0_286.ocx.DllGetClassObject flash32_20_0_0_286.ocx.DllCanUnloadNow kernel32.dll.GetUserDefaultUILanguage kernel32.dll.CreateDirectoryW kernel32.dll.CreateFileW kernel32.dll.DeleteFileW kernel32.dll.MoveFileExA kernel32.dll.MoveFileExW kernel32.dll.RemoveDirectoryW kernel32.dll.GetSystemDirectoryW kernel32.dll.ExpandEnvironmentStringsW kernel32.dll.FindFirstFileW kernel32.dll.FindNextFileW kernel32.dll.GetFileAttributesW kernel32.dll.SetFileAttributesW kernel32.dll.GetFileAttributesExW kernel32.dll.GetCurrentDirectoryW kernel32.dll.SetCurrentDirectoryW kernel32.dll.GetTempPathW kernel32.dll.GetTempFileNameW kernel32.dll.CopyFileW kernel32.dll.GetFullPathNameW kernel32.dll.GetVolumeInformationW kernel32.dll.QueryFullProcessImageNameW user32.dll.CharUpperBuffW shell32.dll.ShellExecuteExW ieframe.dll.IEIsProtectedModeProcess ieframe.dll.IECancelSaveFile ieframe.dll.IESaveFile ieframe.dll.IEShowSaveFileDialog ieframe.dll.IEGetWriteableFolderPath kernel32.dll.SetWaitableTimerEx ntdll.dll.RtlInitUnicodeString ntdll.dll.NtOpenSymbolicLinkObject ntdll.dll.NtQuerySymbolicLinkObject kernel32.dll.GetNativeSystemInfo ieframe.dll.IEIsInPrivateBrowsing kernel32.dll.PowerCreateRequest kernel32.dll.PowerSetRequest kernel32.dll.PowerClearRequest cryptnet.dll.CryptRetrieveObjectByUrlW setupapi.dll.SetupIterateCabinetW kernel32.dll.RegOpenKeyExW kernel32.dll.RegCloseKey cabinet.dll.#20 cabinet.dll.#22 devrtl.dll.DevRtlGetThreadLogToken cryptsp.dll.CryptSetHashParam sechost.dll.QueryServiceConfigA rpcrt4.dll.RpcStringBindingComposeA rpcrt4.dll.RpcBindingFromStringBindingA rpcrt4.dll.RpcEpResolveBinding rpcrt4.dll.RpcStringFreeA oleaut32.dll.VariantCopy propsys.dll.#430 advapi32.dll.RegGetValueW propsys.dll.PropVariantToStringAlloc wininet.dll.FindFirstUrlCacheContainerA wininet.dll.FindNextUrlCacheContainerA wininet.dll.FindCloseUrlCache wininet.dll.CreateUrlCacheContainerA wininet.dll.DeleteUrlCacheContainerA wininet.dll.FindFirstUrlCacheEntryA wininet.dll.FindNextUrlCacheEntryA wininet.dll.InternetGetConnectedState urlmon.dll.#414 dwmapi.dll.DwmInvalidateIconicBitmaps urlmon.dll.URLDownloadToCacheFileW wininet.dll.SetUrlCacheEntryGroupW urlmon.dll.#327 comctl32.dll.#17 comctl32.dll.DllGetVersion ws2_32.dll.#22 wininet.dll.IsUrlCacheEntryExpiredW ws2_32.dll.#116 ©2016 上海魔盾信息科技有限公司
Documentos relacionados
魔盾安全分析报告 URL信息 特征 运行截图 网络分析 访问主机记录
eff13319ebebfd4f40a9c19f0680c39cbfdfc62836037fd14b5913d9c329ad7b5fd64a140d1bfba8f429890b3fbff9f41f705c9aa87a02e3fb5fe92afdf5a530
Leia mais魔盾安全分析报告 URL信息 特征 运行截图 网络分析 访问主机记录
73b474ed362a6854b329dd4f09fb5c62aa91073ffa6e2ca26d0ddc4c4eead8d53252aab22141644bb3dcd6a3244cd8be9924528ebc2fea647bc80f474cd186e5
Leia mais魔盾安全分析报告 URL信息 特征 运行截图 网络分析 访问主机记录
http://ocsp2.globalsign.com/gsorganizationvalsha2g2/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQMnk2cPe3vhNiR6XLHz4QGvBl7BwQUlt5h8b0cFilTHMDMfTuDAEDmGnwCEhEhGuAGlWtDRHAtLRzCaILaCA%3D%3D
Leia mais魔盾安全分析报告 URL信息 特征 运行截图 网络分析 访问主机记录
C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAPBQ2GR\1020931287_DSC_0078[1].jpg C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content...
Leia mais魔盾安全分析报告 URL信息 特征 运行截图 网络分析 访问主机记录
http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-0243119537643981&format=336x280&output=html&h=280&slotname=7625312430&adk=3474974944&w=336&lmt=1457818294&ea=0&flash=20.0.0 M&shv=r...
Leia mais魔盾安全分析报告 文件详细信息 特征
clickUrl=http%3a%2f%2fad.winrar.com.cn%2fclickadvertise%3fAdvertiseID%3d857%26AdvertisesType%3d%e6%9c%8d%e5%8a%a1%e7%b1%bb%26appname%3dwinrar_1_521personal url: http://mini.eastday.com/mini/resourc...
Leia mais魔盾安全分析报告 URL信息 特征 运行截图 网络分析 访问主机记录
C:\Users\desktop.ini C:\Users\test C:\Users\test\Favorites C:\Users\test\Favorites\desktop.ini C:\Users\test\Desktop\desktop.ini C:\Windows\SysWOW64\propsys.dll C:\Windows\sysnative\propsys.dll C:\...
Leia mais魔盾安全分析报告 文件详细信息 特征
• 0x40917c - SetClassLongA • 0x409180 - IsWindowEnabled • 0x409184 - GetSysColor • 0x409188 - GetWindowLongA • 0x40918c - SetCursor • 0x409190 - LoadCursorA • 0x409194 - CheckDlgButton • 0x409198 -...
Leia mais